> Markdown version of [/jobs/ext/2880848-vulnerability-management-analyst-os-infrastructure](https://www.wearedevelopers.com/jobs/ext/2880848-vulnerability-management-analyst-os-infrastructure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Management Analyst (OS/Infrastructure) - **Company:** Unity Technologies - **Location:** Battle Creek, MI, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Databases, Identity and Access Management, Software Vulnerability Management, Data Logging, Computer Networking Systems, SC Clearance, Vulnerability Analysis - **Published:** September 13, 2026 - **Apply:** https://www.careerjet.com/job/us2ceeace7cd13d8acf03cb19faa6b0590/eaa ## About the Role * A minimum of five (5) years of relevant experience * DoD Approved 8570 Baseline Certification: Category IAM Level II * Hands-on experience working with vulnerability scanners * Understanding of vulnerabilities and remediation techniques Clearance Requirements: * Must be a U.S. citizen * Must possess a current Top-Secret clearance. ## Description We are seeking a Vulnerability Management Analyst (OS/Infrastructure) to join our team. You will serve as a Vulnerability Management Analyst responsible for proactively discovering, assessing, and remediating security risks across enterprise networks, operating systems, and applications. Additionally, you will collaborate with mission partners to prioritize remediation efforts and enforce strict adherence to DoD, Defense Logistics Agency (DLA), and DISA security compliance programs. This position is in Battle Creek, MI. This position may require CONUS and OCONUS travel. Responsibilities include, but are not limited to: * Vulnerability Discovery and Risk Assessment * Conducting targeted manual reviews and utilizing automated vulnerability scanners to identify systemic weaknesses. * Analyzing discovered vulnerabilities and accurately characterizing the operational risk to networks, operating systems, applications, databases, and other core information system components. * Engaging proactively with stakeholders and mission partners to facilitate seamless vulnerability discovery. * Remediation Coordination and Mitigation Strategy * Facilitating and coordinating comprehensive remediation efforts across multiple teams and system owners. * Prioritizing mitigation activities strictly based on characterized risk levels and potential impact. * Recommending appropriate, actionable technical measures to remediate identified vulnerabilities and mitigate overarching systemic risks. * Continuous Monitoring, Validation, and Reporting * Tracking ongoing system security postures and logging compliance issues throughout their lifecycle. * Generating comprehensive reports regarding security status and remediation progress for mission partners. * Validating that applied remedial actions are effective and successfully resolve the targeted vulnerabilities. * Strict DoD and Agency Compliance Enforcement * Ensuring the implementation of mandated security settings, specifically those required by Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIG). * Supporting and enforcing compliance with the overarching DoD Information Assurance Vulnerability Management (IAVM) program. * Validating that all systems and remediation activities adhere strictly to DLA and broader DoD information security policies. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)