Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Overview This is aremote role in NC, AZ, and TX. We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role ...
Associate Application Security Engineer - Bug Bounty & Vulnerability Management
Raleigh, NC · On-site +1
$57 - $76.25/hr
Applies cybersecurity expertise to analyze findings, identify trends, improve vulnerability response processes, and help strengthen the organization's overall security posture while continuously ...
Associate Application Security Engineer - Bug Bounty & Vulnerability Management
Raleigh, NC · On-site +1
$57 - $76.25/hr
Applies cybersecurity expertise to analyze findings, identify trends, improve vulnerability response processes, and help strengthen the organization's overall security posture while continuously ...
Vulnerability Management Engineer- Hybrid | Cary, NC We're a leader in data and AI. Through our ... Analyze and prioritize vulnerabilities to help the business understand the security impact. * Track ...
Vulnerability Management Engineer- Hybrid | Cary, NC We're a leader in data and AI. Through our ... Analyze and prioritize vulnerabilities to help the business understand the security impact. * Track ...
Vulnerability Management Engineer- Hybrid | Cary, NC We're a leader in data and AI. Through our ... Analyze and prioritize vulnerabilities to help the business understand the security impact. * Track ...
Vulnerability Management Engineer- Hybrid | Cary, NC We're a leader in data and AI. Through our ... Analyze and prioritize vulnerabilities to help the business understand the security impact. * Track ...
Should be able to collect feedback and analyze weak areas and present the same to management * Should be able to collect gaps in vulnerability management processes and provide optimization ...
Quick apply
Should be able to collect feedback and analyze weak areas and present the same to management * Should be able to collect gaps in vulnerability management processes and provide optimization ...
Senior Vulnerability Management Engineer
Raleigh, NC · On-site
$111K - $152K/yr
Execute comprehensive vulnerability scans across various technological domains including network ... CSPM), Software Composition Analysis (SCA), and Static Application Security Testing (SAST)
Senior Vulnerability Management Engineer
Raleigh, NC · On-site
$111K - $152K/yr
Execute comprehensive vulnerability scans across various technological domains including network ... CSPM), Software Composition Analysis (SCA), and Static Application Security Testing (SAST)
Security Analyst
Morrisville, NC · On-site
Perform authenticated and unauthenticated vulnerability scans across enterprise systems. * Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited ...
Security Analyst
Morrisville, NC · On-site
Perform authenticated and unauthenticated vulnerability scans across enterprise systems. * Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited ...
DevSecOps Analyst
Morrisville, NC · On-site
The successful candidate will possess hands-on experience with vulnerability management platforms ... Analyze vulnerability results. * Track remediation activities. * Conduct risk assessments.
DevSecOps Analyst
Morrisville, NC · On-site
The successful candidate will possess hands-on experience with vulnerability management platforms ... Analyze vulnerability results. * Track remediation activities. * Conduct risk assessments.
Security Analyst
Morrisville, NC · Hybrid
Perform authenticated and unauthenticated vulnerability scans across enterprise systems. * Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited ...
Security Analyst
Morrisville, NC · Hybrid
Perform authenticated and unauthenticated vulnerability scans across enterprise systems. * Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited ...
DevSecOps Analyst
Morrisville, NC · On-site
The successful candidate will possess hands-on experience with vulnerability management platforms ... Analyze vulnerability results. * Track remediation activities. * Conduct risk assessments.
DevSecOps Analyst
Morrisville, NC · On-site
The successful candidate will possess hands-on experience with vulnerability management platforms ... Analyze vulnerability results. * Track remediation activities. * Conduct risk assessments.
Perform authenticated and unauthenticated vulnerability scans across enterprise systems. * Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited ...
Perform authenticated and unauthenticated vulnerability scans across enterprise systems. * Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited ...
The successful candidate will possess hands-on experience with vulnerability management platforms ... Analyze vulnerability results. * Track remediation activities. * Conduct risk assessments.
The successful candidate will possess hands-on experience with vulnerability management platforms ... Analyze vulnerability results. * Track remediation activities. * Conduct risk assessments.
Senior Vulnerability Management Engineer
Raleigh, NC · On-site
$101K - $139K/yr
Execute comprehensive vulnerability scans across various technological domains including network ... Analysis (SCA), and Static Application Security Testing (SAST). * Provide actionable intelligence ...
Senior Vulnerability Management Engineer
Raleigh, NC · On-site
$101K - $139K/yr
Execute comprehensive vulnerability scans across various technological domains including network ... Analysis (SCA), and Static Application Security Testing (SAST). * Provide actionable intelligence ...
Perform vulnerability analysis and remediation coordination for applications. * Facilitate and advise application teams on remediation as needed, including vulnerability burndown. * Assist with ...
Perform vulnerability analysis and remediation coordination for applications. * Facilitate and advise application teams on remediation as needed, including vulnerability burndown. * Assist with ...
Lead Vulnerability Remediation Engineer - Infrastructure Engineer
Raleigh, NC · On-site
$120 - $180/hr
Perform vulnerability identification and prioritization using Qualys and/or other security agents ... Lead or co‑lead root cause analysis for recurring endpoint issues and systemic remediation ...
Lead Vulnerability Remediation Engineer - Infrastructure Engineer
Raleigh, NC · On-site
$120 - $180/hr
Perform vulnerability identification and prioritization using Qualys and/or other security agents ... Lead or co‑lead root cause analysis for recurring endpoint issues and systemic remediation ...
Executing vulnerability and patch management tasks across infrastructure, middleware, and ... Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize ...
