it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

7 jobs found

Email me jobs like this
Refine Search
Current Search
senior vulnerability management analyst
Information Technology Specialist HQ AFMC 3002.0
Credence Dayton, Ohio
Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver on a scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for an Information Technology Specialist at the journeyman level supporting Headquarters Air Force Materiel Command (HQ AFMC) A4/10 in Wright Patterson AFB, OH. The HQ AFMC Directorate of Logistics, Civil Engineering, Force Protection, and Nuclear Integration (A4/10) is responsible for shaping the workforce and infrastructure needed to deliver logistics, sustainment, installation support, and force protection capabilities across the command. This includes providing oversight for acquisition logistics, supply chain management, depot maintenance, base-level logistics operations, and enterprise security programs. Additionally, the directorate delivers strategic facility and infrastructure oversight while providing command-wide direction for Major Command (MAJCOM) security operations, ensuring the readiness and responsiveness required to support war-winning expeditionary capabilities. Responsibilities include, but are not limited to the duties listed below: Provide day-to-day Information Technology Specialist support within Sensitive Compartmented Information Facilities (SCIFs) supporting DoD agencies, the Office of the Secretary of Defense (OSD), and HQ AFMC, including classified enclave activities. Provide Information Assurance (IA) and technical security administrative assistance, IT endpoint administration and support, network engineering assistance, and Site Information Systems Security Manager (ISSM)/Information Systems Security Officer (ISSO) support. Install, maintain, audit, refresh, and support a secure Microsoft Windows endpoint environment. Maintain DoD and Air Force internet applications and protocols, including Internet Protocol (IP), Transmission Control Protocol (TCP), Hypertext Transfer Protocol (HTTP), Secure Hypertext Transfer Protocol (HTTPS), File Transfer Protocol (FTP), and Secure Sockets Layer (SSL). Interface with AFMC HQ customers and provide IT-related support to quickly resolve technical issues. Analyze and troubleshoot system anomalies to ensure optimum equipment performance. Perform periodic maintenance, hardware upgrades and replacement, firmware updates, and system configuration changes. Attend planning and requirements meetings with IT staff, program managers, analysts, and customers as required. Prepare systems for operational use and support operational tests and inspections. Provide technical guidance and Information Assurance support for AFMC technologies. Apply working knowledge of Local Area Network (LAN) and Wide Area Network (WAN) technologies to maintain system operations. Aid with the acquisition and sustainment of IT systems for weapon systems, subsystems, components, and equipment. Assist with security accreditation and information technology certification processes. Assist in the operation of necessary IT systems to ensure standardized file structures and seamless file sharing to support daily interactions with the SIO, SSO, staff, and directorate senior staff. Advise and assist in the development of system security management plans, computer Certification and Accreditation documentation, security vulnerability analyses, and other system security documents identified in MIL-HDBK 1785, DoDI 5000.02, and AF Supplement 1. Attend meetings and prepare/present briefings, graphics, and visuals for/to leadership. Prepare security paperwork, including but not limited to DD Form 2875 and Communications Security (COMSEC) inspection criteria. Assist in access control and perform escort duties for Video Teleconferencing (VTC) visitors. Answer telephones and other modes of administrative communication in the performance of duties. Perform self-inspections; identify security discrepancies; and report security incidents. Support security inspections; identify security discrepancies; and assist in report preparation. Perform courier responsibilities within the local area. Control program media and information within Air Force Materiel Command (AFMC) security guidelines. Populate and update databases, including but not limited to suspense tracking, personnel access, facility, JWICS system, and SharePoint databases, in the performance of assigned duties. Perform daily opening and closing of the SCIF and respond to SCIF after-duty-hour alarm activations when notified. Support AFMC/A2 Directorate JWICS communications to ensure cognizant parties are informed and appropriate responses are prepared, coordinated, and communicated while maintaining required security disciplines. Support the proper handling, preparation, and tracking of physical classified products entering or leaving the facility. Support planning, formulation, editing, development, publication, and storage of Special Access Program (SAP) and Top Secret/Sensitive Compartmented Information (TS/SCI) products. Support meetings and events attended or hosted by the Senior Intelligence Officer (SIO) on an as-required basis. Develop, maintain, and modify schedules and calendars as required on multi-level security systems. Use updated Security Classification Guides (SCGs) or other source documents to perform classification reviews on JWICS IT documentation and ensure proper derivative classification on all documents encountered during performance of duties. Support administrative tasks as necessary to support management, acquisition, and operations functions. Requirements Must have an active or current Top Secret security clearance with Sensitive Compartmented Information eligibility, verifiable in the Defense Information System for Security (DISS). BA/BS and at least three (3) years of experience in the respective