Jobs and Careers
WE
Staff IT Analyst II Cyber - Senior Vulnerability Management Analyst
Western Alliance BankBlock 23, United States, United Statesfull_timeVerifiedPosted 12 Sept 2025
About the role
Job Title:
Staff IT Analyst II Cyber - Senior Vulnerability Management AnalystLocation:
Block 23What you'll do:
The Business Information Security Office (BISO), part of Western Alliance Bank's (WAB) enterprise security organization, serves as the frontline connection between the security programs and technology teams responsible for managing security risks and vulnerabilities. The Vulnerability Management (VM) program within the BISO organization establishes standards, direction, and priorities for vulnerability management processes, and works with security peers, IT program owners, infrastructure teams, and application teams to identify, assess, prioritize, and track the resolution of vulnerabilities in WAB’s cloud and on-premises environments.The Staff IT Analyst II – Cyber is a cross functional role within the VM program that is responsible for driving strategy, ensuring the adoption of requirements, and collaborating with peers who manage vulnerability scans, threat intelligence platforms, exceptions processes and risk reporting. This position is tasked with supporting WAB’s IT organization and business units by analyzing scan results, conducting risk assessments, monitoring remediation progress, automating manual tasks, and ensuring information is well communicated and actionable to enable timely remediation.
- Assist with defining and implementing strategy, processes, procedures, and controls for vulnerability management, threat exposure management, and compliance scanning.
- Review and validate vulnerability scan results from various platforms (e.g., Wiz, Rapid7) for accuracy and relevance and support investigations into false positive detections.
- Support the implementation, management, and maintenance of vulnerability management and external attack surface platforms or tools, including identifying and resolving technical or functional issues and ensuring reliable platform operations.
- Lead the planning and implementation of security measures to protect cybersecurity practices, processes and IT systems.
- Design, monitoring, and evaluation of security safeguards by analyzing these items to identify potential security threats.
- Develop strategies to protect security practices, processes, or IT systems from cyber-attacks.
- Maintain security systems or capabilities by installing, configuring and/or maintaining software, and assisting in monitoring the company network/system for breaches or vulnerabilities.
- Design scripts and deploy automated solutions to streamline manual processes involved in information collection and consolidation.
- Track open vulnerabilities from identification through resolution, coordinating with IT program and asset owners or escalating issues as needed.
- Provide support for developing customized compliance policy scanning rulesets based on CIS benchmarks.
- Work with security, IT teams, and other stakeholders to assess the impact of vulnerabilities in WAB’s environment and establish appropriate mitigating controls.
- Recommend and apply measures to address and resolve vulnerabilities or security exposures.
- Prepare and deliver vulnerability reports and dashboards for technical teams, leadership, and business stakeholders.
- Identify recurring vulnerabilities and trends to assist in long-term risk reduction strategies.
- Lead the planning and implementation of security measures to protect cybersecurity practices, process, and IT systems.
- Support vulnerability management and information security by increasing awareness and use of security services.
- Design and improve KRIs, KPIs, and operational metrics for different audiences and organizational needs.
- Stay informed about new vulnerabilities, cyber threats, and attack vectors.
- Participate in audits and examinations as a subject matter expert when required.
- Propose and spearhead process improvements to enhance the VRM program.
What you'll need:
- 5+ years of related experience in vulnerability management, threat management, security operations, or a related cybersecurity discipline.
- Bachelor’s degree in computer science, IT or related field required.
- Proficiency with vulnerability management tools (e.g., Rapid 7 Insight VM, Qualys, Wiz), and patch/configuration management hardening guidelines and approaches.
- Experience with ServiceNow Vulnerability Response, CIS WorkBench, PowerBI and Power Automate for tracking, reporting, and process automation.
- Solid understanding of operating systems (Windows, Linux), networking concepts, and cloud platforms (AWS, Azure, GCP).
- An intermediate knowledge of general Financial Services or Banking is preferred.
- Intermediate knowledge of applicable regulatory and legal compliance obligations, rules and regu
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s