Executing vulnerability and patch management tasks across infrastructure, middleware, and ... Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize ...
Vulnerability Analyst information
See Raleigh, NC salary details
$30.1K - $38.9K
11% of jobs
$38.9K - $47.6K
9% of jobs
$50.6K is the 25th percentile. Wages below this are outliers.
$47.6K - $56.4K
15% of jobs
$56.4K - $65.1K
15% of jobs
The median wage is $65.4K / yr.
$65.1K - $73.9K
18% of jobs
$80.2K is the 75th percentile. Wages above this are outliers.
$73.9K - $82.6K
11% of jobs
$82.6K - $91.4K
7% of jobs
$91.4K - $100.1K
5% of jobs
$100.1K - $108.9K
4% of jobs
$108.9K - $117.6K
2% of jobs
$117.6K - $126.4K
3% of jobs
$30.1K
$71.2K
$126.4K
How much do vulnerability analyst jobs pay per year?
What are the key skills and qualifications needed to thrive as a vulnerability analyst, and why are they important?
To thrive as a Vulnerability Analyst, you need expertise in cybersecurity principles, risk assessment, and vulnerability management, often supported by a degree in information security or a related field. Familiarity with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7), knowledge of operating systems, and certifications like CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart. These abilities are crucial for accurately identifying system weaknesses and effectively advising teams on how to remediate security threats.
What are the typical day-to-day responsibilities of a vulnerability analyst?
As a Vulnerability Analyst, your daily tasks often include running vulnerability scans, analyzing findings, prioritizing risks based on severity, and working with IT or development teams to coordinate remediation efforts. You will also document your findings, prepare reports for stakeholders, and stay informed about the latest security threats and exploits. Collaboration with other security professionals and IT staff is common, as resolving vulnerabilities often requires cross-functional teamwork. This role requires a balance of technical analysis and effective communication to ensure organizational security posture is continuously improved.
What is a vulnerability analyst?
A Vulnerability Analyst is a cybersecurity professional responsible for identifying, assessing, and mitigating security weaknesses in an organization's systems, networks, and applications. They use tools like vulnerability scanners, penetration testing frameworks, and security assessments to identify potential threats. Their role includes analyzing vulnerabilities, prioritizing risks, and working with IT and security teams to implement necessary patches or fixes. They also stay up to date with emerging threats and ensure compliance with security policies and regulations.

Cyber Security Analyst III - App Security & Vulnerability (Remote)
Raleigh, NC • On-site
Other
Re-posted 17 days ago
First Citizens Bank rating
7.4
Based on 106 frontline employees who took The Breakroom Quiz
109th of 171 rated banks
Job description
This is aremote role in NC, AZ, and TX.
We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role focuses on identifying, analyzing, and mitigating security risks across software development pipelines using SAST, DAST, and SCA tools. The ideal candidate combines hands-on technical expertise with knowledge of modern security practices and emerging technologies, including AI/ML.
Responsibilities
Application Security & Code Analysis
- Perform static (SAST), dynamic (DAST), and software composition analysis (SCA) to identify vulnerabilities in applications and third-party components
- Analyze scan results, triage findings, and prioritize remediation efforts based on risk
- Partner with development teams to remediate vulnerabilities and improve secure coding practices
Vulnerability Management
- Conduct regular security assessments and vulnerability scans across applications and environments
- Validate and reproduce vulnerabilities, including false positive elimination
- Track and report vulnerability metrics, risk trends, and remediation progress
Security Tools & Automation
- Configure, deploy, and maintain security scanning tools (e.g., Checkmarx, Veracode, Fortify, Snyk, Burp Suite, OWASP ZAP)
- Automate security testing processes using scripting or APIs
- Improve scanning efficiency and coverage through tuning and optimization
Qualifications
Bachelor's Degree and 6 years of experience in Information Security OR High School Diploma or GED and 10 years of experience in Information Security
Required Qualifications
- Hands-on experience with:
- SAST, DAST, and SCA tools
- Web application security testing (OWASP Top 10, API security)
- Strong understanding of:
- Secure software development lifecycle (SDLC / DevSecOps)
- Common vulnerabilities (e.g., injection, XSS, authentication flaws)
- Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash)
- Experience interpreting and prioritizing scan results and remediation plans
Preferred Qualifications
- Experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps)
- Familiarity of container and cloud security (AWS, Azure, Google Cloud Platform)
- Familiarity with AI/ML concepts and security implications
- Industry certifications such as:
- CEH, Security+, SSCP, GIAC or comparable.
Key Skills
- Strong analytical and problem-solving skills
- Provide risk-based recommendations to stakeholders
- Ability to communicate technical findings to both technical and non-technical stakeholders
- Experience working cross-functionally with development and engineering teams
- Attention to detail with a risk-based security mindset
Nice-to-Have Experience
- API security testing tools (Postman, SoapUI)
- AI-assisted security tooling (e.g., anomaly detection, code analysis assistants)
- Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2)
- AI/ML & Emerging Technologies
- Leverage AI/ML-based security tools for enhanced detection and analysis
- Assess risks related to AI/ML models (e.g., data poisoning, model inversion, adversarial attacks)
- Participate in securing AI-driven applications and data pipelines
- Threat Analysis & Risk Management
- Assess potential threats and attack vectors relevant to applications and APIs
- Apply threat modeling techniques (e.g., STRIDE) during development lifecycle
Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at
$descr2
$descr3
What First Citizens Bank employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom