Coalfire logo
Coalfire

Cyber solutions that move you forward, faster.

Vulnerability Analyst

Security AnalystSecurity AnalystOtherRemoteSeniorTeam 1,001-5,000Since 2001H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

123 days ago

Salary

$64K - $112K / year

Seniority

Senior

Bachelor Degree3 yrs expEnglishAWSAzureGCPKubernetesPython

Job Description

Vulnerability Analyst

Coalfire

• Manage Plan of Action & Milestones (POA&Ms) lifecycle including creation, tracking, risk adjustment justification, and deviation requests in coordination with 3PAO assessors and federal stakeholders • Collect, organize, and maintain security control evidence and artifacts for monthly continuous monitoring deliverables and assessment/authorization activities, ensuring alignment with FedRAMP, HITRUST, PCI, and similar frameworks • Maintain accurate system inventory and authorization boundary documentation to ensure scanning scope aligns with approved system boundaries • Analyze scan results for false positives, document justifications, and prepare deviation requests with supporting risk assessments • Translate technical vulnerability findings into risk-based language for federal clients and authorization officials, presenting monthly status briefings as needed • Collaborate with development, SRE, and infrastructure teams to integrate vulnerability management into CI/CD pipelines, cloud environments (AWS, Azure, GCP), and container/Kubernetes platforms • Participate in change management processes to ensure continuous monitoring activities align with system changes and maintain compliance posture • Support and maintain enterprise vulnerability management tools (such as Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring timely updates and patches • Run regular and on-demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation • Track and document vendor dependencies, operational requirements, and open vulnerabilities, producing clear monthly reports and updates for clients • Contribute to improving internal standards and processes, including maintaining documentation, training materials, and standard operating procedures

Job Requirements

  • 3–5 years of professional experience in vulnerability management, compliance monitoring, or related security operations roles
  • Hands-on expertise with operating system, database, network, container, web application, and API vulnerability management
  • Direct experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP
  • Background working within at least one compliance framework (for example, FedRAMP, HITRUST, PCI), including risk assessment and reporting
  • Experience delivering monthly or periodic vulnerability status reports and tracking remediation efforts with internal and external teams
  • Administrator-level certification in AWS, Azure, or GCP
  • Working knowledge of cloud architecture and security controls in AWS, Azure, or GCP, including ability to assess attack surfaces and recommend cloud-native remediation approaches
  • Strong knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS) and risk prioritization frameworks
  • Understanding of NIST 800-53 security controls, particularly RA-5, SI-2, CM-6, and how continuous monitoring supports control implementation
  • Experience with STIG benchmarks and automated compliance scanning tools (SCAP, SCC)
  • Familiarity with baseline configuration standards (CIS Benchmarks, vendor hardening guides) and compliance posture reporting
  • Ability to distinguish false positives from true vulnerabilities and articulate risk-based justifications for deviation requests
  • Proficiency in scripting languages (Python, PowerShell, Bash) for task automation, report generation, and remediation workflows
  • Strong client-facing communication and documentation skills, with ability to present technical findings to federal stakeholders and produce timely compliance reports
  • Ability to work efficiently with cross-functional technical teams to investigate, prioritize, and coordinate vulnerability remediation efforts
  • Bachelor’s degree or equivalent work experience.

Benefits

  • paid parental leave
  • flexible time off
  • certification and training reimbursement
  • digital mental health and wellbeing support membership
  • comprehensive insurance options

Related Job Pages

More Security Analyst Jobs

OtherRemoteTeam 10,001+Since 2013H1B No Sponsor

• Conduct our digital risk management program to improve cybersecurity. • Plan, support, and execute security awareness training campaigns. • Assist with analysis, communication, and documentation of audits. • Undertake compliance program/project initiatives, audits, and benchmarking of security policies against good practice and standards. • Assist in the development and implementation of sustainable compliance framework and processes in the organization to meet IT policies, business requirements, and applicable legal and regulatory requirements. • Gain widespread support of and compliance with information security requirements. • Address vulnerabilities identified from various scans making sure that they are properly addressed and categorized leading in the corrective actions to assure data and infrastructure security. • Assist with SOX compliance testing as required

United States
Job Closed
Cherokee Federal logo

Cyber Security Analyst

Cherokee Federal

Building. Solving. Serving.