technical/professional discipline being performed with proper certifications required in the labor category performance requirements OR six (6) years of directly related experience with proper certifications as described in the labor category performance requirements. Must be able to work successfully in a dynamic environment and effectively interact with numerous DoD, Agency, military/civilian personnel, and industry partners. Must be able to lift up to 50 pounds. Must meet position and certification requirements outlined in DoD Directive 814 for IA Technician Level II within six months of the date of hire. Must have working knowledge of various DODIIS Cryptologic SCI Information Systems Security Standards, Common Criteria, and System Security Policy as they relate to Certification and Accreditation (C&A). Must be familiar with security policy manuals, appropriate Intelligence Community Directives (ICDs), and other guiding policy documents. Why This Role Matters Real-World Impact - Your work will support defense and health agencies where AI solutions directly contribute to national security and public well-being. Growth-Oriented Environment - Learn from technical leaders, innovate within Agentic AI, and mentor those around you in AI best practices. Culture of Empowerment - You'll be part of a team that values innovation, trust, collaboration, and mission success Please join us, as together we build a better world one mission at a time powered by Technology Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development
10/09/2026
Full time
Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With more than 1,700+ team members, 1,500+ AI & data experts, and 100+ prime contracts, we deliver on a scale and with purpose. We've been recognized as a Top Workplace by The Washington Post for six consecutive years and named to the Inc. 5000 list of Fastest-Growing Private Companies in 13 of the past 14 years. Credence is a welcoming environment for those looking to grow and make a meaningful impact. We encourage employees to push boundaries and help solve critical, world-changing federal challenges. Position Summary Credence has an immediate opening for an Information Technology Specialist at the journeyman level supporting Headquarters Air Force Materiel Command (HQ AFMC) A4/10 in Wright Patterson AFB, OH. The HQ AFMC Directorate of Logistics, Civil Engineering, Force Protection, and Nuclear Integration (A4/10) is responsible for shaping the workforce and infrastructure needed to deliver logistics, sustainment, installation support, and force protection capabilities across the command. This includes providing oversight for acquisition logistics, supply chain management, depot maintenance, base-level logistics operations, and enterprise security programs. Additionally, the directorate delivers strategic facility and infrastructure oversight while providing command-wide direction for Major Command (MAJCOM) security operations, ensuring the readiness and responsiveness required to support war-winning expeditionary capabilities. Responsibilities include, but are not limited to the duties listed below: Provide day-to-day Information Technology Specialist support within Sensitive Compartmented Information Facilities (SCIFs) supporting DoD agencies, the Office of the Secretary of Defense (OSD), and HQ AFMC, including classified enclave activities. Provide Information Assurance (IA) and technical security administrative assistance, IT endpoint administration and support, network engineering assistance, and Site Information Systems Security Manager (ISSM)/Information Systems Security Officer (ISSO) support. Install, maintain, audit, refresh, and support a secure Microsoft Windows endpoint environment. Maintain DoD and Air Force internet applications and protocols, including Internet Protocol (IP), Transmission Control Protocol (TCP), Hypertext Transfer Protocol (HTTP), Secure Hypertext Transfer Protocol (HTTPS), File Transfer Protocol (FTP), and Secure Sockets Layer (SSL). Interface with AFMC HQ customers and provide IT-related support to quickly resolve technical issues. Analyze and troubleshoot system anomalies to ensure optimum equipment performance. Perform periodic maintenance, hardware upgrades and replacement, firmware updates, and system configuration changes. Attend planning and requirements meetings with IT staff, program managers, analysts, and customers as required. Prepare systems for operational use and support operational tests and inspections. Provide technical guidance and Information Assurance support for AFMC technologies. Apply working knowledge of Local Area Network (LAN) and Wide Area Network (WAN) technologies to maintain system operations. Aid with the acquisition and sustainment of IT systems for weapon systems, subsystems, components, and equipment. Assist with security accreditation and information technology certification processes. Assist in the operation of necessary IT systems to ensure standardized file structures and seamless file sharing to support daily interactions with the SIO, SSO, staff, and directorate senior staff. Advise and assist in the development of system security management plans, computer Certification and Accreditation documentation, security vulnerability analyses, and other system security documents identified in MIL-HDBK 1785, DoDI 5000.02, and AF Supplement 1. Attend meetings and prepare/present briefings, graphics, and visuals for/to leadership. Prepare security paperwork, including but not limited to DD Form 2875 and Communications Security (COMSEC) inspection criteria. Assist in access control and perform escort duties for Video Teleconferencing (VTC) visitors. Answer telephones and other modes of administrative communication in the performance of duties. Perform self-inspections; identify security discrepancies; and report security incidents. Support security inspections; identify security