> Markdown version of [/jobs/ext/1022279-senior-vulnerability-and-threat-analyst](https://www.wearedevelopers.com/jobs/ext/1022279-senior-vulnerability-and-threat-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Vulnerability and Threat Analyst - **Company:** Monroe University - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $80,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Software System Penetration Testing, Automation of Tests, Bash Shell, Cyber Security, Information Systems, Data Discovery, Information Technology Operations, Python (Programming Language), Network Architecture, Windows PowerShell, Cloud Services, Phishing, Security Information and Event Management, Software Vulnerability Management, Scripting, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Microsoft Sentinel, Splunk, Network Server, Qualys - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e075198966ef12d1 ## About the Role Do you have experience in Risk assessment?, Do you have a Bachelor's degree?, * Deep hands-on expertise with enterprise vulnerability management platforms (Tenable, Rapid7, Qualys, or equivalent), including scan policy design, credentialed scanning, and integration with remediation workflows. * Working knowledge of penetration testing methodologies (PTES, OSSTMM) and experience coordinating or conducting internal or external pen tests. * Familiarity with automated and continuous testing platforms (Pentera, Horizon3, RidgeBot, or similar) is preferred. * Fluency in threat intelligence frameworks - MITRE ATT&CK, Cyber Kill Chain, STIX/TAXII - and practical experience applying them to operational decisions. * Strong scripting skills in Python, PowerShell, or Bash for automation, data analysis, and custom tooling. * Experience with SIEM platforms (Microsoft Sentinel, Splunk, or equivalent) and the ability to write effective detection logic. * Understanding of higher-education threat landscape - ransomware targeting education, phishing against student populations, research-data attacks - or demonstrated ability to learn rapidly. * Strong written communication skills; ability to produce clear, audience-appropriate reporting for technical and non-technical audiences. * Collaborative orientation and comfort working across IT, the outsourced SOC, external vendors, and academic partners. * Interest in mentoring students through the Student Cyber Corps program; experience with applied academic-operational collaboration is a plus., * Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field; equivalent professional experience considered. * Minimum 6-8 years of progressive experience in vulnerability management, penetration testing, threat intelligence, or security operations, with at least 3 years in a senior analyst role. * Professional certifications such as CISSP, GIAC GCIH, GIAC GPEN, OSCP, or equivalent strongly preferred. * Experience in higher education, healthcare, financial services, or another regulated environment is preferred. * Demonstrated experience managing third-party penetration testing or compromise assessment engagements is strongly preferred. * Ability to work on-site at Monroe's Bronx and New Rochelle campuses at least four days per week. ## Description The Senior Vulnerability and Threat Analyst is a senior individual contributor supporting Cybersecurity at Monroe University. This role owns three tightly-integrated disciplines: continuous vulnerability management across Monroe's environment, coordination of internal and external penetration testing activities, and consumption of threat intelligence relevant to the higher-education sector. The Senior Vulnerability and Threat Analyst serves as the primary analyst responsible for identifying, prioritizing, and driving remediation of technical exposures across the institution. This role partners closely with Monroe's IT team, the outsourced Security Operations Center, and external specialized firms engaged for forensics or compromise assessment. The Senior Vulnerability and Threat Analyst also serve as the primary supervisor of the Student Cyber Corps program when it launches, providing faculty-aligned oversight of student-led security engagements. Core Responsibilities: * Establish and operate a continuous vulnerability management program covering endpoints, servers, network infrastructure, cloud workloads, and critical applications. * Prioritize vulnerabilities based on exploitability, institutional exposure, and business impact - not raw CVSS scores - and drive remediation in partnership with IT operations. * Coordinate internal and external penetration testing engagements, including scoping, vendor management, findings validation, and remediation tracking. * Consume and operationalize higher-education-specific threat intelligence through REN-ISAC membership, commercial threat feeds, and government advisories (CISA, FBI IC3). * Serve as the primary Monroe contact for REN-ISAC community engagement, including participation in sector-wide information sharing and peer collaboration. * Conduct proactive threat hunting in the environment to identify indicators of compromise, persistence mechanisms, and suspicious activity not surfaced by automated detections. * Partner with the outsourced Security Operations Center to tune detection rules, improve alert quality, and close visibility gaps. * Own the scoping, vendor selection, and project management of external specialized engagements such as compromise assessments and data discovery projects, in coordination with the CISO. * Supervise the Student Cyber Corps program when launched - designing engagement scope, reviewing student work product, validating findings, and ensuring no student access touches production PII or sensitive systems. * Produce regular vulnerability and threat landscape reporting for the CISO, the CIO, and institutional leadership, translating technical exposure into institutional risk language. * Support GLBA Safeguards Rule compliance by maintaining continuous, documented evidence of vulnerability management and penetration testing activities. * Contribute to incident response investigations as a technical analyst, particularly where historical vulnerability data or threat intelligence is relevant. * Participate in Monroe's incident response on-call rotation once established. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)