1

Senior Vulnerability Management Jobs in Arizona (NOW HIRING)

The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by ... Minimum of 8 years of experience in security operations, vulnerability management, or risk analysis ...

The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by ... Minimum of 8 years of experience in security operations, vulnerability management, or risk analysis ...

The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by ... Minimum of 8 years of experience in security operations, vulnerability management, or risk analysis ...

... senior leadership in concise dashboards. * Control mapping & evidence: Help map vulnerability management practices to regulatory frameworks and collect/curate evidence for audits. * Continuous ...

Security Controls Engineer

Tempe, AZ · On-site

$110 - $160/hr

... vulnerability handling, coordinated disclosure, SBOM transparency, patch management, and post-deployment monitoring. You will track, report, and escal... partnering closely with a Senior Project ...

Sr. Security Engineer

Scottsdale, AZ

$115K - $158K/yr

Overall Purpose This senior position drives the use and availability of the information security tool set, providing a key role in maintaining vulnerability management and configuration management ...

next page

Showing results 1-20

Senior Vulnerability Management information

What does a senior vulnerability management professional do?

A Senior Vulnerability Management professional is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT systems. They lead vulnerability scanning efforts, analyze threats, prioritize remediation actions, and collaborate with IT and security teams to implement solutions. In addition, they often develop vulnerability management policies, provide guidance on best practices, and report on the organization's security posture to leadership. Their role is crucial in reducing the risk of cyberattacks and ensuring compliance with security standards.

What are the key skills and qualifications needed to thrive as a senior vulnerability management professional?

To thrive as a Senior Vulnerability Management professional, you need deep knowledge of cybersecurity principles, threat analysis, and risk assessment, often supported by a relevant degree and certifications like CISSP, CISM, or CompTIA Security+. Familiarity with vulnerability scanning tools (e.g., Nessus, Qualys), patch management systems, and security information and event management (SIEM) platforms is required. Strong analytical thinking, communication, and leadership skills are vital for prioritizing risks and collaborating across teams. These competencies are crucial for identifying, mitigating, and communicating security vulnerabilities to protect organizational assets and ensure regulatory compliance.

What are some common challenges faced by senior vulnerability management professionals, and how can they be addressed?

Senior Vulnerability Management professionals often encounter challenges such as prioritizing vulnerabilities based on risk, coordinating remediation efforts across multiple teams, and managing a high volume of security findings. Addressing these challenges requires strong communication skills to collaborate effectively with IT, development, and business units, as well as the use of automation tools to streamline vulnerability scanning and reporting. Staying current with threat intelligence and regulatory requirements also helps in accurately assessing risks and ensuring comprehensive coverage.

What is the difference between Senior Vulnerability Management vs Vulnerability Analyst?

AspectSenior Vulnerability ManagementVulnerability Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CEH
Work EnvironmentOversees vulnerability programs, manages teams, develops strategiesPerforms vulnerability scans, analyzes findings, reports issues
Employer & Industry UsageUsed in large organizations, cybersecurity teams, IT departmentsCommon in security operations centers, IT security teams

Senior Vulnerability Management roles focus on leading vulnerability programs, strategy, and team management, while Vulnerability Analysts primarily conduct scans and analyze vulnerabilities. Both roles require similar certifications but differ in scope and responsibilities within cybersecurity teams.

What are the most commonly searched types of Vulnerability Management jobs in Arizona?

The most popular types of Vulnerability Management jobs in Arizona are:

What job categories do people searching Senior Vulnerability Management jobs in Arizona look for?

The top searched job categories for Senior Vulnerability Management jobs in Arizona are:

What cities in Arizona are hiring for Senior Vulnerability Management jobs?

Cities in Arizona with the most Senior Vulnerability Management job openings:

Senior Vulnerability Management Analyst

Osaic

Scottsdale, AZ • On-site

$105K - $120K/yr

Other

Medical, Dental, Vision, Retirement

This job post has expired 1 day ago. Applications are no longer accepted.


