Jobs · Information Technology · Indiana

Vulnerability Management Security Analyst

University of Notre Dame · Notre Dame, IN · 1 mo ago
On-siteInformation TechnologyFull-time

Job Description

At the University of Notre Dame, protecting our digital environment and safeguarding our community's data is vital to ensuring the University remains a force for good in the world. To that end, the Office of Information Technology (OIT) is seeking a collaborative and analytical Vulnerability Management Security Analyst to join our information security team.

What You'll Do

  • Support the vulnerability management lifecycle through routine scanning, analysis, and validation of security findings.
  • Prioritize vulnerabilities based on exploitability, exposure, asset criticality, and data sensitivity.
  • Partner with system owners and distributed IT units to coordinate and track remediation progress.
  • Monitor, triage, and escalate security events across SIEM, EDR, email, and cloud platforms.
  • Aid in incident response by gathering evidence, documenting timelines, and recommending containment.
  • Maintain and tune security tools, dashboards, and automated ticketing workflows.
  • Contribute to broader security initiatives such as cloud security, identity protection, and risk reviews.

Qualifications

  • Minimum Qualifications: Bachelor’s degree in Computer Science, Information Technology, Information Security, or a related field, OR an equivalent combination of education and professional experience.
  • Working knowledge of cybersecurity operations, vulnerability management, incident response, security monitoring, enterprise technology, and IT risk management principles.
  • Knowledge of vulnerability management practices, including scanning, validation, risk-based prioritization, remediation tracking, exceptions, compensating controls, and remediation verification.
  • Strong analytical, problem-solving, documentation, communication, security administration, and stakeholder coordination skills.
  • Ability to work in the United States, now or in the future, without visa sponsorship.

Preferred Qualifications

  • Experience in higher education or another complex, decentralized organization.
  • Familiarity with cybersecurity frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, EDUCAUSE guidance, or MITRE ATT&CK.
  • Experience with security operations, vulnerability management, ticketing, or endpoint platforms such as CrowdStrike, ServiceNow, Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or similar tools.
  • Experience supporting vulnerability remediation, phishing investigations, account compromise response, endpoint investigations, cloud security reviews, or security tool administration.
  • Experience with scripting, automation, APIs, dashboarding, or data analysis using Python, PowerShell, Bash, SQL, Excel, or similar technologies.
  • Relevant certifications such as Security+, CySA+, GSEC, GCIH, GCIA, GMON, SSCP, CISSP, or similar credentials.

Additional Information

Please include a cover letter for full consideration of your application. Salary: up to $95K, commensurate with experience
Deadline to apply (subject to change): Thursday, August 6th, 2026

This position maintains a Hybrid work arrangement (1-2 days remote based on operational needs and team expectations.)

Similar jobs