Sr Cyber Security Analyst- Vulnerability Management
McKinney, TX - USA
Job Summary
Position Purpose:
The Senior Cyber Security Analyst at the company will serve as a senior hands-on technical resource within Cyber Security Operations with primary responsibility for enterprise Vulnerability Management and secondary responsibility for supporting Cyber Operations activities associated with mergers and acquisitions. This role is responsible for identifying validating prioritizing tracking and helping drive remediation of vulnerabilities across
the enterprise.
The Senior Cyber Security Analyst will work extensively with vulnerability and exposure management technologies such as Wiz CrowdStrike Rapid7 and Nagomi to improve visibility prioritize risk validate findings and measure reduction of security exposure. The position will also provide hands-on technical support during mergers and acquisitions by assessing acquired environments identifying vulnerabilities and cybersecurity gaps onboarding assets into established security processes validating remediation activities and helping transition acquired environments into standard Cyber Operations practices.
The Senior Cyber Security Analyst will report directly to the Cyber Security Operations Manager and will receive technical direction and engineering guidance from the Cybersecurity Staff Engineer.
Key Responsibilities:
- Serve as a senior hands-on technical resource for the enterprise Vulnerability Management program supporting vulnerability identification validation prioritization remediation and closure.
- Administer maintain optimize and support Vulnerability Management and exposure management technologies including Wiz CrowdStrike Rapid7 Nagomi and related platforms.
- Perform vulnerability assessments across enterprise technology environments including servers workstations network devices cloud-hosted assets applications and other technology assets.
- Analyze and validate vulnerability findings to reduce false positives and ensure remediation efforts are focused on legitimate cybersecurity risk.
- Prioritize vulnerabilities using risk-based factors such as vulnerability severity known exploitation internet accessibility asset criticality business impact threat intelligence exploitability compensating controls and exposure paths.
- Identify and prioritize vulnerabilities associated with active exploitation zero-day vulnerabilities CISA Known Exploited Vulnerabilities emerging threats and other high-risk security conditions.
- Coordinate with Infrastructure Network Cloud Application and other technology teams to drive vulnerability remediation activities through completion.
- Track vulnerabilities throughout the full lifecycle including identification validation remediation mitigation exception risk acceptance and closure.
- Perform technical validation following remediation to confirm vulnerabilities and exposures have been successfully addressed.
- Identify recurring vulnerabilities systemic weaknesses and remediation challenges and recommend technical or process improvements.
- Develop and maintain Vulnerability Management procedures standards runbooks dashboards operational documentation and reporting.
- Support vulnerability exception and risk acceptance processes by providing technical analysis exposure information and compensating-control considerations.
- Perform vulnerability trend analysis and identify areas of increasing enterprise risk or recurring exposure.
- Serve as a primary hands-on technical resource for Nagomi supporting integrations exposure analysis security control validation and risk-based prioritization.
- Correlate vulnerability data asset context threat intelligence and control information within Nagomi to improve remediation prioritization and identify areas of security exposure.
- Analyze Nagomi findings to identify control gaps vulnerabilities security configuration issues and opportunities to reduce enterprise exposure.
- Develop vulnerability and exposure metrics that demonstrate remediation progress vulnerability aging recurring risk coverage and measurable reduction of security exposure.
- Serve as a hands-on Cyber Operations resource supporting mergers acquisitions and business integrations.
- Execute assigned Cyber Operations activities during M&A discovery assessment onboarding and integration efforts.
- Perform technical security discovery and vulnerability assessments within acquired environments to identify cybersecurity risks vulnerabilities unmanaged assets unsupported technologies security configuration weaknesses and technical debt.
- Establish an initial vulnerability and exposure baseline for acquired environments.
- Assist with onboarding acquired assets into enterprise Vulnerability Management and exposure management technologies and processes.
- Perform vulnerability scans technical assessments validation activities and follow-up testing required during acquisition integration.
- Analyze M&A security findings and provide actionable remediation recommendations to the appropriate technology teams.
- Validate patches configuration changes mitigations and other corrective actions implemented during M&A remediation efforts.
- Track assigned M&A cybersecurity findings and Cyber Operations activities through completion.
- Work closely with Infrastructure Network Cloud Application Identity GRC and other technology teams to complete assigned cybersecurity integration activities.
- Assist with transitioning acquired environments into established Vulnerability Management processes remediation workflows reporting standards and Cyber Operations practices.