discrepancies; and assist in report preparation. Perform courier responsibilities within the local area. Control program media and information within Air Force Materiel Command (AFMC) security guidelines. Populate and update databases, including but not limited to suspense tracking, personnel access, facility, JWICS system, and SharePoint databases, in the performance of assigned duties. Perform daily opening and closing of the SCIF and respond to SCIF after-duty-hour alarm activations when notified. Support AFMC/A2 Directorate JWICS communications to ensure cognizant parties are informed and appropriate responses are prepared, coordinated, and communicated while maintaining required security disciplines. Support the proper handling, preparation, and tracking of physical classified products entering or leaving the facility. Support planning, formulation, editing, development, publication, and storage of Special Access Program (SAP) and Top Secret/Sensitive Compartmented Information (TS/SCI) products. Support meetings and events attended or hosted by the Senior Intelligence Officer (SIO) on an as-required basis. Develop, maintain, and modify schedules and calendars as required on multi-level security systems. Use updated Security Classification Guides (SCGs) or other source documents to perform classification reviews on JWICS IT documentation and ensure proper derivative classification on all documents encountered during performance of duties. Support administrative tasks as necessary to support management, acquisition, and operations functions. Requirements Must have an active or current Top Secret security clearance with Sensitive Compartmented Information eligibility, verifiable in the Defense Information System for Security (DISS). BA/BS and at least three (3) years of experience in the respective technical/professional discipline being performed with proper certifications required in the labor category performance requirements OR six (6) years of directly related experience with proper certifications as described in the labor category performance requirements. Must be able to work successfully in a dynamic environment and effectively interact with numerous DoD, Agency, military/civilian personnel, and industry partners. Must be able to lift up to 50 pounds. Must meet position and certification requirements outlined in DoD Directive 814 for IA Technician Level II within six months of the date of hire. Must have working knowledge of various DODIIS Cryptologic SCI Information Systems Security Standards, Common Criteria, and System Security Policy as they relate to Certification and Accreditation (C&A). Must be familiar with security policy manuals, appropriate Intelligence Community Directives (ICDs), and other guiding policy documents. Why This Role Matters Real-World Impact - Your work will support defense and health agencies where AI solutions directly contribute to national security and public well-being. Growth-Oriented Environment - Learn from technical leaders, innovate within Agentic AI, and mentor those around you in AI best practices. Culture of Empowerment - You'll be part of a team that values innovation, trust, collaboration, and mission success Please join us, as together we build a better world one mission at a time powered by Technology Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development
Senior Cloud Security Operations Manager
Cherokee Federal Almont, Colorado
The Senior Cloud Security Operations Manager leads security operations for federal cloud environments, focusing on AWS and Azure. The role oversees cloud monitoring, incident response, vulnerability management, and security posture using tools such as Splunk ES and Prisma Cloud. This position defines detection use cases, builds and maintains AWS logging and integrations, drives compliance with federal standards, and manages a small technical team to ensure secure, reliable cloud services. Responsibilities Lead cloud security operations for AWS environments, including triage, investigation, containment, and recovery. Administer and optimize Splunk Enterprise Security, including data onboarding, CIM alignment, rules, dashboards, and reporting. Manage Prisma Cloud CSPM outcomes, policies, exceptions, and remediation workflows to improve security posture. Engineer and maintain AWS security logging and integrate services like Cloud Trail, VPC Flow Logs, and Guard Duty into monitoring tools. Define and execute AWS incident response playbooks and lead incident handling, evidence collection, and post-incident actions. Drive detection engineering mapped to MITRE ATT&CK and continuously improve detection fidelity and coverage. Ensure continuous monitoring and support compliance with federal security standards such as FISMA and NIST 800-53. Manage and mentor security analysts and engineers, setting performance expectations and overseeing delivery quality. Required Skills Cloud security engineering (AWS, Azure) SIEM administration (Splunk ES) Cloud security posture management (Prisma Cloud or CSPM) Cloud incident response MITRE ATT&CK detection engineering AWS security services (Cloud Trail, Guard Duty, Security Hub, etc.) Identity and access management (IAM) in cloud Vulnerability management coordination Security compliance (FISMA, NIST 800-53) Security automation and scripting
10/08/2026
Full time