Osaic rating

8.1

Company rating: 8.1 out of 10

Based on 12 frontline employees who took The Breakroom Quiz


Job description

Current Employees and Contractors Apply HereOsaic Careers

IT Vulnerability Opportunity in Financial Services

Senior Vulnerability Management Analyst

Location(s):

Atlanta: 2300 Windy Ridge Pkwy SE, Suite750, Atlanta, GA 30339

La Vista:12325 Port Grace Blvd, La Vista, NE 68128

Oakdale: 7755 3rd St. N, Oakdale, MN 55128

Scottsdale: 18700 N Hayden Rd, Suite 255, Scottsdale, AZ 85255

St. Petersburg: 877 Executive Center Dr. W, Suite 300, St. Petersburg, FL 33702

Osaic has returned to the office on a hybrid schedule requiring a minimum of 4 days weekly in the office. Applicants should be located at one of our hubs listed above and must be willing to work this schedule.

Role Type: Full-time, Non-Exempt

Salary: $105,000 - $120,000 per year + annual performance-based bonus

Actual compensation offered will be determined individually, based on a number of job-related factors, including location, skills, licensure, experience, and education.

Our competitive compensation is just one component of Osaic's total compensation package. Additional benefits include health, vision, dental insurance, 401k, paid time away, volunteer days and much more. To view more details of what you can look forward to, visit our careers page:Osaic Benefits.

Summary:

We're seeking a Senior Vulnerability Analyst to lead and mature our enterprise vulnerability programs across SDLC (secure development lifecycle), external attack surface, and internal infrastructure/applications. This role drives endtoend vulnerability lifecycle management, from discovery and risk triage to remediation validation and program metrics, while partnering closely with Engineering, Product, Cloud/SRE, and IT. You'll also coordinate penetration testing readiness, evidence collection, and remediation plans, and help embed security into the development workflow. The ideal candidate has strong application development experience, practical threat modeling skills, and a pragmatic approach to risk.

Education Requirements:

Bachelor's degree preferred, high school diploma (or equivalent) in combination with significant experience will be considered in lieu of degree. Minimum of high school diploma or equivalent is required.

Responsibilities:

  • Lead vulnerability prioritization using CVSS, KEV, exploit intel, and asset criticality.
  • Partner with engineering and application teams to remove remediation blockers.
  • Own complex vulnerability investigations and coordinate cross-team resolution.
  • Mentor junior analysts and help improve internal processes.
  • Provide remediation guidance and secure configuration recommendations.
  • Help with pen test prework: scope definition, rules of engagement, asset inventories, credential/test data coordination, and stakeholder comms.
  • Manage findings intake, severity validation, and remediation plans with accountable owners; track to closure and report to leadership.
  • Lead lessons learned and control improvements to reduce recurring issues and improve test efficiency.
  • Lead continuous reduction of external attack surface: internetexposed services, DNS, certificates, cloud perimeters, API endpoints, and thirdparty exposures.
  • Partner with Cloud, SRE, and Networking to harden configurations, minimize unknown/legacy exposures, and validate fixes.
  • Partner with engineering to mature SAST/DAST/IAST/OSS/SBOM practices, secure build pipelines, and implement "shiftleft" controls (precommit, PR gates, CI quality bars).
  • Guide threat modeling, security requirements, and secure coding practices; advise on remediation patterns and safer libraries/frameworks.
  • Review architecture and code for highrisk components (authN/Z, crypto, secrets handling, supply chain, multitenant boundaries).
  • All other duties as assigned.

Basic Requirements:

  • Deep technical/domain expertise and ability to lead initiatives.
  • Strong understanding of OS, cloud environments, and vulnerability lifecycles.
  • Partner with Detection & Response to ensure logging, alerting, and containment strategies account for known weaknesses.
  • Target certifications: CISSP, GIAC (GSEC/GCIA/GCIH), CCSP.

Preferred Requirements:

  • Experience with KEV catalog operationalization and threat-intel integrations.
  • Knowledge of automation platforms
Current Employees and Contractors Apply Here

What Osaic employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Osaic logo

About Osaic

Sourced by ZipRecruiter

Industry

Finance and insurance

Company size

1,001 - 5,000 Employees

Headquarters location

Phoenix, AZ, US

Year founded

2016