Vulnerability Management Compliance Analyst

Post Date

Apr 19, 2024

Location

Charlotte,
North Carolina

ZIP/Postal Code

28202
US
Jul 13, 2026 Insight Global

Job Type

Contract

Category

Security Engineering

Req #

CLT-698596

Pay Rate

$48 - $72 (hourly estimate)

Job Description

The Vulnerability Analyst will support the configuration compliance and infrastructure vulnerability management programs with identifying, reporting, and enabling remediation of vulnerability and compliance findings. The ideal candidate for this role will have a strong technical foundation in system administration (Unix or Windows), familiarity with networking and cyber security, and hands-on experience with infrastructure scanning tools. The candidate must be equally comfortable speaking with developers as well as infrastructure teams about vulnerabilities and configuration compliance.



Reporting into the Director of Vulnerability Management, the Vulnerability Analyst will be accountable for the identification, reporting and remediation of vulnerability and compliance findings within their area of responsibility.



* Maintain awareness of the latest critical information security vulnerabilities, threats, and exploits

* Assist in facilitating vulnerability and compliance scanning and reporting activities, as directed by senior team members, ensuring accurate & timely identification, reporting, and escalation.

* Leverage vulnerability management reports and metrics, to drive remediation of vulnerabilities for specified areas of the environment

* Communicate with Ally technology staff on vulnerability management and remediation of key vulnerabilities. Assist teams with understanding the vulnerability, possible remediations, and assist with false positives or mitigation solutions.

* Identify enhancements to tools, standards, and processes to enable continuous process improvement and automation of existing processes.

* In zero-day events, iterate through VM lifecycle -- creatively assist with time-sensitive escalations, developing new types of reports, and perform special investigations.







We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.

To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/ .

Required Skills & Experience

MUST HAVE

* Ability to review and write documentation to establish compliance baselines for vulnerability management

* Ability to effectively document vulnerability processes, status reports, etc.

* Detailed understanding of Qualys or a similar vulnerability scanning tool (Symantec, Tenable Nessus, Rapid7, AlgoSec)

* Ability to work independently, self-starter...proactive person who can take moderate direction and own their role



PLUS

* Understanding/experience with Systems Administration (Linux, Unix)

* Understanding of configuration compliance benchmarks such as CIS or STIG

Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.