- Company Name
- Aylo
- Job Title
- Infrastructure Security Analyst - Vulnerability Management
- Job Description
-
**Job Title:**
Infrastructure Security Analyst – Vulnerability Management
**Role Summary:**
Identify, assess, and remediate security vulnerabilities across cloud and on‑premises infrastructure. Strengthen vulnerability management processes, coordinate patching, and communicate findings to technical and non‑technical stakeholders.
**Expectations:**
Consistently perform vulnerability assessments, prioritize findings using industry frameworks, and drive remediation. Collaborate with IT, development, and infra teams to implement scalable solutions. Deliver clear reports and maintain compliance with internal and regulatory standards.
**Key Responsibilities:**
- Conduct routine scans with Qualys, Nessus, Rapid7, and other tools.
- Analyze and prioritize vulnerabilities using CVSS, NIST, OWASP, and other frameworks.
- Develop and implement remediation plans with IT, dev, and infra teams.
- Produce detailed technical and executive‑friendly reporting.
- Coordinate patching and updates for critical systems and applications.
- Use ticketing systems (ServiceNow, JIRA) for tracking and reporting.
- Monitor emerging threats and vulnerabilities to proactively identify risks.
- Improve vulnerability management processes for efficiency and effectiveness.
- Ensure alignment with internal policies, regulatory requirements, and best practices.
**Required Skills:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- 3–5 years of cybersecurity or IT security experience focused on vulnerability management.
- Hands‑on use of vulnerability scanning tools (Qualys, Tenable, Nessus, Rapid7).
- Experience with cloud environments (AWS, Azure, GCP) and container security.
- Scripting proficiency (Python, PowerShell) for automation.
- Familiarity with CNAPP tools (Wiz, Prisma Cloud).
- Strong knowledge of vulnerability management, risk assessment, and patch management.
- Proficiency with ticketing systems (ServiceNow, JIRA).
- Excellent written and verbal communication; ability to present technical findings to non‑technical stakeholders.
- Ability to work independently and collaboratively in a fast‑paced environment.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).
- Certifications such as CompTIA Security+, CEH, GCIH, or relevant vendor certifications (e.g., Qualys Certified Security Analyst) preferred.