About this role
Job title: Information Security Analyst
About the Role Within the Cyber Fusion Center, the Infrastructure Security Team seeks an Information Security Analyst with 3–4 years of experience in vulnerability management, security automation, and risk mitigation. The role emphasizes developing scalable automation solutions (Python/PowerShell/Bash) for vulnerability detection, remediation, and reporting, and requires deep expertise in Tenable, ServiceNow VR and CC modules, cloud security, and third-party platforms (Okta, SAP, ServiceNow, Salesforce, M365). You will lead vulnerability management initiatives, drive automation strategies, integrate security data into ServiceNow, and mentor junior analysts to mature the vulnerability program.
What You'll Do
- Develop, optimize, and maintain automation scripts in Python, PowerShell, or Bash to streamline vulnerability management and remediation.
- Design API-driven integrations between Tenable, ServiceNow VR, and ITSM platforms for automated vulnerability tracking and reporting.
- Automate security workflows, including vulnerability ingestion, prioritization, ticketing, and remediation orchestration.
- Develop and maintain custom security tools to enhance scanning, reporting, and response capabilities.
- Lead enterprise-wide vulnerability assessments using Tenable, Qualys, or Nexpose, with risk-based prioritization.
- Maintain and optimize the ServiceNow VR module for vulnerability lifecycle management; collaborate with IT and development teams for remediation.
- Oversee the integration of Tenable data into ServiceNow VR; improve Configuration Compliance monitoring and remediation workflows.
- Apply expert knowledge of networking and security protocols (TCP/IP, HTTP/S, SSH, DNS, SSL/TLS, VPNs) and collaborate with network/firewall teams to strengthen segmentation.
- Lead compliance automation initiatives aligned with PCI-DSS, NIST, ISO 27001, and CIS benchmarks; develop scripts to generate reports and track remediation.
- Provide technical leadership to junior analysts; document automation workflows and security integration processes; develop trainings and participate in reviews and audits.
What We're Looking For
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent hands-on experience; 3–4 years of cybersecurity, vulnerability management, and security automation.
- Strong coding skills in Python, PowerShell, Bash; ability to write, optimize, and maintain scripts for security automation.
- Expertise in API development and integration between security tools (Tenable, ServiceNow, ITSM platforms).
- Advanced experience with vulnerability management tools such as Tenable, Qualys, or Nexpose.
- Deep knowledge of ServiceNow VR module, including configuration, automation, and integration.
- Strong understanding of network security protocols and common port numbers.
- Experience implementing and operating security automation, vulnerability management, and ITSM integrations.
Nice to Have
- Experience with cloud security platforms and third-party security tools (Okta, SAP, ServiceNow, Salesforce, M365).
- Prior leadership or mentorship experience; ability to document playbooks and automation workflows.
- Familiarity with PCI-DSS, NIST, ISO 27001, CIS, and regulatory requirements.
Compensation & Benefits
- Salary range: $80,200 - $134,250 USD per year
- Bonus: 8% of annual salary, target payout, paid annually
- Benefits: Medical, Dental, Vision, Disability, Health and Dependent Care Reimbursement Accounts, EAP, Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan
- Paid time off and eligibility-based parental leave, vacation, sick, bereavement