> Markdown version of [/jobs/ext/506118-vulnerability-analyst-level-ii-it-systems-specialist-its-department-temporary-full-time](https://www.wearedevelopers.com/jobs/ext/506118-vulnerability-analyst-level-ii-it-systems-specialist-its-department-temporary-full-time). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Analyst -Level II (IT Systems Specialist) - ITS Department - Temporary Full Time - **Company:** City of Phoenix - **Location:** Phoenix, AZ, United States (Remote available) - **Experience:** Experienced - **Salary:** $84,469.0 - $118,872.0 - **Contract:** Temporary contract - **Skills:** Amazon Web Services, Microsoft Azure, CompTIA Security+, Cyber Security, Information Systems, DevOps, Open Web Application Security, PCI Data Security Standards, Software Vulnerability Management, Google Cloud, Cloud Platform System, Cyber Threat Analysis, Information Technology, Tenable Nessus, CIS Benchmarks, Cisco, Qualys, Vulnerability Analysis - **Published:** June 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=49a34379b4824cca ## About the Role Do you have experience in Writing skills?, * Detail-oriented with a strong sense of accountability. * Comfortable working in a fast-paced, high-security environment. * Excellent written and verbal communication and presentation skills. * Knowledge of: + Cloud environments (AWS, Azure, GCP) and related vulnerabilities. + Threat intelligence concepts and emerging vulnerability trends. * Ability to: + Communicate tactfully, verbally and in writing, with department heads, managers, coworkers and vendors to resolve problems, and negotiate resolutions. + Work independently and as part of a team., * Three years of responsible experience in cybersecurity, information technology security, or vulnerability management. * Other combinations of experience and education that meet the minimum requirements may be substituted. * This position is subject to Criminal Justice Information Systems (CJIS) background standards. Candidates who receive a conditional offer of employment must be fingerprinted and will have their fingerprints used to check the Criminal History Records of the State of Arizona Department of Public Safety and the Federal Bureau of Investigation. Any records returned will be reviewed to determine the candidate's suitability for the job. * All finalists for positions are subject to a criminal background check applicable to the department or position. * Some positions require the use of personal or City vehicles on City business. Individuals must be physically capable of operating the vehicles safely, possess a valid driver's license and have an acceptable driving record. Use of a personal vehicle for City business will be prohibited if the employee is not authorized to drive a City vehicle or if the employee does not have personal insurance coverage. For information regarding pre-screening and driving positions, The minimum qualifications listed above, plus: * Two years of experience performing vulnerability assessments and using tools such as Tenable Nessus, Qualys, or Rapid7. * Experience with/in: + Analyzing risk, validate findings, and document remediation efforts clearly. + Cloud environments (AWS, Azure, GCP) and related vulnerabilities. + Common vulnerabilities (OWASP Top 10, CVEs) and related remediation techniques. + Security frameworks such as NIST, and CIS Controls. * Professional certifications supporting cybersecurity or vulnerability management, such as CompTIA Security+, CTIA, GCTI, CISSP, CEH, Cisco CyberOps Associate, or OSCP. ## Description The ITS department is seeking Vulnerability Analysts level II (ITSS) to join the Vulnerability Management Team within the Information Security Operations and Intelligence Division. Vulnerability Analysts level II (ITSS) serve as a proactive defense strategists safeguarding the City's digital infrastructure The Vulnerability Analyst role is responsible for identifying, analyzing, and helping to remediate vulnerabilities in the organization's systems, networks, and applications. This role involves proactive scanning, threat assessments, risk prioritization, and collaboration with IT and development teams to ensure a strong security posture., * Perform regular vulnerability assessments using tools such as Tenable Nessus, Qualys, Rapid7, or similar. * Analyze scan results, validate findings, and determine risk levels. * Track and report vulnerabilities, recommending remediation steps based on risk severity. * Collaborate with IT, DevOps, and system owners to remediate vulnerabilities. * Maintain and update vulnerability scanning tools and systems. * Monitor threat intelligence feeds to stay ahead of emerging vulnerabilities and exploits. * Develop metrics and dashboards to communicate vulnerability trends and compliance status. * Ensure all vulnerability management processes align with compliance requirements (e.g., ISO 27001, NIST, PCI-DSS). * Document processes, findings, and remediation efforts in a clear and auditable manner. * Participate in incident response activities if a vulnerability is exploited. Please note: This is a remote position which is eligible to telework up to five days a week, at department discretion and requires the ability to attend meetings and trainings in-person at a designated City work location when required, based on operational needs. This position requires participation in cyber emergency incidents. This position will be funded through June 2027 with a possibility to be made regular in a future budget cycle. The temporary position will have benefits but will not earn city retirement credits or participate financially into the city's retirement program. If the successful candidate is a current City employee, all benefits will still be applicable, and the employee will still contribute to their pension. Temporary positions are not covered under civil service rules, and thus employment is considered "at-will", and employees may be separated at any time. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)