Senior Vulnerability Management Security Analyst

CU Denver
Aurora, CO, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$81,050.0 - $90,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Information Systems PCI Data Security Standards Systems Integration Software Vulnerability Management IT General Controls (ITGC) Information Technology Vulnerability Analysis

Job description

  • Lead and oversee the enterprise threat and vulnerability management program, ensuring effective risk reduction across environments.
  • Evaluate and interpret threat data to assess risk and communicate recommended actions to stakeholders.
  • Drive remediation efforts by collaborating with IT teams, developers, and system owners.
  • Perform vulnerability scanning across on-prem and cloud environments and validate remediation outcomes.
  • Collaborate with incident response, vendors, and stakeholders to identify and address emerging threats and vulnerabilities.

Requirements

  • Expert-level proficiency in a variety of vulnerability management technologies and principles.
  • Knowledge of regulatory requirements related to security, privacy, and data protection.
  • Excellent written and verbal communication skills.
  • Strong analytical and problem-solving skills, including interpersonal problem resolution.
  • Exhibits intellectual curiosity and a commitment to continuous professional development.
  • Values collaboration and recognizes the importance of building strong professional relationships., * Bachelor’s degree in Information Systems, Computer Science, Engineering, Business, Education, or a closely related field
  • Substitution: 4 years of professional or high-level technical work experience may be substituted for the bachelor’s degree. An associate’s degree with two years of relevant work experience may be substituted for the bachelor’s degree

Experience:

  • 2-4 years of relevant experience configuring and administering enterprise security vulnerability management tools and conducting cyber threat intelligence., * Experience deploying, integrating, and managing Rapid7 InsightVM.
  • Advanced degree in Computer Science, Information Security, or related field.
  • CISSP, GIAC (GSEC, GCIH, GCIA, GPEN) or other technical security certifications.
  • Experience in IT controls monitoring for regulatory and compliance requirements like NIST, CIS, SOX, HIPAA, HITRUST, SSAE 16 - SOC 1 & SOC 2, PCI compliance - PCI DSS / PA-DSS, and NIST is a plus.
  • Penetration testing experience

Knowledge, Skills and Abilities:

  • Expert-level proficiency in a variety of vulnerability management technologies and principles.
  • Knowledge of regulatory requirements related to security, privacy, and data protection.
  • Excellent written and verbal communication skills.
  • Strong analytical and problem-solving skills, including interpersonal problem resolution.
  • Exhibits intellectual curiosity and a commitment to continuous professional development.
  • Values collaboration and recognizes the importance of building strong professional relationships.
  • Demonstrates initiative and a proactive approach to workload management.
  • Works collaboratively with stakeholders to develop solutions that meet defined requirements and desired outcomes.
  • Curiosity, motivation, and a desire for continuous learning.
  • A belief that strong relationships are key to success.
  • A self-starter with a can-do attitude.
  • An effective servant leader and manager of people who begins interactions by listening.
  • A collaborator with a focus on providing solutions based on the requirements and necessary outcomes of those whom we serve.

This position is not eligible for university-sponsored work authorization. Candidates must be authorized to work in the U.S. without current or future university sponsorship. Individuals with existing, valid U.S. work authorization are welcome to apply.

Benefits & conditions

The University of Colorado offers a comprehensive benefits package that includes health insurance, life insurance, retirement plans, tuition benefits, ECO pass, paid time off - vacation, sick, and holidays and more. To see what benefits are available, please visit: https://www.cu.edu/employee-services/benefits-wellness.

Why Work For

The University:

Why work for the University?

At the University of Colorado Anschutz, you’ll be part of a nationally recognized institution at the forefront of health innovation and technology. With multiple prestigious national designations, including as a top-tier academic medical center and a hub for cutting-edge research. CU Anschutz offers IT professionals the opportunity to support groundbreaking work that transforms healthcare and improves lives. Here, your expertise in technology directly empowers world-class research, education, and clinical care. Join a collaborative, mission-driven environment where your skills make a real impact. Here, your work matters.

We have AMAZING benefits and offer exceptional amounts of holiday, vacation and sick leave! The University of Colorado offers an excellent benefits package including:

  • Medical: Multiple plan options
  • Dental: Multiple plan options
  • Additional Insurance: Disability, Life, Vision
  • Retirement 401(a) Plan: Employer contributes 10% of your gross pay
  • Paid Time Off: Accruals over the year
  • Vacation Days: 22/year (maximum accrual 352 hours)
  • Sick Days: 15/year (unlimited maximum accrual)
  • Holiday Days: 10/year
  • Tuition Benefit: Employees have access to this benefit on all CU campuses
  • ECO Pass: Reduced rate RTD Bus and light rail service
  • There are many additional perks & programs with the CU Advantage., The starting salary range (or hiring range) for this position has been established as $81,050 - $90,000.

The above salary range (or hiring range) represents the University’s good faith and reasonable estimate of the range of possible compensation at the time of posting. This position may be eligible for overtime compensation, depending on the level.

Your total compensation goes beyond the number on your paycheck. The University of Colorado provides generous leave, health plans and retirement contributions that add to your bottom line.

About the company

Hybrid - This position is eligible for a hybrid work environment. AMC ISS strives for a high-flex work environment, meaning although this role may predominately be executed effectively with a remote schedule, there may be instances where in-person meetings and/or activities are needed. There is no minimum or prescribed in-person requirement. The work schedule will be based around core working hours in Colorado Mountain Time.

Why Join Us:

Information Strategy and Services (ISS) partners across the campus to deliver information technology services that empower teaching, learning, research, and patient care. ISS is organized into four core functions: Technology & Infrastructure, Security & Compliance, Information & Data Enablement and Business Services. Together, we connect service and technology.

Our work is guided by six shared principles that connect our teams and shape how we serve our customers:

  • Curiosity- Explore beyond one’s own experience and environment.
  • Compassion- Demonstrates empathy, understanding, and respect for all people.
  • Collaboration- Partner well beyond our space and build partnerships to achieve organizational results.
  • Commitment- Dedication and engagement one has to their job, team, organization and university.
  • Competence- Know our craft and be committed to continuous improvement and learning.
  • Confidence- Be empowered and assured to represent our customers and their needs.

Active investment in our culture and our people is foundational in developing and delivering service excellence. To cultivate a people centric workplace, we do the following:

  • Growth & Development: Our Workforce Development Program builds critical skills and supports career advancement.
  • Empowered Managers: Leaders are trained in coaching and team effectiveness to drive success.
  • Open Communication: Stay connected through monthly town halls and annual summits.
  • Wellness Focus: We prioritize employee well-being with supportive wellness initiatives.
  • Coaching Culture: Continuous learning and feedback are part of how we grow together.
  • Flexible Work: We offer flexible arrangements whenever possible to support work-life balance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:00 min

Designing data ingestion architecture with system integration

Eldert Grootenboer +1 · World Congress 2023

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all