> Markdown version of [/jobs/ext/2044868-information-security-analyst-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/2044868-information-security-analyst-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst (Vulnerability Management) - **Company:** Blue Yonder Group, Inc. - **Location:** Dallas, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $98,235.0 - $123,765.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Automation of Tests, Microsoft Azure, Cloud Computing, CompTIA Security+, Cyber Security, Identity and Access Management, Information Security Management, Internet Security, Python (Programming Language), Microsoft Security Essentials, OAuth, OpenID, Oracle (Applications), Windows PowerShell, Azure Active Directory, Security Assertion Markup Language (SAML), Security Information and Event Management, Software Vulnerability Management, EndPointSecurity, SOAPAPI, Information Technology, Restful APIs, Oracle Cloud Infrastructure, Splunk, Qualys, Vulnerability Analysis - **Published:** August 13, 2026 - **Apply:** https://jda.wd5.myworkdayjobs.com/JDA_Careers/job/BYDS-Dallas/Information-Security-Analyst--Vulnerability-Management-_262455 ## About the Role Requirement: US Citizen (Must Hold OR Be Willing to Obtain a Government Clearance), * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field; equivalent professional experience considered in lieu of degree. * 5+ years of cybersecurity, vulnerability management, security operations, or information security experience. * Experience supporting government, defense contractor, or Defense Industrial Base (DIB) environments. * Working knowledge of Cybersecurity Maturity Model Certification (CMMC) Level 2 and NIST SP 800-171 and/or NIST SP 800-53 frameworks. * Hands-on experience with vulnerability scanning tools, vulnerability assessment, remediation, and risk prioritization. * Experience securing cloud-based environments, including Microsoft Azure, Oracle Cloud Infrastructure (OCI), AWS, and/or Microsoft 365. * Strong communication, documentation, and cross-functional collaboration skills. Preferred Qualifications * Experience supporting ISO/IEC 27001 compliance programs and audits. * Familiarity with vulnerability management solutions such as Tenable, OpenVAS, Qualys, Rapid7, Amazon Inspector, Microsoft Defender, or similar tools. * Experience supporting incident response and security investigations. * Experience working within highly regulated environments subject to government or defense cybersecurity requirements. * Industry certifications such as Security+, CySA+, SSCP, GSEC, SC-200, AZ-500, or equivalent cybersecurity certifications. Preferred Certifications * One or more industry-recognized cybersecurity certifications such as Security+, CySA+, SSCP, GSEC, Microsoft Security (SC-200/AZ-500), or equivalent. * Certifications or training related to ISO 27001, NIST SP 800-171, or NIST SP 800-53 are a plus. Soft Skills * Strong analytical, troubleshooting, and problem-solving skills. * Excellent written, verbal, and technical documentation skills. * Ability to manage multiple priorities while maintaining attention to detail. * Ability to communicate effectively with both technical and non-technical stakeholders. * Collaborative mindset with a commitment to continuous learning and professional growth. #LI-Hybrid ## Description The successful candidate will support compliance with ISO/IEC 27001, the Department of Defense Cybersecurity Maturity Model Certification (CMMC) Level 2, NIST (National Institute of Standards and Technology) Special Publication 800-171 and Special Publication 800-53, along with other cybersecurity standards applicable to U.S. Government contractors. The role supports a cloud-first environment utilizing Microsoft Azure, Oracle Cloud Infrastructure (OCI), and Microsoft 365 and will work closely with IT, engineering, and business stakeholders to strengthen Blue Yonder Defense Solutions overall security posture. Security Tech Stack/Tools: Cloud & Identity Platforms * Azure AD / Entra ID, AWS IAM, Oracle IAM * Federation & SSO: SAML, OAuth, OIDC, SCIM Security, Monitoring & Scanning * SIEM/EDR/XDR (CrowdStrike, Splunk, Elastic etc.) * Defender for Endpoint, Defender for Cloud, Oracle Vulnerability Manager, Amazon Inspector, Tenable, OpenVAS * Identity threat analytics and access risk tooling Automation & Dev Integration PowerShell, Python, REST / SCIM / Graph / SOAP APIs Security Compliance * NIST (National Institute of Standards and Technology) SP 800-171 and SP 800-53 * Cybersecurity Maturity Model Certification (CMMC) Level 2 * ISO/IEC 27001 Information Security Management Standard * CIS (Center for Internet Security) Benchmarks * FedRAMP (Federal Risk and Authorization Management Program) fundamentals What You'll Be Doing: * Conduct regular vulnerability scans across cloud and on-premises assets using industry-standard tools. * Analyze scan results, assess risk, prioritize findings, and recommend remediation activities based on business impact. * Collaborate with IT, infrastructure, and development teams to track, prioritize, and remediate security vulnerabilities. * Develop and maintain automation scripts and reporting processes to support vulnerability management activities. * Support incident response efforts by providing vulnerability context, risk analysis, and remediation guidance. * Document vulnerability management processes, findings, remediation activities, and security recommendations. * Assist with compliance initiatives by providing evidence, reporting, and support for ISO 27001, CMMC Level 2, NIST 800-171, and NIST 800-53 requirements. * Stay current with emerging threats, vulnerability trends, cybersecurity technologies, and industry best practices. * Participate in ongoing efforts to strengthen BYDS's security posture across cloud and enterprise environments ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)