freehire launches on Product Hunt on 26 August.

Follow →

Security Analyst

Summary

Own the end-to-end vulnerability management process, triage security findings, coordinate penetration tests, and drive remediation to closure while reporting risk posture to stakeholders.

Key Responsibilities

Vulnerability Management

• Own and manage the end-to-end Vulnerability Management process, including intake, triage, and lifecycle tracking of security findings across the organization's systems and assets.

• Classify vulnerabilities by severity, exploitability, and business impact using frameworks such as CVSS, EPSS, and internal risk criteria.

• Plan, coordinate, and manage Quarterly Vulnerability Assessments — scoping targets, engaging scanning tools, reviewing outputs, and driving findings through to resolution.

• Manage the Yearly Penetration Testing cycle, including scoping, vendor coordination, findings review, and tracking remediation commitments through to closure.

• Track key remediation implementations end-to-end, maintaining visibility from initial detection through to verified closure — for example, overseeing the transition of WAF rules from detection mode to prevention mode, ensuring each step is documented, tested, and signed off.

• Coordinate with remediation teams (engineering, DevOps, infrastructure) to ensure timely resolution of findings, providing clear context and prioritization guidance.

• Maintain and update risk acceptance records, ensuring appropriate approvals are obtained, documented, and reviewed on schedule.

• Track and report on remediation SLAs, escalating overdue or high-risk items to the appropriate stakeholders.

• Produce regular status reports and dashboards that communicate the project's overall security posture to technical and non-technical audiences.

Security Visibility & Reporting

• Aggregate vulnerability data from multiple scanning tools and sources into a coherent, unified view of security risk.

• Develop and maintain metrics and KPIs that enable leadership visibility into ongoing security exposure and program effectiveness.

• Present findings, trends, and recommendations in written reports, executive briefings, and team meetings.

Collaboration & Process Improvement

• Act as a liaison between the security team and remediation owners, facilitating communication and removing blockers to resolution.

• Continuously improve vulnerability management workflows, tooling, and documentation.

• Support audit and compliance activities by providing evidence of vulnerability tracking and risk treatment processes.

• Contribute to threat intelligence efforts and stay current on emerging CVEs and attack trends relevant to the organization.

Qualifications Required

• 2+ years of experience in an information security, vulnerability management, or related role.

• Hands-on experience with vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7, Wiz, or similar).

• Solid understanding of CVSS scoring, vulnerability classification, and risk-based prioritization.

• Experience communicating security findings and risk to both technical teams and business stakeholders.

• Familiarity with common compliance and risk frameworks (e.g., NIST CSF, ISO 27001, SOC 2).

• Familiarity with GovTech's IM8 (Instruction Manual 8) policies and its associated risk-based assessment methodology, including the application of controls, classification of government ICT systems, and conducting or supporting IM8-aligned security reviews.

• Strong organizational skills with the ability to manage multiple workstreams and deadlines simultaneously.

Preferred

• Relevant certifications such as CompTIA Security+, CEH, GWAPT, or equivalent.

• Experience with ticketing and workflow tools (e.g., Jira, ServiceNow) for tracking remediation.

• Scripting or automation skills (Python, Bash) to support data aggregation and reporting workflows.

• Background in cloud security environments (AWS, Azure, GCP).

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available