Vulnerability Management Analyst I: 26-00161
2 days ago
Omaha
Job Description VULNERABILITY MANAGEMENT ANALYST I Location; Omaha, NE JOB DESCRIPTION We are seeking an experienced Vulnerability Management Analyst to support the continued development and execution of our Vulnerability Management program. This contractor will initially focus on reducing the current backlog of overdue vulnerability remediation items while also helping improve the overall process for assigning, tracking, validating, and reporting vulnerabilities across the organization. The successful candidate will work closely with Vulnerability Management, infrastructure, application, security, service management, and technology ownership teams. This role requires someone who can quickly understand a complex technology environment, work independently, coordinate across multiple teams, and bring structure and accountability to a high-volume backlog. This is a hands-on operational and process-focused role. The contractor will not necessarily perform all technical remediation directly but will be responsible for helping ensure vulnerabilities are assigned to the correct owners, remediation plans are established, progress is accurately documented, and overdue items are appropriately escalated. KEY RESPONSIBILITIES • Review and triage the existing backlog of overdue vulnerability remediation tickets., • Validate vulnerability findings, affected assets, application ownership, support-team ownership, remediation status, and target completion dates., • Work with infrastructure, application, cloud, database, middleware, endpoint, and other technology teams to coordinate remediation activities., • Identify tickets that have been incorrectly assigned or that require involvement from multiple support teams., • Help break down complex or multi-team remediation efforts into clearly defined, trackable actions., • Ensure vulnerability tickets contain complete and accurate information, including affected hosts, vulnerability details, ownership, remediation requirements, due dates, exceptions, and status updates., • Follow up with assigned teams to obtain remediation plans, target dates, implementation evidence, and validation of completion., • Coordinate with vulnerability scanning and security teams to confirm whether vulnerabilities have been successfully remediated or require additional action., • Identify recurring ownership, CMDB, assignment-group, asset-management, and process gaps that contribute to overdue vulnerabilities., • Support improvements to ServiceNow workflows, reporting, ticket structures, dashboards, and operating procedures., • Assist with defining and documenting Vulnerability Management roles, responsibilities, escalation paths, service-level expectations, and governance processes., • Develop regular backlog reporting for technology leaders, including aging, ownership, risk severity, remediation progress, blockers, and overdue trends., • Escalate high-risk, significantly overdue, or stalled remediation items through the appropriate management channels., • Support vulnerability exception and risk-acceptance processes where remediation cannot be completed within the required timeframe., • Help establish repeatable processes that can be transitioned to internal team members at the conclusion of the engagement., • Maintain clear documentation of decisions, actions, dependencies, and process improvements. Initial Priorities During the initial phase of the engagement, the contractor will be expected to: • Review and categorize the existing overdue Vulnerability Management backlog., • Confirm technical and business ownership of affected assets and applications., • Correct inaccurate ticket assignments and identify remediation dependencies., • Establish remediation plans and target dates with the responsible teams., • Create a consistent process for tracking progress and escalating stalled items., • Identify systemic issues contributing to the backlog, including CMDB, ownership, workflow, reporting, and accountability gaps., • Recommend practical improvements to the ongoing Vulnerability Management operating process., • Develop documentation and reporting that can be maintained by the internal team. Measures of Success Success in this role will be measured through: • Reduction in the number and age of overdue vulnerability tickets., • Improved accuracy of ticket ownership and assignment., • Increased percentage of vulnerabilities with documented remediation plans and target dates., • Timely escalation of high-risk or stalled remediation items., • Improved visibility into remediation status, risk, blockers, and dependencies., • Documented improvements to Vulnerability Management workflows and procedures., • Creation of a sustainable process that can be transitioned to the internal team. QUALIFICATIONS Required Qualifications • Three or more years of experience in Vulnerability Management, cybersecurity operations, IT risk, infrastructure security, IT service management, or a related technology operations role., • Experience managing or coordinating the remediation of vulnerabilities across multiple technical teams., • Strong working knowledge of vulnerability-management concepts, including severity ratings, risk prioritization, remediation timelines, exceptions, compensating controls, and validation., • Experience working with enterprise vulnerability-scanning platforms such as Tenable, Qualys, Rapid7, CrowdStrike or a comparable tool., • Experience using ServiceNow or another enterprise IT service-management platform to manage tickets, assignments, workflows, and reporting., • Ability to interpret vulnerability findings and communicate remediation requirements to technical and nontechnical stakeholders., • Strong organizational skills and the ability to manage a large volume of open actions, owners, dependencies, and deadlines., • Demonstrated ability to follow up with stakeholders, remove blockers, and escalate issues appropriately., • Strong written and verbal communication skills., • Experience creating operational reports, dashboards, metrics, and executive-level summaries., • Ability to work independently, establish priorities, and deliver results with limited oversight., • Strong proficiency with Microsoft Excel and other Microsoft 365 tools. Preferred Qualifications • Experience working within a large, regulated enterprise, preferably in financial services, insurance, healthcare, or another highly regulated industry., • Familiarity with ServiceNow Vulnerability Response, Configuration Management Database, asset-management, or related ServiceNow modules., • Experience improving vulnerability-management workflows or operating models., • Understanding of infrastructure and application technologies, including Windows, Linux, databases, middleware, cloud services, network devices, and end-user computing., • Experience working with audit, compliance, risk, or governance teams., • Experience supporting process documentation, procedure development, or responsibility-assignment models. Key Competencies • Strong ownership and follow-through., • Ability to quickly learn a complex organizational and technology environment., • Comfortable challenging incomplete information and driving issues toward resolution., • Effective at working across organizational boundaries without direct authority., • Able to balance security risk, technical complexity, operational impact, and business priorities., • Detail-oriented while still able to recognize broader process and risk trends., • Collaborative, pragmatic, and comfortable working directly with technical teams and leadership. \nCompany Description Platinum Resource Group is a professional level consulting firm, providing resources to Fortune 1000 client companies in the areas of technology, human resources, accounting, finance, business systems and supply chain, on a contract and interim basis. PRG has operations in Orange County, San Diego, Los Angeles and San Francisco. As a W-2 employer we offer our consultants direct deposit bi-weekly payroll, health, dental, vision benefits, and referral bonuses. Platinum Resource Group is a professional level consulting firm, providing resources to Fortune 1000 client companies in the areas of technology, human resources, accounting, finance, business systems and supply chain, on a contract and interim basis. PRG has operations in Orange County, San Diego, Los Angeles and San Francisco. As a W-2 employer we offer our consultants direct deposit bi-weekly payroll, health, dental, vision benefits, and referral bonuses.