Experience
- 5+ years
of dedicated Vulnerability Management experience
- Not looking for a general SOC analyst unless they have significant VM ownership
Primary Responsibilities
- Manage the complete vulnerability management lifecycle
- Perform continuous vulnerability discovery using:
- Tenable (Nessus, Tenable.io/Tenable.sc)
- Microsoft Defender Vulnerability Management
- Ensure comprehensive asset coverage across endpoints, servers, and cloud workloads
- Analyze vulnerabilities using:
- CVSS v
- 3.x
- Exploit availability
- Cyble Threat Intelligence
- CISA Known Exploited Vulnerabilities (KEV)
- Prioritize vulnerabilities based on:
- Business criticality
- Internet exposure
- Exploitability
- Lateral movement risk
- Drive remediation from identification through validation
- Track remediation SLAs and governance
- Validate fixes through rescanning
- Produce executive dashboards and operational reports
- Integrate VM processes with ITSM platforms (HALOITSM preferred)