Skip to content
← Back to job listings

Vulnerability Analyst

Fa Etvl Saasfaprod1 · Remote, Uttar Pradesh, India

CybersecurityRemoteExternal listingfull-timeabout 1 hour ago

About The Role

  • The Endpoint Vulnerability Analyst supports endpoint vulnerability remediation efforts across enterprise endpoint environments. This role executes the vulnerability remediation lifecycle for assigned work—triage, risk-based prioritization, root-cause analysis, solution validation, deployment coordination, and reporting—partnering with security, operations, engineering, and application teams. The ideal candidate demonstrates endpoint technical depth, works independently on complex issues, contributes to automation and process improvements, and supports governance activities (SLAs, exception handling, and risk reporting) that improve the firm’s overall risk posture.

-

  • Key Responsibilities
  • Monitor and analyze endpoint vulnerability findings using Tenable/Nessus
  • Assess findings to determine business impact, root cause, and remediation requirements
  • Apply risk-based prioritization aligned to vulnerability severity, exploitability, asset criticality, and remediation SLAs
  • Coordinate endpoint remediation activities, including:
  • Windows and macOS updates and configuration changes
  • Patch management activities (OS and third-party applications)
  • Application and browser updates and configuration changes
  • Driver, firmware, and UEFI/BIOS updates
  • Removal, upgrade, or retirement of outdated applications
  • Develop, test, and troubleshoot PowerShell scripts to support remediation and automation
  • Partner with testing teams to validate remediation solutions prior to deployment
  • Create and manage ServiceNow incidents/requests and change records; support the change management process
  • Coordinate remediation execution with cross-functional teams (testing, deployment, operations, policy, and application owners)
  • Provide endpoint troubleshooting support related to vulnerabilities and remediation deployments
  • Facilitate meetings with internal teams (and business partners, as needed) to drive timely vulnerability resolution
  • Maintain remediation tracking data (task lists, status, owners, and timelines)
  • Prepare regular status reporting on remediation progress, exceptions, and outstanding risk
  • Support remediation exceptions and risk acceptance/waiver workflows; ensure documentation and approvals meet governance requirements
  • Produce and communicate vulnerability remediation metrics (e.g., aging, SLA attainment, recurrence) and provide insights to support decision-making
  • Prioritize and manage multiple concurrent remediation efforts in a deadline-driven environment
  • Follow established security, operational, and documentation standards; document work performed and outcomes
  • Build strong working relationships with partner teams to ensure consistent remediation outcomes
  • Identify recurring remediation gaps and contribute to process improvements (standard operating procedures, playbooks, automation) to reduce repeat vulnerabilities

-

  • Required Skills
  • 5+ years of experience in endpoint engineering/operations, vulnerability management, patch management, or a closely related discipline
  • Experience supporting Windows and macOS endpoints in an enterprise environment
  • Experience with vulnerability scanning and reporting tools (e.g., Tenable/Nessus)
  • Experience with endpoint security, patching, or vulnerability remediation processes
  • PowerShell scripting skills (writing, testing, troubleshooting, or modifying scripts)
  • Proficiency with Microsoft 365 tools (Excel, PowerPoint, Word) for tracking and communication
  • Experience using ServiceNow for ticketing and change management
  • Experience with remote support and troubleshooting tools (BeyondTrust preferred)
  • Working knowledge of Microsoft Intune (device management and policy)

-

  • Additional Required Qualifications
  • Demonstrated ability to influence cross-functional partners and drive work to completion without direct authority
  • Demonstrated organization and time-management skills
  • Ability to manage multiple priorities and deliver results with minimal supervision
  • Strong written and verbal communication skills, including status reporting
  • Ability to partner with technical and non-technical stakeholders to drive outcomes
  • Growth mindset with a willingness to learn new tools, technologies, and security practices

-

  • Preferred Qualifications
  • Relevant certifications (e.g., Security+, CISSP, GIAC) and/or ITIL foundation

-

This is an external listing. JobSpring does not represent or verify the employer. Report this listing