Vulnerability Analyst -Level II (IT Systems Specialist) - ITS Department - Temporary Full Time
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+6 more
Job description
The ITS department is seeking Vulnerability Analysts level II (ITSS) to join the Vulnerability Management Team within the Information Security Operations and Intelligence Division. Vulnerability Analysts level II (ITSS) serve as a proactive defense strategists safeguarding the City’s digital infrastructure
The Vulnerability Analyst role is responsible for identifying, analyzing, and helping to remediate vulnerabilities in the organization’s systems, networks, and applications. This role involves proactive scanning, threat assessments, risk prioritization, and collaboration with IT and development teams to ensure a strong security posture., * Perform regular vulnerability assessments using tools such as Tenable Nessus, Qualys, Rapid7, or similar.
- Analyze scan results, validate findings, and determine risk levels.
- Track and report vulnerabilities, recommending remediation steps based on risk severity.
- Collaborate with IT, DevOps, and system owners to remediate vulnerabilities.
- Maintain and update vulnerability scanning tools and systems.
- Monitor threat intelligence feeds to stay ahead of emerging vulnerabilities and exploits.
- Develop metrics and dashboards to communicate vulnerability trends and compliance status.
- Ensure all vulnerability management processes align with compliance requirements (e.g., ISO 27001, NIST, PCI-DSS).
- Document processes, findings, and remediation efforts in a clear and auditable manner.
- Participate in incident response activities if a vulnerability is exploited.
Please note: This is a remote position which is eligible to telework up to five days a week, at department discretion and requires the ability to attend meetings and trainings in-person at a designated City work location when required, based on operational needs. This position requires participation in cyber emergency incidents.
This position will be funded through June 2027 with a possibility to be made regular in a future budget cycle. The temporary position will have benefits but will not earn city retirement credits or participate financially into the city’s retirement program. If the successful candidate is a current City employee, all benefits will still be applicable, and the employee will still contribute to their pension. Temporary positions are not covered under civil service rules, and thus employment is considered “at-will”, and employees may be separated at any time.
Requirements
Do you have experience in Writing skills?, * Detail-oriented with a strong sense of accountability.
- Comfortable working in a fast-paced, high-security environment.
- Excellent written and verbal communication and presentation skills.
- Knowledge of:
- Cloud environments (AWS, Azure, GCP) and related vulnerabilities.
- Threat intelligence concepts and emerging vulnerability trends.
- Ability to:
- Communicate tactfully, verbally and in writing, with department heads, managers, coworkers and vendors to resolve problems, and negotiate resolutions.
- Work independently and as part of a team., * Three years of responsible experience in cybersecurity, information technology security, or vulnerability management.
- Other combinations of experience and education that meet the minimum requirements may be substituted.
- This position is subject to Criminal Justice Information Systems (CJIS) background standards. Candidates who receive a conditional offer of employment must be fingerprinted and will have their fingerprints used to check the Criminal History Records of the State of Arizona Department of Public Safety and the Federal Bureau of Investigation. Any records returned will be reviewed to determine the candidate’s suitability for the job.
- All finalists for positions are subject to a criminal background check applicable to the department or position.
- Some positions require the use of personal or City vehicles on City business. Individuals must be physically capable of operating the vehicles safely, possess a valid driver’s license and have an acceptable driving record. Use of a personal vehicle for City business will be prohibited if the employee is not authorized to drive a City vehicle or if the employee does not have personal insurance coverage. For information regarding pre-screening and driving positions, The minimum qualifications listed above, plus:
- Two years of experience performing vulnerability assessments and using tools such as Tenable Nessus, Qualys, or Rapid7.
- Experience with/in:
- Analyzing risk, validate findings, and document remediation efforts clearly.
- Cloud environments (AWS, Azure, GCP) and related vulnerabilities.
- Common vulnerabilities (OWASP Top 10, CVEs) and related remediation techniques.
- Security frameworks such as NIST, and CIS Controls.
- Professional certifications supporting cybersecurity or vulnerability management, such as CompTIA Security+, CTIA, GCTI, CISSP, CEH, Cisco CyberOps Associate, or OSCP.
Benefits & conditions
4.14.1 out of 5 stars 200 W Washington St FL 11, Phoenix, AZ 85003 $84,468.80 - $118,872.00 a year - Temporary, Full-time, Pulled from the full job description
- Loan forgiveness
- Tuition reimbursement
- Paid parental leave
- Parental leave
- Health insurance
- Paid time off
- Vision insurance, Pay Range: $84,468.80 to $118,872.00 annually.
Hiring Range: $84,468.80 to $107,806.40 annually.
Pay Range Explanation:
- Pay range is the entire compensation range for the position classification.
- Hiring range is an estimate of where you can receive an offer. The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, education, licenses, training, and internal equity.
Internal Only: Please understand that this is pay grade 063. If selected, your salary offer will be based on the applicable promotion or demotion worksheet in accordance with the City Pay Ordinance.
- Promotions occur when the last two digits of the pay grade increase.
- Demotions occur when the last two digits of the pay grade decrease.
- Lateral transfers occur when there is no change to the last two digits of the pay grade.
- When there is a change in the first digit of the pay grade, there may also be a change to your classification or unit.
Your job classification can be found in eCHRIS > Personal Details under your name, located in the top left section of the page., A comprehensive benefits package is offered which includes: Traditional pension with employer and employee contributions,
- for more details: Pension Information
- 401(a) and 457 plans with employer contributions
- Choice of generous medical HMO, PPO, or HSA/HDHP plans
- Medical enrollment includes a monthly $150 City contribution to a Post-Employment Health Plan
- Wellness incentive of up to $720 annually
- Dental, vision, and life insurance options
- Employer paid long-term disability
- Free Bus/light rail pass
- Tuition reimbursement program up to $6,500 per year
- Paid time off includes 13.5 paid holidays, 12 vacation days, and 15 sick days and personal leave days
- Paid Parental Leave for eligible employees up to 480 hours (12 weeks) of paid leave for the birth, adoption, or foster care placement of a child during a 12-month period
- Federal Student Loan Forgiveness offered through Savi
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
Dev Digest 134 - Where pixels sing?
What Are The Top Skills Required For Azure Developers?