Über diese Sr Cyber Security Analyst- Vulnerability Management Stelle bei SRS Distribution
Position Purpose:
The Senior Cyber Security Analyst at the company will serve as a senior hands-on technical resource within Cyber Security Operations, with primary responsibility for enterprise Vulnerability Management and secondary responsibility for supporting Cyber Operations activities associated with mergers and acquisitions. This role is responsible for identifying, validating, prioritizing, tracking, and helping drive remediation of vulnerabilities across
the enterprise.
The Senior Cyber Security Analyst will work extensively with vulnerability and exposure management technologies such as Wiz, CrowdStrike, Rapid7, and Nagomi to improve visibility, prioritize risk, validate findings, and measure reduction of security exposure. The position will also provide hands-on technical support during mergers and acquisitions by assessing acquired environments, identifying vulnerabilities and cybersecurity gaps, onboarding assets into established security processes, validating remediation activities, and helping transition acquired environments into standard Cyber Operations practices.
The Senior Cyber Security Analyst will report directly to the Cyber Security Operations Manager and will receive technical direction and engineering guidance from the Cybersecurity Staff Engineer.
Key Responsibilities:
- Serve as a senior hands-on technical resource for the enterprise Vulnerability Management program, supporting vulnerability identification, validation, prioritization, remediation, and closure.
- Administer, maintain, optimize, and support Vulnerability Management and exposure management technologies, including Wiz, CrowdStrike, Rapid7, Nagomi, and related platforms.
- Perform vulnerability assessments across enterprise technology environments, including servers, workstations, network devices, cloud-hosted assets, applications, and other technology assets.
- Analyze and validate vulnerability findings to reduce false positives and ensure remediation efforts are focused on legitimate cybersecurity risk.
- Prioritize vulnerabilities using risk-based factors such as vulnerability severity, known exploitation, internet accessibility, asset criticality, business impact, threat intelligence, exploitability, compensating controls, and exposure paths.
- Identify and prioritize vulnerabilities associated with active exploitation, zero-day vulnerabilities, CISA Known Exploited Vulnerabilities, emerging threats, and other high-risk security conditions.
- Coordinate with Infrastructure, Network, Cloud, Application, and other technology teams to drive vulnerability remediation activities through completion.
- Track vulnerabilities throughout the full lifecycle, including identification, validation, remediation, mitigation, exception, risk acceptance, and closure.
- Perform technical validation following remediation to confirm vulnerabilities and exposures have been successfully addressed.
- Identify recurring vulnerabilities, systemic weaknesses, and remediation challenges and recommend technical or process improvements.
- Develop and maintain Vulnerability Management procedures, standards, runbooks, dashboards, operational documentation, and reporting.
- Support vulnerability exception and risk acceptance processes by providing technical analysis, exposure information, and compensating-control considerations.
- Perform vulnerability trend analysis and identify areas of increasing enterprise risk or recurring exposure.
- Serve as a primary hands-on technical resource for Nagomi, supporting integrations, exposure analysis, security control validation, and risk-based prioritization.
- Correlate vulnerability data, asset context, threat intelligence, and control information within Nagomi to improve remediation prioritization and identify areas of security exposure.
- Analyze Nagomi findings to identify control gaps, vulnerabilities, security configuration issues, and opportunities to reduce enterprise exposure.
- Develop vulnerability and exposure metrics that demonstrate remediation progress, vulnerability aging, recurring risk, coverage, and measurable reduction of security exposure.
- Serve as a hands-on Cyber Operations resource supporting mergers, acquisitions, and business integrations.
- Execute assigned Cyber Operations activities during M&A discovery, assessment, onboarding, and integration efforts.
- Perform technical security discovery and vulnerability assessments within acquired environments to identify cybersecurity risks, vulnerabilities, unmanaged assets, unsupported technologies, security configuration weaknesses, and technical debt.
- Establish an initial vulnerability and exposure baseline for acquired environments.
- Assist with onboarding acquired assets into enterprise Vulnerability Management and exposure management technologies and processes.
- Perform vulnerability scans, technical assessments, validation activities, and follow-up testing required during acquisition integration.
- Analyze M&A security findings and provide actionable remediation recommendations to the appropriate technology teams.
- Validate patches, configuration changes, mitigations, and other corrective actions implemented during M&A remediation efforts.
- Track assigned M&A cybersecurity findings and Cyber Operations activities through completion.
- Work closely with Infrastructure, Network, Cloud, Application, Identity, GRC, and other technology teams to complete assigned cybersecurity integration activities.
