Vulnerability Management Security Analyst
Indexed description
Job Description
At the University of Notre Dame, protecting our digital environment and safeguarding our community's data is vital to ensuring the University remains a force for good in the world. To that end, the Office of Information Technology (OIT) is seeking a collaborative and analytical Vulnerability Management Security Analyst to join our information security team.
This position plays a key role in helping OIT and campus technology teams identify, understand, prioritize, and remediate vulnerabilities across endpoint, server, network, identity, cloud, SaaS, application, and third-party environments. The Vulnerability Management Security Analyst supports recurring vulnerability scanning, validates findings, manages security exceptions, and provides actionable remediation guidance to system owners. In addition to day-to-day operations, this role will directly contribute to maturing Notre Dame’s security capabilities by improving automation, dashboards, metrics, and workflows.
What You'll Do
- Support the vulnerability management lifecycle through routine scanning, analysis, and validation of security findings.
- Prioritize vulnerabilities based on exploitability, exposure, asset criticality, and data sensitivity.
- Partner with system owners and distributed IT units to coordinate and track remediation progress.
- Monitor, triage, and escalate security events across SIEM, EDR, email, and cloud platforms.
- Assist with incident response by gathering evidence, documenting timelines, and recommending containment.
- Maintain and tune security tools, dashboards, and automated ticketing workflows.
- Contribute to broader security initiatives such as cloud security, identity protection, and risk reviews.
- Bachelor’s degree in Computer Science, Information Technology, Information Security, or a related field, OR an equivalent combination of education and professional experience.
- Working knowledge of cybersecurity operations, vulnerability management, incident response, security monitoring, enterprise technology, and IT risk management principles.
- Knowledge of vulnerability management practices, including scanning, validation, risk-based prioritization, remediation tracking, exceptions, compensating controls, and remediation verification.
- Ability to evaluate vulnerability findings, alerts, logs, endpoint telemetry, network activity, cloud events, and authentication patterns to identify risk and recommend action.
- Strong analytical, problem-solving, documentation, communication, security administration, and stakeholder coordination skills.
- Ability to work in the United States, now or in the future, without visa sponsorship.
- Experience in higher education or another complex, decentralized organization.
- Familiarity with cybersecurity frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, EDUCAUSE guidance, or MITRE ATT&CK.
- Experience with security operations, vulnerability management, ticketing, or endpoint platforms such as CrowdStrike, ServiceNow, Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or similar tools.
- Experience supporting vulnerability remediation, phishing investigations, account compromise response, endpoint investigations, cloud security reviews, or security tool administration.
- Experience with scripting, automation, APIs, dashboarding, or data analysis using Python, PowerShell, Bash, SQL, Excel, or similar technologies.
- Relevant certifications such as Security+, CySA+, GSEC, GCIH, GCIA, GMON, SSCP, CISSP, or similar credentials.
- Please include a cover letter for full consideration of your application.
- Salary: up to 95K, commensurate with experience
- Deadline to apply (subject to change): Thursday, August 13th, 2026
- This position maintains a Hybrid work arrangement (1-2 days remote based on operational needs and team expectations.)
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search