This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Associate, Vulnerability Assessment based in United States.
This role offers an opportunity to contribute to cybersecurity programs by identifying, analyzing, and helping remediate vulnerabilities across complex technology environments.
You will support security assessment activities that strengthen organizational resilience and reduce risk exposure.
The position combines technical analysis, vulnerability management, reporting, and collaboration with security and technology teams.
You will work with industry-leading security tools and frameworks while developing expertise in offensive security and risk management practices.
The ideal candidate is detail-oriented, curious, and passionate about improving security outcomes through data-driven assessments.
This is a remote opportunity within a collaborative environment focused on continuous learning, professional growth, and impactful cybersecurity work.
Accountabilities:
The Associate, Vulnerability Assessment will support vulnerability identification, analysis, validation, and reporting activities to help organizations strengthen their security posture. The role requires strong attention to detail, technical curiosity, and the ability to collaborate with internal and external stakeholders to deliver accurate and actionable security insights.
- Operate, review, and assess vulnerability scanning tools such as Tenable, Qualys, Nexpose, Prisma Cloud, and Burp to identify security weaknesses.
- Analyze vulnerability scan results and produce detailed reports covering findings, credential validation, asset inventory, and remediation status.
- Provide recommendations for addressing host-based and web application vulnerabilities while helping teams prioritize remediation efforts.
- Perform manual validation activities to confirm vulnerability resolution and assess the accuracy of reported findings.
- Review client-provided justifications related to vendor dependencies, false positives, operational constraints, and risk adjustments.
- Collaborate with technical teams and stakeholders to ensure timely delivery of assessment results and effective risk reduction strategies.
- Apply cybersecurity frameworks, policies, and industry best practices to support vulnerability management processes.
- Contribute to continuous improvement of assessment methodologies, reporting practices, and security operations.
Requirements:
The successful candidate will bring foundational cybersecurity knowledge, familiarity with vulnerability assessment processes, and the ability to analyze technical information effectively. Strong communication skills, a willingness to learn, and an understanding of security frameworks are essential for success in this role.
- Less than 2 years of professional experience in vulnerability assessment or related cybersecurity functions.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent combination of education and experience.
- Hands-on experience with at least one vulnerability scanning platform, such as Tenable, Qualys, Nexpose, Prisma Cloud, or Burp.
- Understanding of vulnerability identification, scanning, analysis, remediation strategies, and security reporting practices.
- Knowledge of vulnerability management best practices and cybersecurity risk assessment principles.
- Familiarity with security frameworks and compliance standards such as ISO, NIST, COBIT, HIPAA/HITECH, and related regulations.
- Strong analytical and problem-solving skills with the ability to interpret technical findings and recommend improvements.
- Effective written and verbal communication skills with the ability to explain security concepts clearly.
- Preferred experience with additional frameworks such as FedRAMP, FISMA, SOC, ISO, HIPAA, or HITRUST.
- Familiarity with cloud platforms including AWS, Azure, or Google Cloud.
- Exposure to configuration standards such as CIS benchmarks and STIGs.
- Experience with scripting languages such as Python, Bash, or PowerShell is a plus.
- Relevant certifications such as Security+, CCSK, AWS Cloud Practitioner, SSCP, GSEC, CEH, Cloud+, SC-900, ISC² CC, AZ-900, Cloud Essentials+, or GCP are valued.
Benefits:
- Competitive annual salary range of $86,000–$96,000, based on experience, location, education, certifications, and other job-related factors.
- Potential eligibility for incentive, commission, and recognition programs.
- Flexible remote work model designed to support productivity and work-life balance.
- Comprehensive health, insurance, and wellness benefits.
- Paid parental leave and flexible time-off programs.
- Certification and professional training reimbursement to support career development.
- Digital mental health and wellbeing support resources.
- Opportunities to participate in employee communities, professional events, and team-building initiatives.
- Supportive environment focused on professional growth, collaboration, and cybersecurity innovation.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1