The posting
WE are looking for a Vulnerability Management Analyst supports the AWPT program by triaging vulnerabilities, validating remediation, coordinating stakeholders, and managing the vulnerability lifecycle to ensure timely closure of security findings from AI-powered penetration testing tools.
Responsibilities
- Review and triage findings from AI-based penetration testing tools to assess exploitability, severity, technical impact, and business risk
- Identify false positives and duplicate vulnerabilities to improve accuracy of vulnerability data
- Recommend severity adjustments and risk acceptance decisions based on thorough risk assessment
- Coordinate with application teams to develop and validate remediation plans
- Review code changes, logs, and supporting evidence to confirm remediation effectiveness
- Retest vulnerabilities and validate fixes to ensure successful remediation before closure
- Enhance Jira-based triage workflows and automation to streamline vulnerability management processes
- Develop dashboards and lifecycle tracking reports to monitor vulnerability status and trends
- Improve vulnerability correlation and tracking capabilities for comprehensive risk visibility
- Support integration efforts with AI-powered testing platforms to optimize security assessments
- Manage vulnerability lifecycle tracking through Jira to ensure timely issue resolution
- Coordinate stakeholders and facilitate resolution of vulnerability-related issues across teams
- Escalate critical or overdue vulnerabilities to appropriate leadership for prompt action
- Produce governance metrics and executive reports to inform decision-making and compliance
Required competencies and certifications
- Vulnerability Management and Risk Assessment
- Penetration Testing concepts and OWASP Top 10 knowledge
- Jira workflow management and reporting skills
- Application Security and Secure Coding principles
- Security analytics and dashboard development
- Strong communication and stakeholder management skills
Preferred competencies and qualifications
- CEH, GWAPT, OSCP, CISSP, or equivalent certifications
- Experience in vulnerability governance for large enterprises
- Knowledge of AI-assisted security testing platforms



