> Markdown version of [/jobs/ext/1803640-cybersecurity-threat-vulnerability-analyst](https://www.wearedevelopers.com/jobs/ext/1803640-cybersecurity-threat-vulnerability-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Threat & Vulnerability Analyst - **Company:** Horizon Blue Cross Blue Shield of New Jersey - **Location:** Newark, NJ, United States (Remote available) - **Experience:** Experienced - **Salary:** $97,800.0 - $133,455.0 - **Contract:** Permanent contract - **Skills:** Microsoft Excel, Microsoft Windows, Apple Mac Systems, CompTIA Security+, Cyber Security, Linux, Internet Security, Information Systems Security Architecture Professional, Microsoft Visio, Microsoft PowerPoint, Software Vulnerability Management, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Cybercrime, Patch Management, Nessus, Nexpose, Qualys, Vulnerability Analysis - **Published:** July 7, 2026 - **Apply:** https://bcbsnj.wd5.myworkdayjobs.com/hc/job/Newark-NJ---Remote/Cybersecurity-Threat---Vulnerab-Analyst_2026-0087 ## About the Role * High School Diploma or GED required. * Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field preferred. * Relevant experience may be considered in lieu of a degree. Experience: * Minimum of five (5) years of Information Security experience required. * At least three (3) years of experience focused on vulnerability identification, assessment, and remediation. * Experience working within a large enterprise environment preferred. * Experience supporting security audits, regulatory compliance reviews, and risk management programs preferred. Certifications: * One or more of the following certifications is required or strongly preferred: * CISSP (Certified Information Systems Security Professional) * GCTI (GIAC Cyber Threat Intelligence) * GIAC certifications * CompTIA Security+ * Certified Ethical Hacker (CEH) Knowledge: * Strong understanding of cybersecurity frameworks and methodologies, including Cyber Kill Chain, Defense-in-Depth, and related security models. * Comprehensive knowledge of vulnerability management and patch management processes and their respective remediation approaches. * Deep understanding of indicators of compromise (IOCs), advanced persistent threats (APTs), cybercrime techniques, and attacker tactics, techniques, and procedures (TTPs). * Knowledge of operating systems including Windows, Linux/Unix, and macOS. * Experience with vulnerability management platforms such as Nessus, Qualys, InsightVM (Nexpose), or similar solutions. * Knowledge of Center for Internet Security (CIS) benchmarks and Critical Security Controls. * Familiarity with threat intelligence platforms and sources such as Recorded Future, ThreatConnect/ThreatStream, H-ISAC, NJCCIC, and similar resources. * Understanding of audit, regulatory, and compliance requirements related to cybersecurity programs. Skills & Abilities: * Proven ability to prioritize vulnerabilities and systems based on risk, asset criticality, and business impact. * Experience utilizing CVSS scoring and risk-based vulnerability management methodologies. * Strong analytical, investigative, and problem-solving skills. * Excellent verbal and written communication skills, including the ability to present technical information to both technical and non-technical audiences. * Experience creating executive-level dashboards, scorecards, and presentations using tools such as Microsoft PowerPoint, Visio, and Excel. * Experience developing and documenting security processes, standards, and procedures. * Ability to facilitate cross-functional collaboration and drive vulnerability remediation efforts across multiple teams. * Experience negotiating remediation plans, exception requests, SLA extensions, and false-positive determinations. * Strong project management, organizational, and time-management skills. * Ability to manage multiple priorities in a fast-paced environment. * Demonstrated attention to detail and commitment to operational excellence. * Self-motivated and capable of working independently while maintaining effective communication with stakeholders. * Strong interpersonal skills with the ability to build partnerships and influence outcomes across the organization. ## Description This role works closely with the Enterprise Business and Technology Solutions (EBTS) Division to develop, implement, and enhance processes that identify, assess, and remediate vulnerabilities across Horizon's technology environment. The analyst is responsible for performing internal and external vulnerability assessments, managing vulnerability scanning programs, establishing security standards, and evaluating exceptions and false-positive findings. The position plays a key role in reducing organizational risk by partnering with technology teams to prioritize and remediate vulnerabilities, developing long-term security solutions, and supporting threat intelligence and threat hunting initiatives. The incumbent will stay current on emerging threats, industry standards, and security trends, providing regular updates and recommendations to leadership regarding risks requiring remediation. What You'll Do * Develop and enhance vulnerability scanning strategies to ensure comprehensive coverage across Horizon's enterprise environment. * Conduct internal and external vulnerability assessments and validate scan results. * Apply established vulnerability management standards to classify vulnerabilities based on severity, exploitability, and business risk. * Categorize and prioritize assets according to criticality and organizational impact. * Partner with EBTS teams to develop and execute vulnerability remediation plans in accordance with established service level agreements (SLAs). * Track and report remediation activities to ensure timely resolution of identified vulnerabilities. * Analyze emerging cyber threats and assess potential impacts to Horizon's technology environment. * Communicate current risk exposure, remediation efforts, and security recommendations to senior leadership and key stakeholders. * Develop, maintain, and present weekly and monthly vulnerability management metrics and executive reports. * Create, update, and maintain policies, standards, procedures, and process documentation related to vulnerability management and threat intelligence operations. * Ensure security controls, policies, and standards are operating effectively to satisfy audit and regulatory requirements. * Assist in the development and maturation of a threat hunting program by documenting threat scenarios, response playbooks, and use cases. * Collaborate with internal teams to investigate, validate, and resolve vulnerability findings, false positives, and remediation exceptions. * Support continuous improvement initiatives aimed at strengthening the organization's overall cybersecurity posture ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job)