freehire launches on Product Hunt on 26 August.

Follow →

Vulnerability Management Analyst

Summary

Run vulnerability scans on Windows servers and workstations, validate findings, prioritize fixes, and coordinate remediation with IT teams to reduce security risks.

  • Manage and support enterprise vulnerability management activities across Windows Server and Windows workstation environments.
  • Perform regular vulnerability assessments using approved scanning tools (e.g., Qualys, Tenable, Rapid7, Microsoft Defender Vulnerability Management).
  • Analyze vulnerability scan results, validate findings, and prioritize remediation activities based on risk, severity, and business impact.
  • Coordinate with infrastructure, server, desktop, application, and security teams to ensure timely remediation of identified vulnerabilities.
  • Track, monitor, and report vulnerability remediation progress against organizational SLAs and compliance requirements.
  • Lead monthly vulnerability review meetings and provide recommendations for risk reduction.
  • Investigate and resolve false positives, exception requests, and vulnerability-related operational issues.
  • Support security audits, regulatory compliance assessments, and internal governance requirements.
  • Develop remediation plans for critical and high-risk vulnerabilities affecting Windows operating systems and Microsoft technologies.
  • Work closely with SCCM/MECM, Intune, and Windows Operations teams to ensure effective patch deployment and compliance management.
  • Monitor emerging security threats, vulnerabilities, and vendor advisories affecting Microsoft platforms.
  • Perform root cause analysis for recurring vulnerabilities and recommend preventive controls.
  • Create and maintain vulnerability management procedures, remediation runbooks, and technical documentation.
  • Generate executive dashboards, compliance reports, remediation metrics, and risk-based reporting for leadership teams.
  • Support vulnerability remediation projects, security initiatives, and continuous improvement activities.
  • Participate in incident response activities related to security vulnerabilities, malware outbreaks, and zero-day threats.

Education

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field.

Experience

  • 3-7 years of experience in Vulnerability Management, Windows Infrastructure, Cybersecurity Operations, or Endpoint Security.
  • Hands-on experience managing vulnerabilities in enterprise Windows Server and Windows desktop environments.
  • Experience working with vulnerability scanning and assessment tools such as Qualys, Tenable, Rapid7, or Microsoft Defender Vulnerability Management.
  • Experience coordinating remediation activities across multiple technology teams.
  • Strong understanding of patch management, security compliance, and risk management processes.

Technical Skills

  • Strong knowledge of Windows Server and Windows 10/11 operating systems.
  • Experience with vulnerability assessment, risk prioritization, and remediation tracking.
  • Familiarity with Microsoft Defender for Endpoint and Defender Vulnerability Management.
  • Experience with SCCM/MECM, Microsoft Intune, and Windows patch management processes.
  • Knowledge of Active Directory, Group Policy, Entra ID (Azure AD), DNS, DHCP, and Windows security configurations.
  • Understanding of CVSS scoring, Common Vulnerabilities and Exposures (CVE), and security risk assessment methodologies.
  • Experience reviewing security advisories from Microsoft and other vendors.
  • Familiarity with security hardening standards and frameworks such as CIS Benchmarks, NIST, and ISO 27001.
  • Basic scripting knowledge using PowerShell for automation, reporting, and remediation activities.
  • Understanding of endpoint security, malware protection, and vulnerability lifecycle management.

Preferred Qualifications

  • Microsoft Security, Compliance, and Identity certifications.
  • CompTIA Security+, CySA+, or equivalent cybersecurity certification.
  • Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) (preferred but not mandatory).
  • ITIL Foundation certification.
  • Experience with cloud security and Azure-based environments.

Key Competencies

  • Strong analytical and problem-solving skills.
  • Risk-based decision-making and prioritization capabilities.
  • Effective stakeholder management and cross-functional collaboration.
  • Strong reporting and presentation skills.
  • Attention to detail and commitment to security best practices.
  • Ability to manage multiple remediation activities in a fast-paced enterprise environment.
  • Proactive mindset with a focus on continuous improvement and security posture enhancement.

See also