Назад
Company hidden
12 часов назад

GRC, Vulnerability Management Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC, Vulnerability Management Analyst (Cybersecurity): Governing an enterprise vulnerability management program by tracking remediation, managing risk exceptions, and producing executive reporting with an accent on risk-based prioritization, compliance, and accountability. Focus on analyzing vulnerability trends, escalating unresolved risks, and improving governance workflows across infrastructure, cloud, application, and business teams.

Location: On-site in Atlanta, Georgia, United States

Company

hirify.global is a global fintech company providing insurance, reinsurance, payroll, benefits, cybersecurity, mortgage, and related solutions.

What you will do

  • Govern the enterprise Vulnerability Management Program in alignment with cybersecurity policies, standards, and risk requirements.
  • Track vulnerabilities through identification, remediation, mitigation, risk acceptance, and closure.
  • Coordinate remediation ownership, prioritization, review meetings, and risk-based timelines across technical and business stakeholders.
  • Manage vulnerability exceptions, risk acceptances, compensating controls, remediation extensions, and escalations.
  • Develop dashboards, scorecards, KPIs, and executive reports covering SLA compliance, vulnerability aging, exceptions, and closure rates.
  • Support audits, regulatory examinations, governance documentation, continuous improvement, and program roadmaps.

Requirements

  • Bachelor’s degree in cybersecurity, information security, information technology, risk management, business administration, or a related field.
  • 3+ years of experience in cybersecurity governance, risk management, compliance, audit, or vulnerability management.
  • Knowledge of vulnerability management concepts, remediation workflows, vulnerability prioritization, and risk-based decision-making.
  • Understanding of NIST, CIS Controls, ISO 27001, and COBIT frameworks and standards.
  • Experience developing executive reporting, metrics, dashboards, and performance indicators.
  • Strong analytical, communication, stakeholder management, and cross-functional coordination skills.

Nice to have

  • 5+ years of experience supporting enterprise cybersecurity governance or vulnerability management programs.
  • Experience with GRC platforms such as Archer, ServiceNow, or MetricStream.
  • Familiarity with Tenable, Qualys, Rapid7, Wiz, or Microsoft Defender Vulnerability Management.
  • Experience with SOX, HIPAA, NYDFS, PCI-DSS, SOC 2, or ISO certification compliance programs.
  • CRISC, CISA, CISM, CGRC, or Security+ certification.

Culture & Benefits

  • On-site collaboration with cybersecurity, IT, infrastructure, cloud, application development, risk, and compliance teams.
  • Medical, dental, vision, life, disability, fertility, and wellness benefits.
  • Paid time off, holidays, sick time, employee assistance resources, and Calm app access.
  • 401(k) with immediate vesting, HSA, FSA, commuter benefits, and employee discounts.
  • Paid maternity and paternity leave, legal plan options, and pet insurance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →