Padmi
Coalfire logo
Coalfire

FedRAMP assessment · CMMC advisory

Vulnerability Analyst

Remote · United States$80k–$134k/yrPosted 2 months ago
SecurityMid-levelRegular Full Time
Apply at Coalfire

Opens the source posting on jobs.lever.co

Source description

About the role

View original

3–5 years of professional experience in vulnerability management, compliance monitoring, or related security operations roles

Hands-on expertise with operating system, database, network, container, web application, and API vulnerability management

Direct experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP

Background working within at least one compliance framework (for example, FedRAMP, HITRUST, PCI), including risk assessment and reporting

Experience delivering monthly or periodic vulnerability status reports and tracking remediation efforts with internal and external teams

Administrator-level certification in AWS, Azure, or GCP

Working knowledge of cloud architecture and security controls in AWS, Azure, or GCP, including ability to assess attack surfaces and recommend cloud-native remediation approaches

Strong knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS) and risk prioritization frameworks

Understanding of NIST 800-53 security controls, particularly RA-5, SI-2, CM-6, and how continuous monitoring supports control implementation

Experience with STIG benchmarks and automated compliance scanning tools (SCAP, SCC)

Familiarity with baseline configuration standards (CIS Benchmarks, vendor hardening guides) and compliance posture reporting

Ability to distinguish false positives from true vulnerabilities and articulate risk-based justifications for deviation requests

Proficiency in scripting languages (Python, PowerShell, Bash) for task automation, report generation, and remediation workflows

Strong client-facing communication and documentation skills, with ability to present technical findings to federal stakeholders and produce timely compliance reports

Ability to work efficiently with cross-functional technical teams to investigate, prioritize, and coordinate vulnerability remediation efforts

Bachelor’s degree or equivalent work experience.

US citizenship (required due to client contractual requirements)

More at Coalfire

Related open roles

View all roles