Security Analyst125 days ago
OtherRemoteTeam 5,001-10,000Since 1969H1B No Sponsor

• Provide support to the MARAD Information Assurance Program for operations, business and administrative in support of the System Authorization Process and deliverables as defined in this document. • Direct involvement with MARAD Program Office and the Information System Security Manager (ISSM) on cybersecurity and authority to operate (ATO) matters related to information systems supporting the MARAD CIO. • Manage MARAD’s Information System’s core documentation, in accordance with each phase of the system engineering process / System Development Life Cycle (SDLC) with standardized templates, baseline management with supporting checklists and technical guides. • Support creation/update of FIPS 199 Security Categorization document. • Support creation/update security control selection listing (include justification for applicable tailor and or risk acceptance). • Support creation/update System Security Plan (SSP); ensure discovered and identified system components, control implementation status are addressed. • Assist in security incident response, risk mitigation, and compliance reporting. • Performs other job-related duties as assigned.

United States
$135K - $151K / year
Job Closed
OtherRemoteTeam 5,001-10,000H1B Sponsor

• Running detection & response monitor SIEM/EDR telemetry, triage alerts, contain and eradicate threats, then lead root-cause analysis and post-mortems. • Enhancing signal quality by designing correlation searches, refining detection rules, and automating SOAR playbooks to reduce false positives and MTTR. • Analyzing vulnerabilities by extracting findings from platforms like Wiz, Vulcan, Grype, Tenable, and quantifying infrastructure impact to prioritize effectively. • Ensuring remediation governance by generating tickets, assigning owners, enforcing deadlines, and verifying resolutions through rescans and evidence collection thoroughly. • Creating visibility and KPIs by maintaining dashboards tracking vulnerabilities, remediation speed, SLA adherence, MTTR/MTTD, patch age, and risk trends. • Strengthening controls by mapping emerging TTPs to defenses, recommending new detections, and implementing safeguards across cloud, container, and on-prem environments.

United States
Job Closed
Republic Services logo

Senior Information Security Analyst

Republic Services

As a leader in environmental solutions, recycling & waste, we partner with customers to create a more sustainable world.

Security Analyst126 days ago
OtherRemoteTeam 10,001+Since 1998H1B No Sponsor

• Acts as the escalation point for reviewing security events and incidents from a wide variety of cybersecurity technologies such as endpoint security tools, network security tools, etc. • Performs event correlation using information gathered from a variety of sources within the enterprise to continuously improve detection • Provides support in obtaining and maintaining compliance with NIST standards • Creates and/or maintains incident response documentation including the Incident Response Plan, Incident Response Playbooks, etc. • Partners with various stakeholders across the business to improve overall security posture • Coordinates end-to-end incident response activities related to a wide variety of security risks and threats, including but not limited to, ransomware, system compromise, account takeover, phishing, etc. • Implements security controls and processes to protect digital assets and conduct routine security audits to ensure compliance • Maintains active Threat Intelligence program, integrate Threat Intel with detection and monitoring to proactively block malicious actors • Proactively searches for advanced threats that may evade existing security solutions • Uses threat intelligence to analyze network, endpoint, and application data • Creates and adjusts threat-hunting scripts and queries to improve detection • Contributes to knowledge base and procedural documentation • Mentors less experienced analysts and provide guidance during critical incidents and investigations • Performs other job-related duties as assigned or apparent • Implementing and maintaining security controls in IaaS environments • Driving optimization of Cloud specific security coverage • Developing and maintaining Cloud specific security standards and procedures

United States
$99.8K - $137.3K / year
Job Closed