Use approved vulnerability management, cloud security, CSPM/CNAPP, container, code-scanning, and external attack-surface tools to identify vulnerabilities, misconfigurations, exposed services ...
Use approved vulnerability management, cloud security, CSPM/CNAPP, container, code-scanning, and external attack-surface tools to identify vulnerabilities, misconfigurations, exposed services ...
Analyze vulnerability data from scanners and toolsets (e.g., Qualys, Tenable, Rapid7) and translate findings into actionable insights * Support lifecycle processes including vulnerability ...
Analyze vulnerability data from scanners and toolsets (e.g., Qualys, Tenable, Rapid7) and translate findings into actionable insights * Support lifecycle processes including vulnerability ...
Cybersecurity Project Manager (Vulnerability Management)
Juno Beach, FL · On-site
$60 - $65/hr
Ability to interpret vulnerability scan results and collaborate with teams for remediation. * Experience configuring and performing vulnerability scans In a corporate landscape * Understanding of ...
Quick apply
Cybersecurity Project Manager (Vulnerability Management)
Juno Beach, FL · On-site
$60 - $65/hr
Ability to interpret vulnerability scan results and collaborate with teams for remediation. * Experience configuring and performing vulnerability scans In a corporate landscape * Understanding of ...
Ability to interpret vulnerability scan results and collaborate with teams for remediation. * Experience configuring and performing vulnerability scans In a corporate landscape * Understanding of ...
Ability to interpret vulnerability scan results and collaborate with teams for remediation. * Experience configuring and performing vulnerability scans In a corporate landscape * Understanding of ...
Key Responsibilities ● Perform vulnerability scanning, STIG assessments, and security compliance monitoring ● Develop and manage POA&Ms for identified vulnerabilities in compliance with DoD ...
Key Responsibilities ● Perform vulnerability scanning, STIG assessments, and security compliance monitoring ● Develop and manage POA&Ms for identified vulnerabilities in compliance with DoD ...
INFORMATION SECURITY ANALYST IV - 43004418
$90K - $110K/yr
Five (5) or more years of experience administering enterprise vulnerability scanning and reporting tools in large-scale environments. * Excellent interpersonal and communication skills (English ...
INFORMATION SECURITY ANALYST IV - 43004418
$90K - $110K/yr
Five (5) or more years of experience administering enterprise vulnerability scanning and reporting tools in large-scale environments. * Excellent interpersonal and communication skills (English ...
INFORMATION SECURITY ANALYST IV - 43004418
Tallahassee, FL · On-site
$90K - $110K/yr
Five (5) or more years of experience administering enterprise vulnerability scanning and reporting tools in large-scale environments. * Excellent interpersonal and communication skills (English ...
INFORMATION SECURITY ANALYST IV - 43004418
Tallahassee, FL · On-site
$90K - $110K/yr
Five (5) or more years of experience administering enterprise vulnerability scanning and reporting tools in large-scale environments. * Excellent interpersonal and communication skills (English ...
INFORMATION SECURITY ANALYST IV - 43004418
$90K - $110K/yr
Five (5) or more years of experience administering enterprise vulnerability scanning and reporting tools in large-scale environments. * Excellent interpersonal and communication skills (English ...
INFORMATION SECURITY ANALYST IV - 43004418
$90K - $110K/yr
Five (5) or more years of experience administering enterprise vulnerability scanning and reporting tools in large-scale environments. * Excellent interpersonal and communication skills (English ...
Network Vulnerability Scanning (Nessus/Tenable) * Advanced User Authentication Structures (Cisco ACS and RSA ACE servers) * OS Hardening and Security: IBMi Series, Linux, Mac, Windows * Application ...
Network Vulnerability Scanning (Nessus/Tenable) * Advanced User Authentication Structures (Cisco ACS and RSA ACE servers) * OS Hardening and Security: IBMi Series, Linux, Mac, Windows * Application ...
Senior Cyber Security Engineer
Tampa, FL · On-site
Network Vulnerability Scanning (Nessus/Tenable) * Advanced User Authentication Structures (Cisco ACS and RSA ACE servers) * OS Hardening and Security: IBMi Series, Linux, Mac, Windows * Application ...
Senior Cyber Security Engineer
Tampa, FL · On-site
Network Vulnerability Scanning (Nessus/Tenable) * Advanced User Authentication Structures (Cisco ACS and RSA ACE servers) * OS Hardening and Security: IBMi Series, Linux, Mac, Windows * Application ...
Guide web application vulnerability scanning and remediation for each release. *Provide expert-level interpretation of findings, risk evaluation, and remediation guidance. *Lead vulnerability ...
Guide web application vulnerability scanning and remediation for each release. *Provide expert-level interpretation of findings, risk evaluation, and remediation guidance. *Lead vulnerability ...
Guide web application vulnerability scanning and remediation for each release. *Provide expert-level interpretation of findings, risk evaluation, and remediation guidance. *Lead vulnerability ...
Guide web application vulnerability scanning and remediation for each release. *Provide expert-level interpretation of findings, risk evaluation, and remediation guidance. *Lead vulnerability ...
Cyber Security Administrator
Tampa, FL · On-site
This role ensures documentation of ATO, security compliance, continuous monitoring, vulnerability scanning, and incident response. This future opportunity is contingent upon award. * The ...
Quick apply
Cyber Security Administrator
Tampa, FL · On-site
This role ensures documentation of ATO, security compliance, continuous monitoring, vulnerability scanning, and incident response. This future opportunity is contingent upon award. * The ...
Cyber Security Administrator
Tampa, FL · On-site
This role ensures documentation of ATO, security compliance, continuous monitoring, vulnerability scanning, and incident response. This future opportunity is contingent upon award. * The ...
Quick apply
Cyber Security Administrator
Tampa, FL · On-site
This role ensures documentation of ATO, security compliance, continuous monitoring, vulnerability scanning, and incident response. This future opportunity is contingent upon award. * The ...
The role involves managing security compliance, Authority to Operate (ATO) processes, continuous monitoring, vulnerability scanning, and incident response within cloud and hybrid environments.
The role involves managing security compliance, Authority to Operate (ATO) processes, continuous monitoring, vulnerability scanning, and incident response within cloud and hybrid environments.
Ensure vulnerability scans are functioning and accurate, troubleshoot and remediate where necessary * Create Tenable Security Center dashboards and reports as necessary to communicate remediation ...
Ensure vulnerability scans are functioning and accurate, troubleshoot and remediate where necessary * Create Tenable Security Center dashboards and reports as necessary to communicate remediation ...
Cyber Security Administrator
Doral, FL · On-site
The role involves managing security compliance, Authority to Operate (ATO) processes, continuous monitoring, vulnerability scanning, and incident response within cloud and hybrid environments.
Cyber Security Administrator
Doral, FL · On-site
The role involves managing security compliance, Authority to Operate (ATO) processes, continuous monitoring, vulnerability scanning, and incident response within cloud and hybrid environments.
Physical Security System Administrator
Doral, FL · On-site
$100K - $115K/yr
This individual provides Tier 2 IT services in support of collateral and SCI physical security programs, performs daily monitoring and vulnerability scanning of the ESS network, and maintains ...
Physical Security System Administrator
Doral, FL · On-site
$100K - $115K/yr
This individual provides Tier 2 IT services in support of collateral and SCI physical security programs, performs daily monitoring and vulnerability scanning of the ESS network, and maintains ...
Conduct vulnerability scans using ACAS and assess findings to ensure compliance with DoD and organizational requirements * Manage and update POA&Ms, tracking remediation progress and ensuring ...
Conduct vulnerability scans using ACAS and assess findings to ensure compliance with DoD and organizational requirements * Manage and update POA&Ms, tracking remediation progress and ensuring ...
Will be responsible for performing scans of assigned information systems, including vulnerability, network detection and mapping, and controlled interfaces. The candidate must be knowledgeable on a ...
Will be responsible for performing scans of assigned information systems, including vulnerability, network detection and mapping, and controlled interfaces. The candidate must be knowledgeable on a ...
Vulnerability Scanning information
What is the job description of vulnerability scanning?
Can you make $500,000 a year in cyber security?
Can I make $200 a year in cyber security?
Is 40 too old for cyber security?
What does a Vulnerability Scanning job entail?
A Vulnerability Scanning job involves using automated tools to identify security weaknesses in computer systems, networks, and applications. Professionals in this role assess potential vulnerabilities, generate reports, and provide recommendations to improve security. They work closely with IT and security teams to ensure threats are mitigated before they can be exploited. Strong analytical skills and knowledge of cybersecurity best practices are essential for success in this role.
What are the key skills and qualifications needed to thrive in the Vulnerability Scanning position, and why are they important?
To thrive in Vulnerability Scanning, you need a strong understanding of cybersecurity principles, networking, and operating systems, often supported by a relevant degree or certifications such as CompTIA Security+ or Certified Ethical Hacker (CEH). Familiarity with vulnerability scanning tools like Nessus, Qualys, OpenVAS, as well as SIEM platforms, is essential. Excellent analytical thinking, attention to detail, and clear communication skills set top candidates apart in this specialized field. These skills and qualities are crucial for accurately identifying security weaknesses, producing actionable reports, and collaborating effectively with IT teams to enhance organizational security.
What does a typical day look like for someone working in Vulnerability Scanning?
A typical day in Vulnerability Scanning involves running scheduled and ad-hoc scans across various systems to identify potential security threats and weaknesses. You will analyze scan results, document findings, and collaborate closely with IT and security teams to prioritize and address vulnerabilities. Regular communication with stakeholders is common, as you'll often need to translate technical risks into understandable recommendations. The work environment is usually dynamic, requiring continuous learning to stay updated on emerging threats and new scanning technologies. This role offers strong opportunities for growth into broader cybersecurity or leadership positions.

Other
Medical, Life, Retirement
Posted 4 days ago
JetBlue rating
7.7
Based on 80 frontline employees who took The Breakroom Quiz
10th of 26 rated airlines
Job description
Position Summary
At JetBlue, cybersecurity is driven by risk management, threat-informed defense, and operational resilience. The Analyst, Vulnerability Management - Cloud supports JetBlue's vulnerability management program across cloud-hosted infrastructure, cloud control planes, containers, infrastructure as code, and application-adjacent cloud services. This Crewmember identifies, analyzes, validates, reports, and coordinates remediation of cloud vulnerabilities and misconfigurations across JetBlue's multi-cloud environment, including AWS, Azure, GCP, OCI, and future cloud platforms as adopted.
The Analyst works closely with Cybersecurity, Cloud Engineering, DevOps, Infrastructure, Application, Product, GRC, Threat Intelligence, and Managed Service Provider teams to improve vulnerability visibility, remediation accountability, and risk-based prioritization.
Essential Responsibilities
- Conduct and support vulnerability assessments across cloud-hosted infrastructure, cloud configurations, containers, Kubernetes, infrastructure as code, application components, and related cloud services.
- Use approved vulnerability management, cloud security, CSPM/CNAPP, container, code-scanning, and external attack-surface tools to identify vulnerabilities, misconfigurations, exposed services, outdated software, and insecure deployment patterns.
- Analyze findings using severity, exploitability, CISA KEV status, exposure, asset criticality, data sensitivity, compensating controls, and business impact.
- Coordinate with cloud engineering, DevOps, application, infrastructure, and product owners to prioritize and track remediation through patching, configuration changes, code changes, image updates, infrastructure-as-code changes, or compensating controls.
- Validate remediation through rescans, evidence review, configuration review, ticket closure checks, or other approved verification methods.
- Assist with authenticated scan coverage, agent deployment coordination, cloud account onboarding, asset tagging, ownership validation, and CMDB/application mapping.
- Support remediation governance by tracking findings against JetBlue policy timelines and escalating overdue, disputed, or blocked remediation items.
- Collaborate with engineering and QA teams to ensure proper Software Development Life Cycle (SDLC) practices and minimize the release of vulnerable software through the deployment pipeline.
- Route non-remediated or delayed findings through the approved cyber risk exception / acceptance process when required.
- Configure and maintain vulnerability metrics and reporting for cloud findings, remediation progress, risk exposure, aging, coverage gaps, recurring issues, and exception trends.
