Job detail for Vulnerability/Threat Management Analyst

R
Vulnerability/Threat Management Analyst
Revinate
Todayvia fourdayweek

Use AI to assess how you fit

What You'll Do
Run continuous vulnerability scanning in Tenable and Crowdstrike Falcon to make sure every asset across our public cloud environment is inventoried, covered, and assessed.

Prioritize findings by real-world risk, using exploitability, threat intelligence, and asset context rather than CVSS severity scores alone, so we never send teams chasing vulnerabilities that can't actually be exploited.

Validate high-priority findings hands-on, whether by spinning up a test virtual machine in our cloud VPC or using AI-assisted tooling to confirm exploitability in our test environments.

Automate the path from finding to ticket with existing tools, push validated fixes through remediation teams via our ticketing workflow (Jira), and follow up to make sure SLAs are met.

Help define vulnerability management standards and report on program health, and participate in the mandatory on-call rotation for security incident response alongside the Director of Security and our AI-driven SOC alert analyst.

What You'll Bring
Hands-on, real-world experience running vulnerability management in a business environment, ideally with Tenable (experience with Qualys, Rapid7 InsightVM, or Kenna also translates).

Experience working in public cloud environments (AWS, Azure, or GCP), including the ability to stand up test infrastructure to validate findings.

Strong scripting skills for automating scan-to-ticket workflows (Python is a plus).

A working knowledge of offensive security techniques, at the level of PenTest+ or OSCP, sufficient to confirm whether a finding is genuinely exploitable.

Experience with remediation ticketing workflows (Jira) and endpoint security tooling; hands-on time with CrowdStrike Falcon Complete will make you stand out.

Certifications such as CompTIA CySA+ or GIAC GEVA (most valued), or Security+, GSEC, PenTest+, OSCP, or SSCP. Certifications are a plus, not a requirement, and no degree is required. Proven hands-on experience matters most to us.

A background in security compliance, security operations, or application security. On a lean team, the ability to wear more than one hat goes a long way.

People Describe You As
A self-starter. Hand you the documentation for a pipeline someone else built, and you'll read it, ask the right questions, and then run with it without needing step-by-step direction.

Someone who closes the loop. Finding the vulnerability is only half the job for you. You get real satisfaction from seeing the fix shipped and the dashboard trend in the right direction.

An automator at heart. When you see the same manual task twice, you're already writing the script so no one has to do it a third time.

Calm and dependable under pressure. When the on-call page comes in, you stay focused, triage methodically, and communicate clearly.

A pragmatic partner. You can explain to an engineering team why one fix matters now and another can wait, and they trust your judgment because your tickets are always worth their time.