- Assist with transitioning acquired environments into established Vulnerability Management processes, remediation workflows, reporting standards, and Cyber Operations practices.
- Support automation, API integrations, reporting, and workflow improvements that increase the efficiency and scalability of Vulnerability Management activities.
Direct Manager Direct Reports:
- The Senior Cyber Security Engineer will report directly to the Cyber Security Operations Manager.
- This role does not have any direct reports.
- The Senior Cyber security Engineer will receive technical direction, eguidance, standards, and technical prioritization from the Cybersecurity Staff Analyst.
- The position will work closely with Cyber Security Operations, Cyber Engineering, Infrastructure, Network, Cloud, Application, Identity, GRC, and other technology teams to drive vulnerability remediation and support M&A Cyber Operations activities.
Travel Requirements:
- The Senior Cyber Security Engineer may be required to travel occasionally to support mergers and acquisitions, cybersecurity assessments, acquired-company integration activities, technical meetings, or other business requirements.
- Travel may include visits to acquired organizations, branch locations, data centers, offices, or other company facilities as needed to support hands-on Cyber Operations activities.
Physical Requirements:
- The Senior Cyber Security Engineer position involves working in a standard office environment, with duties requiring extended periods of sitting, standing, and computer use.
- The role requires the ability to communicate effectively with technical teams, business partners, leadership, and other stakeholders both verbally and in written form.
- Occasional travel may be necessary to attend meetings, assessments, site visits, or M&A integration activities.
- The company is committed to the principles of the Americans with Disabilities Act (ADA) and will provide reasonable accommodations to enable individuals with disabilities to perform the essential functions of this role effectively. Candidates seeking accommodations are encouraged to reach out to our HR department to discuss how we can support your application and work environment needs.
Working Conditions:
- The Senior Cyber Security Engineer role is designed to operate within a hybrid work environment, blending both in-office and remote work arrangements to support flexibility, collaboration, and productivity.
- The position operates in a fast-paced Cyber Security Operations environment where priorities may shift based on vulnerability severity, emerging threats, active exploitation, business risk, mergers and acquisitions, and remediation requirements.
- The role requires the ability to independently manage multiple technical priorities while maintaining strong communication and coordination with Cyber Security, IT, and business stakeholders.
- The Senior Cyber Security Engineer is expected to work collaboratively with technical teams to drive measurable reduction in enterprise vulnerability exposure and support the secure integration of acquired environments.
Minimum Qualifications:
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related technical field from an accredited institution, or equivalent combination of education and professional experience.
- At least 5 years of progressive experience in Cybersecurity, Vulnerability Management, Security Engineering, Cyber Security Operations, or a related technical discipline.
- Strong hands-on experience with enterprise Vulnerability Management technologies and processes.
- Demonstrated experience using vulnerability or exposure management technologies such as Wiz, CrowdStrike, Rapid7, Nagomi, or comparable platforms.
- Strong understanding of vulnerability identification, validation, prioritization, remediation, mitigation, exception handling, and closure.
- Strong knowledge of CVE, CVSS, CISA Known Exploited Vulnerabilities, EPSS, threat intelligence, exploitability, and risk-based vulnerability prioritization.
- Experience assessing vulnerabilities across Windows, Linux, network, cloud-hosted, application, and enterprise infrastructure environments.
- Demonstrated ability to analyze vulnerability findings across multiple data sources and determine appropriate remediation or mitigation actions.
- Experience working with Infrastructure, Network, Cloud, Application, and other technology teams to drive vulnerability remediation through completion.
- Strong analytical and problem-solving skills with the ability to distinguish technical severity from actual organizational risk.
- Experience developing vulnerability reporting, dashboards, remediation metrics, technical documentation, procedures, and operational standards.
- Strong written and verbal communication skills with the ability to communicate technical risks and remediation requirements to both technical and non-technical stakeholders.
- Demonstrated ability to independently manage multiple priorities and technical workstreams within a fast-paced Cyber Security Operations environment.
Preferred Qualifications:
- Hands-on experience supporting cybersecurity activities associated with mergers, acquisitions, divestitures, or large-scale technology integrations.
- Experience performing technical vulnerability assessments of newly acquired environments.
- Experience establishing vulnerability and exposure baselines for acquired or newly integrated organizations.
- Experience onboarding acquired assets into enterprise Vulnerability Management technologies and processes.
- Advanced experience with Wiz, CrowdStrike vulnerability capabilities, Rapid7, Nagomi, or similar vulnerability and exposure management technologies.
