> Markdown version of [/jobs/ext/2941504-vulnerability-security-analyst](https://www.wearedevelopers.com/jobs/ext/2941504-vulnerability-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Security Analyst - **Company:** Caterpillar - **Location:** Nashville, TN, United States - **Experience:** Experienced - **Salary:** $81,370.0 - $122,060.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Command-Line Interface, Cyber Security, Data Visualization, Linux, Intrusion Detection Systems, Python (Programming Language), Network Administration, Power BI, SQL Databases, Tableau (Software), Software Vulnerability Management, Web Applications, Data Processing, Scripting, Software Security, Mitre Att&ck, Firewalls (Computer Science), Information Technology, Servicenow - **Published:** September 16, 2026 - **Apply:** https://www.nashvillejobsite.com/job.asp?id=3392076945&tx=JJ8175FFJ&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Requires a relevant degree or certification in a computer-related field, or 2-4 years of IT experience in security compliance, infrastructure, security analytics, or metrics-focused roles. * Experience with ServiceNow and ServiceNow integrations * Experience with policy exception risk management, balancing security risk against business requirements * Experience with security vulnerability remediation * Experience with enterprise security log collection and management * Experience in metrics collection, analytical, reporting and communication skills * Excellent verbal and written communication skills, with the ability to explain complex data to non-technical stakeholders. * Strong analytical and problem-solving skills * Understanding of current cyberattacks and evolving tactics, techniques, and procedures(TTP's) * Understanding of the MITRE ATT&CK framework Top Candidates will also have: * Knowledge of Caterpillar policies and procedures, and a general understanding of Caterpillar's organization * Proficiency with data visualization tools, such as Tableau or Power BI. * Knowledge of scripting languages, such as Python or SQL, for data manipulation and analysis. * Experience working on a cybersecurity incident response team * Experience in IT security, network administration, operating system administration for Linux, Windows, or macOS, or a technical operations role. This includes experience with command-line tools, services, data manipulation, installation, and system operations. * Drive to learn new things about vulnerability management, exploits, hacker techniques, and overall security operations * Ability to work collaboratively in a complex, rapidly changing, and culturally diverse environment * Self-starter who enjoys significant challenges, change management, and being held accountable to produce quantifiable results * Must have a strong customer focus and ability to work effectively across matrix IT teams * Excellent human relations skills are required to develop a cooperative relationship with others inside and outside of Caterpillar IT. * Must be adaptable to work in a varied, fast paced, ever changing global environment * Help desk, break/fix, or desktop support experience. ## Description Caterpillar's Cybersecurity Team is seeking a Security Analyst to assume a highly technical role on a dynamic team. The Vulnerability Disclosure Team is an innovative and multi-functional team that works to protect Caterpillar's intellectual property across a global enterprise environment. As a member of this team, you will help discover, assess, and address emerging security challenges facing the organization, as well as collect, analyze, and report security-related events and incidents. Ideal candidates would be highly motivated and technically proficient, as well as capable of participating on a team to complete tasks, assignments, and projects in both individual and cooperative group-based contexts. The candidate will be responsible for continuous vulnerability lifecycle management within Caterpillar, including collecting, reporting, and assessing the impact of vulnerability data from internal and external sources. The candidate will also serve as a liaison between Corporate Cybersecurity and business partners to better understand their operations, maintain global security processes, and build collaborative relationships. This role will collect data from security tools and systems, such as intrusion detection systems, firewalls, and incident management platforms, while enhancing metrics collection and reporting to improve security visibility. The Vulnerability Security Analyst will keep up with industry trends as well as the vulnerability threat landscape and partner with other security and IT professionals to assess potential impact from vulnerabilities specific to Caterpillar's environment. What You Will Do: Provide strategic/thought leadership on maturing and optimizing vulnerability management programs focused on web application protection Closely support and collaborate with other cybersecurity teams Ensure the vulnerability management capability is fully interoperable and integrated with existing vulnerability management capabilities Engage with stakeholders, to include IT professionals, management, and auditors to provide remediation assistance as appropriate, including developing reporting and guidance Obtain and maintain knowledge on existing security procedures and directives related to application security and vulnerability management Participate in occasional rotational shift work, including nights, weekends, and 24x7 monitoring coverage. Analyze security events to identify trends, anomalies, and potential threats; prepare clear reports for stakeholders. Collaborate with security engineering, architecture, and SOC teams to implement detection logic and improve threat visibility. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)