Source description
About the role
Job Description
Job : Vulnerability Management Analyst- NERC CIP
Location : on site San Diego, CA (Onsite travel required across San Diego service territory)
Duration : 12+Months
Job Summary: We are seeking a detail-oriented and proactive Vulnerability Management Analyst to support ongoing cybersecurity and compliance initiatives, particularly within NERC CIP environments.
This role will focus on identifying, analyzing, and remediating vulnerabilities across critical infrastructure, as well as supporting compliance documentation and site-level assessments.
The ideal candidate will have experience with industry-standard scanning tools and a strong understanding of vulnerability lifecycle management in a regulated utility setting. Key Responsibilities:
Perform routine vulnerability scans using tools such as Tenable , Tripwire IP360 , and other industry-standard solutions.
Analyze scan results, validate findings , and work directly with system and application owners to prioritize and remediate vulnerabilities based on risk and criticality.
Track and manage remediation efforts and verify closure of identified vulnerabilities through re-scanning and stakeholder collaboration.
Partner with application and infrastructure teams to ensure patching and configuration compliance .
Support and contribute to NERC CIP compliance efforts by maintaining documentation, providing evidence, and generating reports as needed.
Assist in developing and maintaining metrics and dashboards to communicate vulnerability posture and identify trends over time.
Document systems, asset inventories, and rack elevations at each NERC CIP-impacted site .
Travel to other substations across the service territory to conduct site assessments, physical verification, and documentation work.
Contribute to the continuous improvement of vulnerability management processes, procedures, and operational playbooks. Qualifications:
2+ years of experience in cybersecurity, IT operations, or vulnerability management.
Hands-on experience with vulnerability scanning tools such as Tenable , IP360 , Qualys , etc.
Familiarity with patch management , risk-based remediation , and security baselines .
Understanding of NERC CIP standards and evidence requirements preferred.
Strong organizational and communication skills with the ability to work independently and in cross-functional teams.
Ability to travel to substations and critical facilities across San Diego County.
Proficiency in Excel, dashboarding tools, and basic scripting is a plus. Preferred Certifications (Nice to Have):
CompTIA Security+
GIAC Security Essentials (GSEC)
Certified Information Systems Auditor (CISA)
Certified Information Systems Security Professional (CISSP)
NERC CIP Certification or training
More at 3B Staffing