- Support automation API integrations reporting and workflow improvements that increase the efficiency and scalability of Vulnerability Management activities.
Direct Manager Direct Reports:
- The Senior Cyber Security Engineer will report directly to the Cyber Security Operations Manager.
- This role does not have any direct reports.
- The Senior Cyber security Engineer will receive technical direction eguidance standards and technical prioritization from the Cybersecurity Staff Analyst.
- The position will work closely with Cyber Security Operations Cyber Engineering Infrastructure Network Cloud Application Identity GRC and other technology teams to drive vulnerability remediation and support M&A Cyber Operations activities.
Travel Requirements:
- The Senior Cyber Security Engineer may be required to travel occasionally to support mergers and acquisitions cybersecurity assessments acquired-company integration activities technical meetings or other business requirements.
- Travel may include visits to acquired organizations branch locations data centers offices or other company facilities as needed to support hands-on Cyber Operations activities.
Physical Requirements:
- The Senior Cyber Security Engineer position involves working in a standard office environment with duties requiring extended periods of sitting standing and computer use.
- The role requires the ability to communicate effectively with technical teams business partners leadership and other stakeholders both verbally and in written form.
- Occasional travel may be necessary to attend meetings assessments site visits or M&A integration activities.
- The company is committed to the principles of the Americans with Disabilities Act (ADA) and will provide reasonable accommodations to enable individuals with disabilities to perform the essential functions of this role effectively. Candidates seeking accommodations are encouraged to reach out to our HR department to discuss how we can support your application and work environment needs.
Working Conditions:
- The Senior Cyber Security Engineer role is designed to operate within a hybrid work environment blending both in-office and remote work arrangements to support flexibility collaboration and productivity.
- The position operates in a fast-paced Cyber Security Operations environment where priorities may shift based on vulnerability severity emerging threats active exploitation business risk mergers and acquisitions and remediation requirements.
- The role requires the ability to independently manage multiple technical priorities while maintaining strong communication and coordination with Cyber Security IT and business stakeholders.
- The Senior Cyber Security Engineer is expected to work collaboratively with technical teams to drive measurable reduction in enterprise vulnerability exposure and support the secure integration of acquired environments.
Minimum Qualifications:
- Bachelors degree in Cybersecurity Information Security Computer Science Information Technology Engineering or a related technical field from an accredited institution or equivalent combination of education and professional experience.
- At least 5 years of progressive experience in Cybersecurity Vulnerability Management Security Engineering Cyber Security Operations or a related technical discipline.
- Strong hands-on experience with enterprise Vulnerability Management technologies and processes.
- Demonstrated experience using vulnerability or exposure management technologies such as Wiz CrowdStrike Rapid7 Nagomi or comparable platforms.
- Strong understanding of vulnerability identification validation prioritization remediation mitigation exception handling and closure.
- Strong knowledge of CVE CVSS CISA Known Exploited Vulnerabilities EPSS threat intelligence exploitability and risk-based vulnerability prioritization.
- Experience assessing vulnerabilities across Windows Linux network cloud-hosted application and enterprise infrastructure environments.
- Demonstrated ability to analyze vulnerability findings across multiple data sources and determine appropriate remediation or mitigation actions.
- Experience working with Infrastructure Network Cloud Application and other technology teams to drive vulnerability remediation through completion.
- Strong analytical and problem-solving skills with the ability to distinguish technical severity from actual organizational risk.
- Experience developing vulnerability reporting dashboards remediation metrics technical documentation procedures and operational standards.
- Strong written and verbal communication skills with the ability to communicate technical risks and remediation requirements to both technical and non-technical stakeholders.
- Demonstrated ability to independently manage multiple priorities and technical workstreams within a fast-paced Cyber Security Operations environment.
Preferred Qualifications:
- Hands-on experience supporting cybersecurity activities associated with mergers acquisitions divestitures or large-scale technology integrations.
- Experience performing technical vulnerability assessments of newly acquired environments.
- Experience establishing vulnerability and exposure baselines for acquired or newly integrated organizations.
- Experience onboarding acquired assets into enterprise Vulnerability Management technologies and processes.
- Advanced experience with Wiz CrowdStrike vulnerability capabilities Rapid7 Nagomi or similar vulnerability and exposure management technologies.