The Senior Cloud Security Operations Manager leads security operations for federal cloud environments, focusing on AWS and Azure. The role oversees cloud monitoring, incident response, vulnerability management, and security posture using tools such as Splunk ES and Prisma Cloud. This position defines detection use cases, builds and maintains AWS logging and integrations, drives compliance with federal standards, and manages a small technical team to ensure secure, reliable cloud services. Responsibilities Lead cloud security operations for AWS environments, including triage, investigation, containment, and recovery. Administer and optimize Splunk Enterprise Security, including data onboarding, CIM alignment, rules, dashboards, and reporting. Manage Prisma Cloud CSPM outcomes, policies, exceptions, and remediation workflows to improve security posture. Engineer and maintain AWS security logging and integrate services like Cloud Trail, VPC Flow Logs, and Guard Duty into monitoring tools. Define and execute AWS incident response playbooks and lead incident handling, evidence collection, and post-incident actions. Drive detection engineering mapped to MITRE ATT&CK and continuously improve detection fidelity and coverage. Ensure continuous monitoring and support compliance with federal security standards such as FISMA and NIST 800-53. Manage and mentor security analysts and engineers, setting performance expectations and overseeing delivery quality. Required Skills Cloud security engineering (AWS, Azure) SIEM administration (Splunk ES) Cloud security posture management (Prisma Cloud or CSPM) Cloud incident response MITRE ATT&CK detection engineering AWS security services (Cloud Trail, Guard Duty, Security Hub, etc.) Identity and access management (IAM) in cloud Vulnerability management coordination Security compliance (FISMA, NIST 800-53) Security automation and scripting
Senior Vulnerability Management Analyst
System One Birmingham, Alabama
Job Description Job Description Job Title: Senior Vulnerability Management Analyst Location: Lafayette, LA, Knoxville, TN, Columbia, SC, Birmingham, AL Type: Permanent Fulltime Overview Seeking a Senior Vulnerability Management Analyst to support vulnerability governance, risk management, compliance, and remediation oversight within a large-scale financial services technology environment. This role focuses on ensuring vulnerabilities are appropriately tracked, prioritized, escalated, and remediated in accordance with established security standards, risk frameworks, and service level requirements. The analyst will work across cybersecurity, infrastructure, cloud, application, and risk teams to analyze vulnerability data, monitor remediation progress, support risk exceptions, and provide clear reporting to technology leadership. This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Columbia, SC, Birmingham, AL Responsibilities Manage vulnerability governance activities and support compliance with security policies, standards, controls, and risk frameworks. Analyze vulnerability data and remediation metrics across technology domains, including cloud and AWS based environments. Track remediation progress, aging, and SLA adherence and identify issues requiring escalation. Support vulnerability risk assessments, exception reviews, and risk acceptance processes. Monitor control effectiveness and identify recurring vulnerabilities, systemic risks, and remediation gaps. Prepare vulnerability metrics, trends, dashboards, and governance reporting for leadership and other stakeholders. Maintain vulnerability management standards, procedures, guidelines, and supporting documentation. Document process flows, remediation workflows, escalation paths, and governance processes. Maintain evidence and documentation supporting control validation, audits, regulatory reviews, and risk acceptance. Partner with technology and security teams to improve vulnerability management processes and data quality. Requirements 8+ years of experience in cybersecurity, technology risk, vulnerability management, or a closely related field. Strong experience with vulnerability management and vulnerability remediation governance in a large enterprise environment. Working knowledge of vulnerability management across AWS/cloud environments, infrastructure, applications, and related technology platforms. Experience tracking vulnerability remediation, aging, SLA compliance, risk exceptions, and escalations. Strong understanding of cybersecurity risk management, security controls, governance, and compliance requirements. Ability to analyze large vulnerability datasets and turn findings into actionable risk and remediation reporting. Advanced Microsoft Excel skills, including pivot tables, VLOOKUP/XLOOKUP, data cleansing, reconciliation, and trend analysis. Experience developing executive or leadership level reporting and presentations using PowerPoint. Strong technical writing skills with experience maintaining security standards, procedures, guidelines, and governance documentation. Experience documenting process flows and vulnerability remediation/governance workflows. Strong attention to data accuracy and the ability to identify trends, systemic risks, and control gaps. Ability to work effectively across cybersecurity, cloud, infrastructure, application, risk, and compliance teams. Sound judgment regarding risk escalation, remediation exceptions, and issues requiring leadership attention. Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Information Technology, or a related technical field required. Ref: Pittsburgh
10/07/2026
Full time
