Vulnerability Analyst - North Central region (Remote - PST preferred)
Remote - PST preferred
Applications have closed
GuidePoint Security LLC
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
Vulnerability Analysts who work for GuidePoint are knowledgeable and passionate technologists who are self-motivated and self-directed. They are willing to take ownership of and be materially involved in the complete professional services lifecycle, from pre-sales through delivery. Most importantly, they take direction well, function as part of a team, and are willing to learn and absorb new security focused technologies and disciplines. They are passionate about customer service, and invest themselves in fostering and maintaining positive relationships with their customers. Life-long learners, GuidePoint’s analysts are never satisfied with the status quo and constantly challenge themselves to improve, both personally and professionally.
Note: This is a remote position but we are ideally looking for someone living on the west coast (PST).
Technical Skills & Knowledge we are looking for:
- Experience with the entire vulnerability management lifecycle, assisting with building and maintaining vulnerability management programs in large and complex environments
- Must have experience with Qualys (deployment experience a plus)
- Experience performing basic scripting tasks using only what is found in the environment, such as BASH, PowerShell, Python, Perl or other native scripting languages a plus
- Experience with Kenna Security, Nucleus, Brinqa or similar risk management tools a plus
- Experience with ServiceNow integrations a plus
- Experience with Microsoft VM tools a plus
- An understanding of operating systems such as Windows Server, Windows 10/7, Mac OSX, RHEL, and Ubuntu Linux and the ability to perform basic functions at the CLI
- An understanding of networking concepts, protocols and detailed knowledge of how networks function
- A strong understanding of systems design and implementation
- An understanding of how and why vulnerabilities exist and are exploited
- Ability to understand and articulate complex vulnerability information to both technical and non-technical audience
- Ability to quantify true risk of vulnerability findings given environmental and extenuating circumstance
- Ability to interpret vulnerability scan results and build creative remediation strategies to remediate vulnerabilities
- Ability to design compensating controls when technical fixes may not be feasible
- A working knowledge of Application Security and infrastructure specific vulnerabilities such as those included in the OWASP Top 10 (SQL Injection, Cross-site Scripting, etc.)
- Strong written and verbal communication skills
- A strong desire to learn new technologies and contribute to a fast-growing company
Other relevant experience:
- Experience with programming languages such as Python, Java, C, C++, C#, PHP, Ruby or .NET
- Hands on experience hardening systems to benchmarks such as CIS, NIST, etc.
- Experience with enterprise software deployment tools such as SSM, JAMF, BigFix, or Tanium
- Familiarity with other Information Security tools such as Nessus, Kismet, Nmap, Burp, Netsparker, WebInspect, AppScan, Nexpose, Core Impact, Metasploit, etc.
Education:
- Bachelor's degree in Computer Science, Engineering, Information Systems / Security or related discipline preferred
We use Greenhouse Software as our applicant tracking system and Free Busy for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.
Why GuidePoint?
GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 800 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 3,500 customers.
Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.
This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.
Some added perks….
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- 100% employer-paid medical premiums (employee only $0 deductible and HSA plans) along with 75% employer-paid family contributions
- 100% employer-paid dental premiums (employee only) along with 75% employer-paid family contributions
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Bash C Computer Science Core Impact Jamf Java Linux Metasploit Nessus NIST Nmap OWASP Perl PHP PowerShell Python Qualys Risk management Ruby Scripting SQL SQL injection Ubuntu Vulnerabilities Vulnerability management Windows XSS
Perks/benefits: Career development Flex hours Flex vacation
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open o365 Security Architect jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Analytics-related jobs
- Open CISM-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open EDR-related jobs