Vulnerability Management Analyst - Remote (Required candidates from Payment and card industry

Job Role: Vulnerability Management Analyst<br><br>Location: 100% Remote<br><br>Long Term Contract<br><br><strong>Job Description<br><br></strong>Note - Looking for the candidates from Payment and card industry<br><br>Pay rate is $50/hr.<br><br>Key Responsibilities<br><br>Validate and triage vulnerability findings from internal scans, external scans, attack surface management sources, and threat intelligence, including scope validation, ownership attribution, and exposure assessment.<br><br>Assess severity, exploitability, exposure, business impact, compensating controls, and residual risk to support risk-based prioritization across infrastructure, cloud, container, endpoint, network, and externally exposed environments.<br><br>Engage technology stakeholders and remediation owners throughout the vulnerability lifecycle, from identification and owner routing through remediation treatment, progress tracking, closure validation, and risk-based escalation.<br><br>Support rapid response for vulnerability threat intelligence escalations and PatchNow Critical events through scope analysis, owner routing, remediation treatment, tracking, and closure verification.<br><br>Work with vulnerability management, scanning, reporting, external exposure, and risk prioritization tools to validate data, investigate discrepancies, confirm asset context, and compress operational response times.<br><br>Identify recurring risk patterns, workflow friction, and data quality issues; recommend practical improvements to processes, tooling, automation, and reporting that improve remediation outcomes and operational consistency.<br><br><strong>Required Qualifications<br><br></strong>3+ years of demonstrated experience in vulnerability management in enterprise class environments.<br><br>Experience with vulnerability management across cloud and container environments and supporting enterprise tools.<br><br>Strong understanding of vulnerability management lifecycle activities, including identification, validation, prioritization, remediation coordination, risk treatment awareness, and closure verification.<br><br>Experience working with large datasets, vulnerability reports, asset information, and operational metrics to identify trends, discrepancies, and actionable insights.<br><br>Strong written and verbal communication skills, with the ability to translate technical vulnerability findings into clear remediation guidance, risk summaries, and prioritization recommendations for technical and non-technical stakeholders.<br><br>Working knowledge of common enterprise technology environments, including servers, endpoints, network infrastructure, cloud platforms, containerized workloads, and container image lifecycle management.<br><br><strong>Preferred Qualifications<br><br></strong>Experience in financial services, regulated environments, or organizations with formal technology risk, audit, compliance, and vulnerability management regulatory requirements (PCI DSS, FFIEC).<br><br>Scripting, automation, API, and data analysis experience using tools or languages such as Python, PowerShell, VBA, Power Query, SQL, R, or similar.<br><br>Experience with business intelligence, reporting, or analytics tools such as Power BI and Excel for validating reports, analyzing trends, and communicating actionable insights.<br><br>Practical familiarity with AI-enabled productivity or analysis tools, coding assistants, prompt-based workflows, or tool orchestration in a professional setting.<br><br>Relevant security or technology certifications such as Security+, CySA+, CISSP, cloud security certifications, vulnerability management vendor certifications, or equivalent practical experience.<br><br><strong>Tools And Environment (Preferred)<br><br></strong>Vulnerability management and scanning platforms such as Qualys, Wiz, or comparable enterprise vulnerability management tools.<br><br>External attack surface management tools, exposure monitoring platforms, and internet-facing asset discovery workflows.<br><br>Cloud and container environments, including AWS, Azure, GCP, Kubernetes, container image lifecycle management, and cloud workload security fundamentals.

Back to blog