Job Description Job Description Job Title: Senior Vulnerability Management Analyst Location: Lafayette, LA, Knoxville, TN, Columbia, SC, Birmingham, AL Type: Permanent Fulltime Overview Seeking a Senior Vulnerability Management Analyst to support vulnerability governance, risk management, compliance, and remediation oversight within a large-scale financial services technology environment. This role focuses on ensuring vulnerabilities are appropriately tracked, prioritized, escalated, and remediated in accordance with established security standards, risk frameworks, and service level requirements. The analyst will work across cybersecurity, infrastructure, cloud, application, and risk teams to analyze vulnerability data, monitor remediation progress, support risk exceptions, and provide clear reporting to technology leadership. This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Columbia, SC, Birmingham, AL Responsibilities Manage vulnerability governance activities and support compliance with security policies, standards, controls, and risk frameworks. Analyze vulnerability data and remediation metrics across technology domains, including cloud and AWS based environments. Track remediation progress, aging, and SLA adherence and identify issues requiring escalation. Support vulnerability risk assessments, exception reviews, and risk acceptance processes. Monitor control effectiveness and identify recurring vulnerabilities, systemic risks, and remediation gaps. Prepare vulnerability metrics, trends, dashboards, and governance reporting for leadership and other stakeholders. Maintain vulnerability management standards, procedures, guidelines, and supporting documentation. Document process flows, remediation workflows, escalation paths, and governance processes. Maintain evidence and documentation supporting control validation, audits, regulatory reviews, and risk acceptance. Partner with technology and security teams to improve vulnerability management processes and data quality. Requirements 8+ years of experience in cybersecurity, technology risk, vulnerability management, or a closely related field. Strong experience with vulnerability management and vulnerability remediation governance in a large enterprise environment. Working knowledge of vulnerability management across AWS/cloud environments, infrastructure, applications, and related technology platforms. Experience tracking vulnerability remediation, aging, SLA compliance, risk exceptions, and escalations. Strong understanding of cybersecurity risk management, security controls, governance, and compliance requirements. Ability to analyze large vulnerability datasets and turn findings into actionable risk and remediation reporting. Advanced Microsoft Excel skills, including pivot tables, VLOOKUP/XLOOKUP, data cleansing, reconciliation, and trend analysis. Experience developing executive or leadership level reporting and presentations using PowerPoint. Strong technical writing skills with experience maintaining security standards, procedures, guidelines, and governance documentation. Experience documenting process flows and vulnerability remediation/governance workflows. Strong attention to data accuracy and the ability to identify trends, systemic risks, and control gaps. Ability to work effectively across cybersecurity, cloud, infrastructure, application, risk, and compliance teams. Sound judgment regarding risk escalation, remediation exceptions, and issues requiring leadership attention. Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Information Technology, or a related technical field required. Ref: Pittsburgh
Senior Vulnerability Management Analyst
System One Knoxville, Tennessee
Job Description Job Description Job Title: Senior Vulnerability Management Analyst Location: Lafayette, LA, Knoxville, TN, Columbia, SC, Birmingham, AL Type: Permanent Fulltime Overview Seeking a Senior Vulnerability Management Analyst to support vulnerability governance, risk management, compliance, and remediation oversight within a large-scale financial services technology environment. This role focuses on ensuring vulnerabilities are appropriately tracked, prioritized, escalated, and remediated in accordance with established security standards, risk frameworks, and service level requirements. The analyst will work across cybersecurity, infrastructure, cloud, application, and risk teams to analyze vulnerability data, monitor remediation progress, support risk exceptions, and provide clear reporting to technology leadership. This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Columbia, SC, Birmingham, AL Responsibilities Manage vulnerability governance activities and support compliance with security policies, standards, controls, and risk frameworks. Analyze vulnerability data and remediation metrics across technology domains, including cloud and AWS based environments. Track remediation progress, aging, and SLA adherence and identify issues requiring escalation. Support vulnerability risk assessments, exception reviews, and risk acceptance processes. Monitor control effectiveness and identify recurring vulnerabilities, systemic risks, and remediation gaps. Prepare vulnerability metrics, trends, dashboards, and governance reporting for leadership and other stakeholders. Maintain vulnerability management standards, procedures, guidelines, and supporting documentation. Document process flows, remediation workflows, escalation paths, and governance processes. Maintain evidence and documentation supporting control validation, audits, regulatory reviews, and risk acceptance. Partner with technology and security teams to improve vulnerability management processes and data quality. Requirements 8+ years of experience in cybersecurity, technology risk, vulnerability management, or a closely related field. Strong experience with vulnerability management and vulnerability remediation governance in a large enterprise environment. Working knowledge of vulnerability management across AWS/cloud environments, infrastructure, applications, and related technology platforms. Experience tracking vulnerability remediation, aging, SLA compliance, risk exceptions, and escalations. Strong understanding of cybersecurity risk management, security controls, governance, and compliance requirements. Ability to analyze large vulnerability datasets and turn findings into actionable risk and remediation reporting. Advanced Microsoft Excel skills, including pivot tables, VLOOKUP/XLOOKUP, data cleansing, reconciliation, and trend analysis. Experience developing executive or leadership level reporting and presentations using PowerPoint. Strong technical writing skills with experience maintaining security standards, procedures, guidelines, and governance documentation. Experience documenting process flows and vulnerability remediation/governance workflows. Strong attention to data accuracy and the ability to identify trends, systemic risks, and control gaps. Ability to work effectively across cybersecurity, cloud, infrastructure, application, risk, and compliance teams. Sound judgment regarding risk escalation, remediation exceptions, and issues requiring leadership attention. Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Information Technology, or a related technical field required. Ref: Pittsburgh