- Experience with attack surface analysis exposure management security control validation and risk-based vulnerability prioritization.
- Experience using APIs scripting or automation to integrate security technologies automate vulnerability workflows or improve reporting capabilities.
- Experience developing and maintaining vulnerability dashboards executive reporting remediation metrics and operational performance indicators.
- Experience working within a large distributed enterprise containing multiple business units locations technology platforms and acquired organizations.
- Strong understanding of enterprise vulnerability remediation processes including patching configuration management mitigation exceptions and risk acceptance.
- Experience identifying systemic vulnerability patterns and recommending long-term engineering or process improvements.
- Relevant cybersecurity certifications are preferred.
Minimum Education:
- A Bachelors degree in Cybersecurity Information Security Computer Science Information Technology Engineering or a related technical field is preferred. Equivalent professional experience may be considered in lieu of a degree.
Preferred Education:
- A Bachelors or Masters degree in Cybersecurity Information Security Computer Science Information Technology Engineering or a related technical discipline is preferred.
Minimum Years Of Work Experience:
- 5 years of progressive experience in Cybersecurity Vulnerability Management Security Engineering Cyber Security Operations or a related technical discipline.
Certifications:
- Preferred: Certified Information Systems Security Professional (CISSP).
- Preferred: GIAC Security Essentials (GSEC) GIAC Certified Incident Handler (GCIH) or other relevant GIAC certification.
- Preferred: CompTIA Security or CySA.
- Preferred: Vendor-specific certifications related to vulnerability management exposure management cloud security or security operations technologies.
Competencies:
1. Vulnerability Management Expertise:
Demonstrated ability to identify validate prioritize track and drive
remediation of enterprise vulnerabilities using risk-based methodologies and
multiple security data sources.
2. Technical Analysis:
Strong analytical capability to investigate complex vulnerability findings
validate technical risk distinguish severity from actual exposure and
determine appropriate remediation or mitigation actions.
3. Risk-Based Prioritization:
Ability to evaluate vulnerabilities using business context asset criticality
exploitation activity threat intelligence exposure and compensating controls
rather than relying solely on vulnerability severity scores.
4. Security Technology Expertise:
Strong hands-on knowledge of Vulnerability Management and exposure management
platforms such as Wiz CrowdStrike Rapid7 Nagomi and similar technologies.
5. M&A Technical Execution:
Ability to perform hands-on cybersecurity assessments vulnerability discovery
integration activities validation remediation support and operational
transition activities within acquired environments.
6. Cross-Functional Collaboration:
Demonstrated ability to work effectively with Cyber Security Infrastructure
Network Cloud Application Identity GRC and other technology teams to drive
remediation and achieve cybersecurity objectives.
7. Problem-Solving Acumen:
Advanced ability to identify complex technical issues analyze root causes
develop practical solutions and drive cybersecurity findings through
resolution.
8. Operational Excellence:
Strong focus on repeatable processes documentation automation reporting
measurable risk reduction and continuous improvement within Vulnerability
Management and Cyber Security Operations.
Not the right job for you Register your details at the Introduce Yourself link (top right) and well be in touch!
Job Location: SRS Distribution - McKinney
7440 State Highway 121 McKinney TX 75070-3104
As an Equal Employment Opportunity (EEO) employer SRS Distribution Inc. including all its subsidiaries provides job opportunities to qualified individuals without regard to actual or perceived race color creed religion national origin sex gender age disability gender identity sexual orientation citizenship status uniform service veteran status marital status genetic information physical or mental disability or any other characteristic in accordance with applicable federal state and local EEO laws. If you are an individual with a disability or a disabled veteran and require a reasonable accommodation in applying for any posted position please contact Human Resources at US: 855.556.3221 or by email to: with the nature of your accommodation request and include the Business name location and title of the job opening. Please allow one (1) business day for a reply. All employment offers are contingent upon successful completion of a background check and drug screen as permitted by law.
Medical Dental Vision Disability & Life Insurance Wellness Benefits 401(k) Retirement Plan Employee Stock Purchase Program Paid Holidays & Vacation Days Professional Growth Opportunities Development & Training Programs. All benefits subject to eligibility.
Should a Candidate be submitted to fill a position by a recruiting or staffing services agency (Agency) the Company has no obligation to pay the Agency any fee for submission offer placement or any service without a fully executed contract of service covering the engagement.
Required Experience:
Senior IC