Information Security Analyst (Vulnerability Management)

Blue Yonder Group, Inc.
Dallas, TX, United States
5 days ago
Apply on jda.wd5.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$98,235.0 - $123,765.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Automation of Tests Microsoft Azure Cloud Computing CompTIA Security+ Cyber Security Identity and Access Management Information Security Management Internet Security Python (Programming Language) Microsoft Security Essentials
+16 more
OAuth OpenID Oracle (Applications) Windows PowerShell Azure Active Directory Security Assertion Markup Language (SAML) Security Information and Event Management Software Vulnerability Management EndPointSecurity SOAPAPI Information Technology Restful APIs Oracle Cloud Infrastructure Splunk Qualys Vulnerability Analysis

Job description

The successful candidate will support compliance with ISO/IEC 27001, the Department of Defense Cybersecurity Maturity Model Certification (CMMC) Level 2, NIST (National Institute of Standards and Technology) Special Publication 800-171 and Special Publication 800-53, along with other cybersecurity standards applicable to U.S. Government contractors. The role supports a cloud-first environment utilizing Microsoft Azure, Oracle Cloud Infrastructure (OCI), and Microsoft 365 and will work closely with IT, engineering, and business stakeholders to strengthen Blue Yonder Defense Solutions overall security posture.

Security Tech Stack/Tools:

Cloud & Identity Platforms

  • Azure AD / Entra ID, AWS IAM, Oracle IAM
  • Federation & SSO: SAML, OAuth, OIDC, SCIM

Security, Monitoring & Scanning

  • SIEM/EDR/XDR (CrowdStrike, Splunk, Elastic etc.)
  • Defender for Endpoint, Defender for Cloud, Oracle Vulnerability Manager, Amazon Inspector, Tenable, OpenVAS
  • Identity threat analytics and access risk tooling

Automation & Dev Integration

PowerShell, Python, REST / SCIM / Graph / SOAP APIs

Security Compliance

  • NIST (National Institute of Standards and Technology) SP 800-171 and SP 800-53
  • Cybersecurity Maturity Model Certification (CMMC) Level 2
  • ISO/IEC 27001 Information Security Management Standard
  • CIS (Center for Internet Security) Benchmarks
  • FedRAMP (Federal Risk and Authorization Management Program) fundamentals

What You’ll Be Doing:

  • Conduct regular vulnerability scans across cloud and on-premises assets using industry-standard tools.
  • Analyze scan results, assess risk, prioritize findings, and recommend remediation activities based on business impact.
  • Collaborate with IT, infrastructure, and development teams to track, prioritize, and remediate security vulnerabilities.
  • Develop and maintain automation scripts and reporting processes to support vulnerability management activities.
  • Support incident response efforts by providing vulnerability context, risk analysis, and remediation guidance.
  • Document vulnerability management processes, findings, remediation activities, and security recommendations.
  • Assist with compliance initiatives by providing evidence, reporting, and support for ISO 27001, CMMC Level 2, NIST 800-171, and NIST 800-53 requirements.
  • Stay current with emerging threats, vulnerability trends, cybersecurity technologies, and industry best practices.
  • Participate in ongoing efforts to strengthen BYDS’s security posture across cloud and enterprise environments

Requirements

Requirement: US Citizen (Must Hold OR Be Willing to Obtain a Government Clearance), * Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field; equivalent professional experience considered in lieu of degree.

  • 5+ years of cybersecurity, vulnerability management, security operations, or information security experience.
  • Experience supporting government, defense contractor, or Defense Industrial Base (DIB) environments.
  • Working knowledge of Cybersecurity Maturity Model Certification (CMMC) Level 2 and NIST SP 800-171 and/or NIST SP 800-53 frameworks.
  • Hands-on experience with vulnerability scanning tools, vulnerability assessment, remediation, and risk prioritization.
  • Experience securing cloud-based environments, including Microsoft Azure, Oracle Cloud Infrastructure (OCI), AWS, and/or Microsoft 365.
  • Strong communication, documentation, and cross-functional collaboration skills.

Preferred Qualifications

  • Experience supporting ISO/IEC 27001 compliance programs and audits.
  • Familiarity with vulnerability management solutions such as Tenable, OpenVAS, Qualys, Rapid7, Amazon Inspector, Microsoft Defender, or similar tools.
  • Experience supporting incident response and security investigations.
  • Experience working within highly regulated environments subject to government or defense cybersecurity requirements.
  • Industry certifications such as Security+, CySA+, SSCP, GSEC, SC-200, AZ-500, or equivalent cybersecurity certifications.

Preferred Certifications

  • One or more industry-recognized cybersecurity certifications such as Security+, CySA+, SSCP, GSEC, Microsoft Security (SC-200/AZ-500), or equivalent.
  • Certifications or training related to ISO 27001, NIST SP 800-171, or NIST SP 800-53 are a plus.

Soft Skills

  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent written, verbal, and technical documentation skills.
  • Ability to manage multiple priorities while maintaining attention to detail.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Collaborative mindset with a commitment to continuous learning and professional growth.

LI-Hybrid

Benefits & conditions

The annual salary range for this position is $98,234.50 - $123,765.49

The salary range information provided, reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual salary will be commensurate with skills, experience, certifications or licenses and other relevant factors. In addition, this role will be eligible to participate in either the annual performance bonus or commission program, determined by the nature of the position.

At Blue Yonder, we care about the wellbeing of our employees and those most important to them. This is reflected in our robust benefits package and options that includes:

  • Comprehensive Medical, Dental and Vision
  • 401K with Matching
  • Flexible Time Off
  • Corporate Fitness Program
  • A variety of voluntary benefits such as; Legal Plans, Accident and Hospital Indemnity, Pet Insurance and much more

At Blue Yonder, we are committed to a workplace that genuinely fosters inclusion and belonging in which everyone can share their unique voices and talents in a safe space. We continue to be guided by our core values and are proud of our diverse culture as an equal opportunity employer. We understand that your career search may look different than others, and embrace the professional, personal, educational, and volunteer opportunities through which people gain experience.

Our Values

If you want to know the heart of a company, take a look at their values. Ours unite us. They are what drive our success - and the success of our customers. Does your heart beat like ours? Find out here: Core Values

About the company

Blue Yonder Defense Solutions, LLC., a Blue Yonder company, is the leader in supply chain autonomous planning. Our innovative solutions empower businesses to optimize their supply chains, enhance customer experiences, and drive sustainable growth. We are committed to delivering cutting-edge technology and unparalleled expertise to help our defense and humanitarian-aid clients navigate the complexities of the modern supply chain.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jda.wd5.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all