1

Vulnerability Management Analyst Jobs in Ohio (NOW HIRING)

Analyze threat intelligence, exploit data, CVSS scores, and emerging vulnerabilities to support ... Manage vulnerability exceptions, false-positive handling, and risk acceptance processes. * Create ...

$95K - $123K/yr

Oversees and manages the Vulnerability Management program, reports on Woodward's progress ... Expertise in analyzing current policy, identifying contemporary language changes, working with ...

next page

Showing results 1-20

Vulnerability Management Analyst information

What is a vulnerability management analyst?

A Vulnerability Management Analyst is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT infrastructure. They use scanning tools, analyze threat data, and collaborate with teams to prioritize and remediate risks. Their role is crucial in maintaining cybersecurity by ensuring systems are patched and configured securely. Additionally, they may develop reports and provide recommendations to improve security posture. This position requires knowledge of security frameworks, risk assessment, and vulnerability management tools.

What are the typical daily responsibilities of a vulnerability management analyst?

On a typical day, a Vulnerability Management Analyst reviews system scans, analyzes reports for potential vulnerabilities, and works with IT or security teams to prioritize remediation efforts. They may also track the status of vulnerabilities, ensure timely patch application, and help develop or update security policies. Collaboration with various departments is common to coordinate testing, remediation, and communicate risk summary findings. This role requires keeping up with emerging threats and sometimes participating in security audits or compliance reviews, making it both dynamic and integral to the organization's overall cybersecurity posture.

What are the key skills and qualifications needed to thrive as a vulnerability management analyst?

A Vulnerability Management Analyst requires a strong background in cybersecurity principles, risk assessment, and IT networking, often supported by a relevant degree or certifications like CompTIA Security+, CISSP, or CEH. Experience with vulnerability scanning tools (such as Nessus, Qualys, or Rapid7) and familiarity with ticketing systems or SIEM platforms is essential. Strong analytical skills, attention to detail, effective communication, and the ability to work collaboratively help individuals succeed in this role. These capabilities are vital to proactively identify, assess, and mitigate security vulnerabilities, ensuring the organization's digital assets remain secure and compliant.

What are the most commonly searched types of Vulnerability Management Analyst jobs in Ohio?

The most popular types of Vulnerability Management Analyst jobs in Ohio are:

What are popular job titles related to Vulnerability Management Analyst jobs in Ohio?

For Vulnerability Management Analyst jobs in Ohio, the most frequently searched job titles are:

What job categories do people searching Vulnerability Management Analyst jobs in Ohio look for?

The top searched job categories for Vulnerability Management Analyst jobs in Ohio are:

What cities in Ohio are hiring for Vulnerability Management Analyst jobs?

Cities in Ohio with the most Vulnerability Management Analyst job openings:

Infographic showing various Vulnerability Management Analyst job openings in Ohio as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution.

Vulnerability Management Specialist

Core Specialty

Cincinnati, OH • On-site

Full-time

Medical, Dental, Vision, Life, Retirement

Re-posted 26 days ago


Job description

The Vulnerability Management Specialist is a hands-on individual contributor responsible for executing Core Specialty's vulnerability management program across endpoints, servers, cloud resources, and applications. This role focuses on continuous vulnerability scanning, risk analysis, remediation coordination, and reporting, working closely with IT, Infrastructure, Endpoint, and Threat teams.
The ideal candidate is highly analytical, detail-oriented, and comfortable operating in a metrics-driven, SLA-based environment, with the ability to translate technical findings into actionable remediation guidance.
The selected candidate will be required to work a hybrid schedule (3 days in office/2 remote) out of our Dallas, TX, or Cincinnati, OH office. No relocation assistance is being offered with this role.
Key Accountabilities/Deliverables:
  • Conduct continuous vulnerability scanning across enterprise assets using Qualys and related tools.
  • Analyze scan results to validate findings, remove false positives, and assess exploitability.
  • Prioritize vulnerabilities using CVSS, Qualys Detection Score (QDS), asset criticality, and business impact.
  • Enforce remediation SLAs aligned to severity levels: Critical: 7 days, High: 30 days, Medium: 60 days, Low: 180 days.
  • Partner with Infrastructure, EUC, Cloud, and Application teams to drive timely remediation.
  • Support remediation activities using Qualys, Intune, JAMF, PolicyPak, and Microsoft Defender.
  • Ensure vulnerability management activities aligned with NIST, CIS Controls, ISO 27001, and insurance regulatory expectations.
  • Partner with Threat Intelligence and SOC teams to assess vulnerability exposure related to active threats.
  • Develop scripts (PowerShell) and workflows to support remediation, reporting, and validation.

Technical Knowledge and Understanding:
  • Strong understanding of: CVSS scoring and risk prioritization, patch management and remediation workflows, endpoint, server, and cloud security fundamentals.
  • Ability to analyze technical findings and communicate risk clearly to non-security teams.
  • Strong documentation and organizational skills.

Experience required:
  • 4+ years of experience in vulnerability management, security engineering, or threat operations.
  • Hands-on experience with vulnerability scanning platforms (Qualys preferred; Tenable/Rapid7 acceptable).
  • Experience working with Intune, JAMF, or similar endpoint management tools.

Certifications (Preferred):
  • CompTIA Security+
  • Qualys Vulnerability Management certifications
  • GIAC certifications (e.g., GSEC, GCIH)
  • CISSP (or progress toward certification)

Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa for this position.
#LI-Hybrid
At Core Specialty, you will receive a competitive salary and opportunities for professional development and advancement. We offer medical, dental, vision, and life insurances; short and long-term disability; a Company-match of 100% of a 6% contribution 401(k) plan; an Employee Assistance Plan; Health Savings Account, Flexible Spending Account, Health Reimbursement Account, and a wellness program