10/07/2026
Full time
Job Description Job Description Job Title: Senior Vulnerability Management Analyst Location: Lafayette, LA, Knoxville, TN, Columbia, SC, Birmingham, AL Type: Permanent Fulltime Overview Seeking a Senior Vulnerability Management Analyst to support vulnerability governance, risk management, compliance, and remediation oversight within a large-scale financial services technology environment. This role focuses on ensuring vulnerabilities are appropriately tracked, prioritized, escalated, and remediated in accordance with established security standards, risk frameworks, and service level requirements. The analyst will work across cybersecurity, infrastructure, cloud, application, and risk teams to analyze vulnerability data, monitor remediation progress, support risk exceptions, and provide clear reporting to technology leadership. This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Columbia, SC, Birmingham, AL Responsibilities Manage vulnerability governance activities and support compliance with security policies, standards, controls, and risk frameworks. Analyze vulnerability data and remediation metrics across technology domains, including cloud and AWS based environments. Track remediation progress, aging, and SLA adherence and identify issues requiring escalation. Support vulnerability risk assessments, exception reviews, and risk acceptance processes. Monitor control effectiveness and identify recurring vulnerabilities, systemic risks, and remediation gaps. Prepare vulnerability metrics, trends, dashboards, and governance reporting for leadership and other stakeholders. Maintain vulnerability management standards, procedures, guidelines, and supporting documentation. Document process flows, remediation workflows, escalation paths, and governance processes. Maintain evidence and documentation supporting control validation, audits, regulatory reviews, and risk acceptance. Partner with technology and security teams to improve vulnerability management processes and data quality. Requirements 8+ years of experience in cybersecurity, technology risk, vulnerability management, or a closely related field. Strong experience with vulnerability management and vulnerability remediation governance in a large enterprise environment. Working knowledge of vulnerability management across AWS/cloud environments, infrastructure, applications, and related technology platforms. Experience tracking vulnerability remediation, aging, SLA compliance, risk exceptions, and escalations. Strong understanding of cybersecurity risk management, security controls, governance, and compliance requirements. Ability to analyze large vulnerability datasets and turn findings into actionable risk and remediation reporting. Advanced Microsoft Excel skills, including pivot tables, VLOOKUP/XLOOKUP, data cleansing, reconciliation, and trend analysis. Experience developing executive or leadership level reporting and presentations using PowerPoint. Strong technical writing skills with experience maintaining security standards, procedures, guidelines, and governance documentation. Experience documenting process flows and vulnerability remediation/governance workflows. Strong attention to data accuracy and the ability to identify trends, systemic risks, and control gaps. Ability to work effectively across cybersecurity, cloud, infrastructure, application, risk, and compliance teams. Sound judgment regarding risk escalation, remediation exceptions, and issues requiring leadership attention. Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Information Technology, or a related technical field required. Ref: Pittsburgh
Technical Program Analyst - Security, Risk & Compliance
Visa Austin, Texas
About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description Visa's Corporate IT organization is made up of several teams that all work towards the same goal: To build, operate, and maintain the IT systems and infrastructure necessary to enable a highly connected and collaborative workforce that helps power Visa's business. With our mission in mind, we work to ensure the world is connected through the most advanced and innovative digital payment network that enables individuals, businesses, and economies to thrive. We prioritize delightful user experiences. We do not take orders, rather, we build deep partnerships with our business partners and champion proactive new ways technology can advance our business into the future. The Security, Risk and Compliance Analyst role resides on the Corporate IT (CIT) Business Operations team and directly supports Visa's Chief Information Officer (CIO) and the CIT leadership team. The team is responsible for governance and adherence to Visa corporate cyber security requirements and running point on all internal/external audit and compliance requests, with oversight for all CIT-owned applications. The position requires a program management professional with the ability to seamlessly flex between the strategic and the tactical. This role requires attention to detail and analytical rigor, as well as the ability to synthesize and streamline information for executive reporting. You'll interact with a wide range of stakeholders both within CIT and with cross-functional teams, including Cyber Security, Risk, Compliance, Audit, as well as senior leadership. Essential Functions: Assist with critical security administration