- Experience with attack surface analysis, exposure management, security control validation, and risk-based vulnerability prioritization.
- Experience using APIs, scripting, or automation to integrate security technologies, automate vulnerability workflows, or improve reporting capabilities.
- Experience developing and maintaining vulnerability dashboards, executive reporting, remediation metrics, and operational performance indicators.
- Experience working within a large, distributed enterprise containing multiple business units, locations, technology platforms, and acquired organizations.
- Strong understanding of enterprise vulnerability remediation processes, including patching, configuration management, mitigation, exceptions, and risk acceptance.
- Experience identifying systemic vulnerability patterns and recommending long-term engineering or process improvements.
- Relevant cybersecurity certifications are preferred.
Minimum Education:
- A Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related technical field is preferred. Equivalent professional experience may be considered in lieu of a degree.
Preferred Education:
- A Bachelor’s or Master’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related technical discipline is preferred.
Minimum Years Of Work Experience:
- 5 years of progressive experience in Cybersecurity, Vulnerability Management, Security Engineering, Cyber Security Operations, or a related technical discipline.
Certifications:
- Preferred: Certified Information Systems Security Professional (CISSP).
- Preferred: GIAC Security Essentials (GSEC), GIAC Certified Incident Handler (GCIH), or other relevant GIAC certification.
- Preferred: CompTIA Security+ or CySA+.
- Preferred: Vendor-specific certifications related to vulnerability management, exposure management, cloud security, or security operations technologies.
Competencies:
1. Vulnerability Management Expertise:
Demonstrated ability to identify, validate, prioritize, track, and drive
remediation of enterprise vulnerabilities using risk-based methodologies and
multiple security data sources.
2. Technical Analysis:
Strong analytical capability to investigate complex vulnerability findings,
validate technical risk, distinguish severity from actual exposure, and
determine appropriate remediation or mitigation actions.
3. Risk-Based Prioritization:
Ability to evaluate vulnerabilities using business context, asset criticality,
exploitation activity, threat intelligence, exposure, and compensating controls
rather than relying solely on vulnerability severity scores.
4. Security Technology Expertise:
Strong hands-on knowledge of Vulnerability Management and exposure management
platforms such as Wiz, CrowdStrike, Rapid7, Nagomi, and similar technologies.
5. M&A Technical Execution:
Ability to perform hands-on cybersecurity assessments, vulnerability discovery,
integration activities, validation, remediation support, and operational
transition activities within acquired environments.
6. Cross-Functional Collaboration:
Demonstrated ability to work effectively with Cyber Security, Infrastructure,
Network, Cloud, Application, Identity, GRC, and other technology teams to drive
remediation and achieve cybersecurity objectives.
7. Problem-Solving Acumen:
Advanced ability to identify complex technical issues, analyze root causes,
develop practical solutions, and drive cybersecurity findings through
resolution.
8. Operational Excellence:
Strong focus on repeatable processes, documentation, automation, reporting,
measurable risk reduction, and continuous improvement within Vulnerability
Management and Cyber Security Operations.
Not the right job for you? Register your details at the 'Introduce Yourself' link (top right) and we'll be in touch!
Job Location: SRS Distribution - McKinney
7440 State Highway 121 McKinney, TX 75070-3104
As an Equal Employment Opportunity (EEO) employer SRS Distribution Inc., including all its subsidiaries, provides job opportunities to qualified individuals without regard to actual or perceived race, color, creed, religion, national origin, sex, gender, age, disability, gender identity, sexual orientation, citizenship status, uniform service, veteran status, marital status, genetic information, physical or mental disability, or any other characteristic in accordance with applicable federal, state, and local EEO laws. If you are an individual with a disability or a disabled veteran and require a reasonable accommodation in applying for any posted position, please contact Human Resources at US: 855.556.3221, or by email to: [email protected] with the nature of your accommodation request and include the Business name, location and title of the job opening. Please allow one (1) business day for a reply. All employment offers are contingent upon successful completion of a background check and drug screen, as permitted by law.
Medical, Dental, Vision, Disability & Life Insurance, Wellness Benefits, 401(k) Retirement Plan, Employee Stock Purchase Program, Paid Holidays & Vacation Days, Professional Growth Opportunities, Development & Training Programs. All benefits subject to eligibility.
Should a Candidate be submitted to fill a position by a recruiting or staffing services agency (“Agency”), the Company has no obligation to pay the Agency any fee for submission, offer, placement or any service without a fully executed contract of service covering the engagement.