- Partner with Threat Intelligence, Detection & Response, Penetration Testing, and Application Security teams to incorporate active exploitation, external exposure, attack path, and test-result context into prioritization.
- Support Cyber compliance requirements with evidence, reporting, and control validation for PCI, SOX, TSA-related obligations, and other applicable oversight frameworks.
- Participate in cross-functional working sessions to improve cloud vulnerability remediation processes, reduce direct exposure, strengthen compensating controls, and improve cloud security visibility.
- Other duties as assigned.
Minimum Experience and Qualifications
- Bachelor's Degree in Computer Science, Information Security, Information Technology, Cybersecurity, Cloud Computing, or a related field; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience
- One (1) year of experience in vulnerability management, cloud security, security operations, infrastructure security, DevOps, application security, or a related cybersecurity role.
- Working knowledge of at least one major cloud provider; AWS/Azure preferred.
- Experience with vulnerability scanning tools such as Tenable, Qualys, Rapid7, Prisma Cloud, Wiz, Defender for Cloud, AWS Inspector, or similar.
- Understanding of cloud shared responsibility models, cloud networking, identity, compute, storage, containers, Kubernetes, and infrastructure-as-code concepts.
- Ability to analyze scan results, identify false positives, validate risk, and communicate remediation needs clearly.
- Knowledge of vulnerability risk factors such as CVSS, exploitability, internet exposure, asset criticality, data sensitivity, compensating controls, and remediation timelines.
- Familiarity with patch management, configuration remediation, change management, and remediation validation.
- Strong written and verbal communication skills with the ability to interact effectively with stakeholders across all levels of the organization.
- Ability to work collaboratively with Cybersecurity, IT, DevOps, infrastructure, product, application, compliance, and managed service provider teams.Available for occasional overnight travel (10%).
- Must pass a pre-employment drug test.
- Must be legally eligible to work in the country in which the position is located.
- Authorization to work in the United States is required; this position is not eligible for visa sponsorship.
Preferred Experience and Qualifications
- Two (2) years of experience in vulnerability management, cloud security, DevSecOps, infrastructure security, or application security.
- Experience with CSPM, CNAPP, CWPP, container scanning, code scanning, IaC scanning, or external attack surface management.
- Working knowledge with AWS Systems Manager, Azure Update Manager, cloud-native patching tools, or enterprise patch platforms.
- Understanding with Kubernetes, container registries, golden images, base-image maintenance, and CI/CD security gates.
- Experience using Terraform, CloudFormation, ARM/Bicep, Kubernetes manifests, or other infrastructure-as-code technologies.
- Knowledge of NIST CSF, CIS Controls, CIS Benchmarks, PCI DSS, TSA cybersecurity requirements, ISO 27001, or similar standards.
- Certifications such as Security+, CySA+, AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer, CCSK, CCSP, or equivalent.
Crewmember Expectations
- Regular attendance and punctuality.
- Potential need to work flexible hours and be available to respond on short notice.
- Able to maintain a professional appearance.
- When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of aircraft.
- Must be an appropriate organizational fit for the JetBlue culture, that is, exhibit the JetBlue values of Safety, Caring, Integrity, Passion and Fun.
- Promote JetBlue's #1 value of safety as a Safety Ambassador, supporting JetBlue's Safety Management System components, Safety Policy, and behavioral standards.
- Identify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue's confidential reporting systems (Aviation Safety Action Program (ASAP) or Safety Action Report (SAR))
- The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.
Equipment
- Computer and other office equipment.
Work Environment
- Traditional office environment.
Physical Effort
- Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary)
Compensation
- The base pay range for this position is between $70,000.00 and $120,000.00 per year. Base pay is one component of JetBlue's total compensation package, which may also include access to healthcare benefits, a 401(k) plan and company match, crewmember stock purchase plan, short-term and long-term disability coverage, basic life insurance, free space available travel on JetBlue, and more.
#LI-AC1
#LI-Hybrid
About JetBlue
Sourced by ZipRecruiter
Industry
Aviation
Company size
10,000+ Employees
Headquarters location
New York, NY, US
Year founded
1998