Senior IT Professional – Security / Vulnerability Management Analyst jobs in United States
cer-icon
Apply on Employer Site
company-logo

Securance Consulting · 5 hours ago

Senior IT Professional – Security / Vulnerability Management Analyst

Securance Consulting is seeking a Senior IT Professional – Security / Vulnerability Management Analyst to oversee the vulnerability management lifecycle across law enforcement and municipal technology environments. The role involves vulnerability scanning, risk scoring, patch lifecycle coordination, and providing subject matter expertise in security reporting and remediation governance.

Cyber SecurityInformation ServicesInformation Technology
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Oversee routine and ad-hoc vulnerability scanning of network infrastructure, endpoints, servers, applications, and cloud environments
Ensure scanning coverage aligns with asset inventories and operational priorities
Validate scan configurations, credentials, and scope accuracy
Analyze vulnerability findings using CVSS, EPSS, exploit intelligence, and business context
Assign risk scores and remediation priorities based on likelihood and impact
Identify systemic risk patterns and recurring exposure trends
Coordinate remediation activities with infrastructure, application, and operations teams
Track remediation progress and validate closure
Support patch deployment planning and prioritization
Escalate overdue or high-risk remediation items
Produce vulnerability dashboards, trend analysis, and executive summaries
Communicate risk posture to technical teams and leadership
Maintain vulnerability metrics for governance and audit reporting
Support vulnerability management policy and procedure development
Ensure alignment with NIST and industry standards
Identify process improvement opportunities and tool enhancements
Provide vulnerability context and mitigation guidance during security incidents
Assist with rapid exposure assessment during active events
Serve as a trusted advisor for vulnerability and patch risk decisions
Partner with cross-functional teams to reduce organizational risk

Qualification

Vulnerability management lifecycleVulnerability scanning platformsRisk-based prioritizationCompTIA Security+GIAC GSECCompTIA CySA+NIST 800-53 familiarityScripting experienceTechnical risk communicationCross-team collaboration

Required

Associate's degree in Computer Science, Management and Information Systems (MIS), Business, or a related field
System-specific technical certifications may substitute for the Associate degree
Experience in IT security, infrastructure, or application support may substitute for education on a year-for-year basis
Minimum of 24 months of technology experience in IT security or supporting security aspects of IT infrastructure or application teams
Hands-on experience with vulnerability scanning platforms such as Qualys, Tenable, or Rapid7
Experience coordinating remediation activities across technical teams
CompTIA Security+
GIAC GSEC
CompTIA CySA+
Vulnerability management lifecycle
Risk-based prioritization
Patch lifecycle coordination
Security reporting and metrics
CVSS and exploit risk analysis
Cross-team collaboration
Technical risk communication

Preferred

Experience in law enforcement or regulated environments
Familiarity with NIST 800-53 and NIST CSF
Scripting or automation experience (Python, PowerShell)
Experience with asset inventory and CMDB integration

Company

Securance Consulting

twittertwittertwitter
company-logo
Securance Consulting is an IT company that provides cloud security and cybersecurity services.

Funding

Current Stage
Early Stage

Leadership Team

leader-logo
Paul Ashe
President, Founder
linkedin
Company data provided by crunchbase