North Logo

North

Vulnerability Management Analyst

Posted 14 Days Ago
Remote
Hiring Remotely in US
70K-110K Annually
Mid level
Remote
Hiring Remotely in US
70K-110K Annually
Mid level
Identify, analyze, prioritize, and track vulnerabilities across cloud, container, data center, network, and endpoint environments using Wiz and Tenable. Partner with engineering, IT, cloud infrastructure, and operations teams to advocate remediation, monitor SLAs, report risk metrics, support PCI-DSS audits, and improve vulnerability management processes and automation.
The summary above was generated by AI

Vulnerability Management Analyst

North - Remote

North is seeking a detail-oriented Vulnerability Management Analyst to join our Cybersecurity team. In this role, you will help protect our payment processing platform, cloud environments, and internal infrastructure by identifying, analyzing, and prioritizing technical vulnerabilities.

Working closely with engineering, cloud infrastructure, and IT teams, you will leverage enterprise security tools (such as Wiz and Tenable) to track risk and diplomatically advocate for timely remediation. This role is ideal for an early-to-mid career cybersecurity professional with strong analytical and interpersonal skills who enjoys turning security data into actionable fixes.

What you'll do:

  • Vulnerability Identification & Scanning: Operate, maintain, and assist in configuring scanning platforms (Wiz, Tenable) across cloud assets, containers, data centers, network infrastructure, and endpoints.

  • Analysis & Prioritization: Review vulnerability data, reduce false positives, and prioritize risks based on business context, CVSS scores, threat intelligence, and payment industry risk factors.

  • Remediation Advocacy: Act as a liaison to engineering, IT, and operations teams to champion patching initiatives, explain technical risks, and follow up on overdue SLAs.

  • Tracking & Metrics: Track remediation progress, communicate risk posture to leadership, and maintain dashboards, reports, and key performance indicators (KPIs).

  • Compliance Support: Support security audit and compliance efforts (such as PCI-DSS) by providing evidence of regular vulnerability scanning and remediation.

  • Continuous Improvement: Refine vulnerability management processes, playbooks, and automated workflows to reduce exposure windows.

What we need from you: 

Education and Experience

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related technical field (or equivalent practical experience).

  • 3 years of hands-on experience in cybersecurity, IT, system administration, or risk management.

  • Hands-on experience operating enterprise scanning platforms, specifically Wiz and Tenable.

Knowledge, Skills & Abilities

  • Core Vulnerability Concepts: Solid understanding of the vulnerability management lifecycle, Common Vulnerabilities and Exposures (CVEs), CVSS scoring, and common attack vectors and vulnerability exploitation.

  • Tooling Familiarity: Exposure to enterprise scanner technologies (Tenable) and cloud security/exposure management tools (Wiz).

  • Analytical Mindset: Ability to analyze large datasets of vulnerability scans, identify trends, and translate raw data into clear, actionable reporting.

  • Interpersonal & Communication Skills: Excellent verbal and written communication skills while building relationships across teams and encouraging patch completion.

  • Technical Foundations: Understanding of core OS concepts (Windows, Linux), cloud security fundamentals (AWS, Azure, or GCP), and enterprise networking.

How to stand out (Preferred):

  • 5 years of relevant or hands-on experience in cybersecurity, IT, system administration, or risk management

  • Experience within fintech, payment processing, or another highly regulated, fast-paced environment.

  • Familiarity with payment industry standards and security frameworks (PCI-DSS, NIST Cybersecurity Framework, CIS Benchmarks).

  • Experience using ticketing and project tracking tools such as Jira to track vulnerability work items.

  • Basic scripting knowledge (Python, PowerShell, Bash, or API queries) to automate reporting or routine tasks. 

  • Certifications such as CompTIA Security+, Network+, or eJPT are a plus, but not required.

Salary range: $70,000-$110,000

Pay within this range varies by work location and on job-related knowledge, skills, and experience. We look forward to discussing your salary expectations and our full total rewards offerings throughout the interview process.

Please note: North is a US based company and no sponsorship is available for this position at this time.

Who we are: 

North, and our family of companies, are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company, we provide everything business owners need to get paid, whether they serve customers in a physical storefront, online, or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning, hands-on approach to personal service that our merchants won’t find anywhere else.

Let’s go North, together! Our most important resource is our people. Join our diverse team of innovators and do-ers and make your mark on the future of payments technology. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling. 

At North, we celebrate diversity and create an inclusive environment for everyone. We are an equal opportunity employer.

To learn more about North, and our family of companies, visit our website: north.com

Similar Jobs

Yesterday
Remote
United States
Senior level
Senior level
Artificial Intelligence • Cloud • Information Technology • Cybersecurity
Conduct vulnerability scans across enterprise, cloud, and on-premises environments; validate findings and patch levels; assess exploitability and risk; prioritize remediation; maintain POA&Ms; coordinate with technical teams; support RMF continuous monitoring, STIG compliance, reporting, and incident response. The role requires active Top Secret clearance, cybersecurity experience, ACAS/Nessus expertise, and Security+, ACAS, and CEH certifications.
Top Skills: AcasAWSCmdbCvssDod RmfNessusPoa&MPowershellPythonSIEMStigs
Yesterday
In-Office or Remote
6 Locations
110K-120K Annually
Mid level
110K-120K Annually
Mid level
Hardware • Security • Software • Cybersecurity
Manage vulnerability management and continuous monitoring for a multi-cloud government-certified environment. Process vulnerabilities into POAMs, coordinate remediation with engineering teams, develop compliance metrics, prepare assessment artifacts, support FedRAMP changes, onboard product teams, improve processes using automation and AI agents, and maintain documentation. The role requires cybersecurity experience, vulnerability management expertise, government security framework knowledge, strong communication, and U.S. citizenship with clearance eligibility.
Top Skills: AzrampFedrampGoogle GeminiGoogle WorkspaceGovrampInformation Security ManualItsg-33Nist 800-53Tx-RampWiz
7 Minutes Ago
Remote or Hybrid
US
135K-210K Annually
Senior level
135K-210K Annually
Senior level
Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
Lead product vision, strategy, adoption, roadmap prioritization, user research, metrics, and cross-functional execution for an AI-powered B2B insurance submissions platform. Partner across design, engineering, marketing, customer experience, and operations; manage integrations with adjacent products; resolve dependencies; communicate strategy and outcomes to senior leadership; and mentor other product managers.
Top Skills: AgileAIApplied EpicConfluenceJIRA

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account