Vulnerability Management Analyst
NewrezAbout the role
Exceed the expectations of our residential mortgage borrowers & business partners through superior service, simple processes, and effective communications.
We deliver on this mission by empowering our employees by encouraging and recognizing superior performance and innovative solutions, by promoting teamwork and divisional cooperation.
POSITION SUMMARY
The Vulnerability Management (VM) Analyst is a hands-on practitioner responsible for discovering, analyzing, prioritizing, and tracking remediation of vulnerabilities across endpoints, servers, cloud platforms, containers, and applications. The analyst operates the VM toolset, improves scan coverage and data quality, partners with system and application owners to drive remediation within policy SLAs, and produces clear, actionable reporting for both technical teams and leadership. The role supports zero-day events, audit requests, and continuous program maturation as part of the enterprise VM program governed by our Patch & Vulnerability Management Standard.
DESCRIPTION
Duties and Responsibilities
- Scanning Operations & Coverage
- Execute authenticated and agent-based scans using Qualys (VMDR, WAS/TotalAppSec) for on-premises, cloud assets, containers, and web applications.
- Manage Suridata for SaaS security posture and asset discovery.
- Assist with Veracode application security scanning and reporting.
- Maintain scan schedules, credentials, and agent health; expand coverage to new assets and services.
- Coordinate with platform owners to enable safe scanning and validate rescans.
- Triage, Analysis & Prioritization
- Review and triage scan results, reducing false positives and noise.
- Apply risk-based frameworks (CVSS v3.1, CISA KEV, EPSS, asset criticality) to prioritize remediation.
- Provide clear remediation guidance and document knowledgebase notes.
- Remediation Coordination & Tracking
- Create and route remediation tickets via ITSM platforms (e.g., ServiceNow, Jira).
- Track SLA attainment and escalate issues as needed.
- Partner with infrastructure, desktop, cloud, and application teams to resolve blockers.
- Validate fixes through rescans and close tickets with evidence.
- Data Quality, Integrations & Automation
- Improve asset-to-owner mapping and tag critical systems.
- Support automation for ticket creation, routing, and exception reviews.
- Maintain operational runbooks and playbooks.
- Reporting, Metrics & Audit Support
- Build and publish dashboards on coverage, SLA performance, exception inventory, and risk reduction.
- Provide evidence for internal/external audits and customer security reviews.
- Exceptions & Risk Acceptance
- Process exception requests per policy, ensuring compensating controls and tracking expiry/review dates.
- Monitor and drive timely renewal or closure of exceptions.
- Zero-Day / Major Event Response
- Assist with rapid assessment, scoping, communication, and mitigation during critical events.
- Participate in after-hours rotations as needed.
- Performs related duties as assigned by management.
Qualifications and Education Requirements
- Bachelor’s degree in Information Security, Information Systems, Computer Science, or equivalent practical experience.
- 2-4 years in Information Security or Systems Engineering, including 2+ years directly operating a vulnerability management program or toolset in a multi-platform environment.
- Exposure to Windows/Linux patching, cloud platforms (Azure/AWS), container registries, and network devices; understanding of change management and maintenance windows.
- Familiarity with NIST CSF/ISO 27001; experience supporting audits and customer security requests preferred.
- Preferred Certifications: Security+, CySA+, GSEC, AZ-500, Qualys VMDR Specialist, or similar.
Skills, Abilities, and Knowledge
- Technical depth in vulnerability scanning, agent management, and authenticated scans across Windows/Linux, cloud workloads, and containers.
- Ability to apply risk analysis frameworks and understand exploitability and business impact.
- Scripting experience (PowerShell and/or Python) and comfort with Excel/Power BI or SQL for reporting.
- Familiarity with ITSM/CMDB integrations.
- Strong communication skills for translating technical findings into actionable tickets and summaries.
- Process discipline for maintaining documentation and audit evidence.
Additional Information:
While this description is intended
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s