functions to protect Visa from vulnerabilities, including data analysis and research across systems, tracking and reporting activities. Partner closely with technology delivery partners and cyber security, in collaboration with CIT senior leadership, to support the overall Visa and CIT organizational goals and needs. Build processes that meet CITs business objectives and ensure compliance and completeness. As a change agent, discover opportunities for process improvements, pilot and then drive on a larger scale. Assist with executive reporting and operational technology metrics focusing on continuous improvement to maximize decision making and executive visibility. Program management and delivery of special CIO projects, as identified, to support security administration functions and processes. Guide CIT through compliance reviews and audit examinations, acting as a quarter-back to retrieve and package information from relevant experts, to ensure timely responses to internal partners and external regulators. Support rapid onboarding activities of solutions identified as critical for CIT. Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager. Qualifications Basic Qualifications: 2+ years of relevant work experience and a Bachelors degree, OR 5+ years of relevant work experience. Masters graduates must have 2+ years of relevant work experience to qualify. Excellent verbal, written, and presentation skills with strong attention to detail Demonstrated ability to effectively communicate technical and business issues and solutions to multiple organizational levels Highly proficient in Microsoft Office suite, including Excel and PowerPoint Strong organization skills, ability to multi-task, show initiative and work aggressively to meet deadlines Preferred Qualifications: Experience managing technically complex, cross-organizational, multi-stakeholder initiatives Highly proficient in Microsoft Office suite, including Excel and PowerPoint Summarizing and communicating key financial information and business strategy at an executive level Good judgment, strong common sense, and excellent attention to detail Ability to work independently with strong time management and ability to execute on multiple concurrent deliverables Proactive and solution-oriented, solid analytical and problem-solving skills, ability to think strategically Certifications in cyber security or related, meaningful experience in cyber security or vulnerability management, meaningful experience in compliance, risk, or audit roles Demonstrated flexibility and adaptability to changes in priorities, work demands, roles and responsibilities Demonstrated understanding of corporate protocol, maintaining a high level of discretion and confidentiality Experience with managing information and access within SharePoint, Tableau, other databases Strong process orientation and demonstrated knowledge of project management techniques, methodologies, and best practices Information for US Applicants For roles located in the US, the estimated salary range for this position is $104,600.00 to $ 162,300.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. Work Hours Varies upon the needs of the department. Travel Requirements This position requires travel 5-10% of the time. Mental/Physical Requirements This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.
10/07/2026
Full time
About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description Visa's Corporate IT organization is made up of several teams that all work towards the same goal: To build, operate, and maintain the IT systems and infrastructure necessary to enable a highly connected and collaborative workforce that helps power Visa's business. With our mission in mind, we work to ensure the world is connected through the most advanced and innovative digital payment network that enables individuals, businesses, and economies to thrive. We prioritize delightful user experiences. We do not take orders, rather, we build deep partnerships with our business partners and champion proactive new ways technology can advance our business into the future. The Security, Risk and Compliance Analyst role resides on the Corporate IT (CIT) Business Operations team and directly supports Visa's Chief Information Officer (CIO) and the CIT leadership team. The team is responsible for governance and adherence to Visa corporate cyber security requirements and running point on all internal/external audit and compliance requests, with oversight for all CIT-owned applications. The position requires a program management professional with the ability to seamlessly flex between the strategic and the tactical. This role requires attention to detail and analytical rigor, as well as the ability to synthesize and streamline information for executive reporting. You'll interact with a wide range of stakeholders both within CIT and with cross-functional teams, including Cyber Security, Risk, Compliance, Audit, as well as senior leadership. Essential Functions: Assist with critical security administration functions to protect Visa from vulnerabilities, including data analysis and research across systems, tracking and reporting activities. Partner closely with technology delivery partners and cyber security, in collaboration with CIT senior leadership, to support the overall Visa and CIT organizational goals and needs. Build processes that meet CITs business objectives and ensure compliance and completeness. As a change agent, discover opportunities for process improvements, pilot and then drive on a larger scale. Assist with executive reporting and operational technology metrics focusing on continuous improvement to maximize decision making and executive visibility. Program management and delivery of special CIO projects, as identified, to support security administration functions and processes. Guide CIT through compliance reviews and audit examinations, acting as a quarter-back to retrieve and package information from relevant experts, to ensure timely responses to internal partners and external regulators. Support rapid onboarding activities of solutions identified as critical for CIT. Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager. Qualifications Basic Qualifications: 2+ years of relevant work experience and a Bachelors degree, OR 5+ years of relevant work experience. Masters graduates must have 2+ years of relevant work experience to qualify. Excellent verbal, written, and presentation skills with strong attention to detail Demonstrated ability to effectively communicate technical and business issues and solutions to multiple organizational levels Highly proficient in Microsoft Office suite, including Excel and PowerPoint Strong organization skills, ability to multi-task, show initiative and work aggressively to meet deadlines Preferred Qualifications: Experience managing technically complex, cross-organizational, multi-stakeholder initiatives Highly proficient in Microsoft Office suite, including Excel and PowerPoint Summarizing and communicating key financial information and business strategy at an executive level Good judgment, strong common sense, and excellent attention to detail Ability to work independently with strong time management and ability to execute on multiple concurrent deliverables Proactive and solution-oriented, solid analytical and problem-solving skills, ability to think strategically Certifications in cyber security or related, meaningful experience in cyber security or vulnerability management, meaningful experience in compliance, risk, or audit roles Demonstrated flexibility and adaptability to changes in priorities, work demands, roles and responsibilities Demonstrated understanding of corporate protocol, maintaining a high level of discretion and confidentiality Experience with managing information and access within SharePoint, Tableau, other databases Strong process orientation and demonstrated knowledge of project management techniques, methodologies, and best practices Information for US Applicants For roles located in the US, the estimated salary range for this position is $104,600.00 to $ 162,300.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. Work Hours Varies upon the needs of the department. Travel Requirements This position requires travel 5-10% of the time. Mental/Physical Requirements This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.
Senior Cybersecurity Operations Engineer
GovCIO LLC Colorado Springs, Colorado
GovCIO LLC seeks a Senior CSOC Support Engineer to bolster cybersecurity operations for federal customers. In this role, you'll support a 24x7 Cyber Security Operations Center by managing and tuning SIEM and security tools, integrating new data sources, and improving alert fidelity. You'll troubleshoot complex issues, guide junior analysts, and collaborate with engineers to refine detection use cases and automation. You'll also document playbooks, liaise with government stakeholders, and help drive continuous improvements that strengthen mission-critical federal networks and systems against evolving cyber threats. Responsibilities Support and enhance tools and workflows for a 24x7 Cyber Security Operations Center (CSOC). Administer, tune, and integrate SIEM and other security platforms to improve alert quality. Troubleshoot complex security tooling and data ingestion issues. Develop and maintain detection content, runbooks, and standard operating procedures. Collaborate with analysts, engineers, and government stakeholders on incident handling and improvements. Mentor junior CSOC staff on tools, processes, and best practices. Monitor system health and performance of security infrastructure. Support automation initiatives to streamline triage and response activities. Required Skills Cybersecurity operations SIEM tools (Splunk/Elastic/etc.) IDS/IPS management Incident detection and triage Linux/Windows administration Network security and TCP/IPSecurity automation and scripting Vulnerability management Ticketing and ITSM tools Documentation and reporting
10/05/2026
Full time
GovCIO LLC seeks a Senior CSOC Support Engineer to bolster cybersecurity operations for federal customers. In this role, you'll support a 24x7 Cyber Security Operations Center by managing and tuning SIEM and security tools, integrating new data sources, and improving alert fidelity. You'll troubleshoot complex issues, guide junior analysts, and collaborate with engineers to refine detection use cases and automation. You'll also document playbooks, liaise with government stakeholders, and help drive continuous improvements that strengthen mission-critical federal networks and systems against evolving cyber threats. Responsibilities Support and enhance tools and workflows for a 24x7 Cyber Security Operations Center (CSOC). Administer, tune, and integrate SIEM and other security platforms to improve alert quality. Troubleshoot complex security tooling and data ingestion issues. Develop and maintain detection content, runbooks, and standard operating procedures. Collaborate with analysts, engineers, and government stakeholders on incident handling and improvements. Mentor junior CSOC staff on tools, processes, and best practices. Monitor system health and performance of security infrastructure. Support automation initiatives to streamline triage and response activities. Required Skills Cybersecurity operations SIEM tools (Splunk/Elastic/etc.) IDS/IPS management Incident detection and triage Linux/Windows administration Network security and TCP/IPSecurity automation and scripting Vulnerability management Ticketing and ITSM tools Documentation and reporting
Senior Cloud Security Assessor
Spry Methods Washington, Washington DC
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/26/2026
Full time
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board