We are seeking a Security Analyst with hands-on experience in vulnerability management, cloud security posture management (CSPM), and data security posture management (DSPM) to join our security team. This role is responsible for identifying, assessing, and helping remediate security risks across our infrastructure, cloud environments, and data assets.
Key Responsibilities
Manage and operate Rapid7 InsightVM (or equivalent) to scan, identify, prioritize, and track remediation of vulnerabilities across on-prem and cloud assets
Monitor and manage cloud security posture using CSPM tooling to identify misconfigurations, compliance gaps, and risky permissions across cloud environments (AWS, Azure, and/or GCP)
Utilize Varonis to monitor data security posture, including sensitive data discovery, access governance, permissions analysis, and anomalous data access/behavior
Perform regular vulnerability scans, analyze results, and produce prioritized remediation reports for IT and engineering stakeholders
Track remediation efforts to closure and report on risk trends, SLA compliance, and overall security posture metrics
Investigate and respond to alerts related to data exposure, excessive permissions, and abnormal access patterns
Collaborate with IT, DevOps, and application teams to remediate identified vulnerabilities and misconfigurations
Assist in maintaining and tuning policies, rules, and dashboards within Rapid7, CSPM, and Varonis platforms
Support audit and compliance efforts by providing evidence of vulnerability management and data security controls
Document findings, processes, and procedures related to vulnerability and posture management programs
Required Qualifications
2+ years of hands-on experience with Rapid7 (InsightVM or InsightCloudSec) for vulnerability management
2+ years of experience with Cloud Security Posture Management (CSPM) tools and concepts
2+ years of experience with Varonis for data security posture management (DSPM)
Solid understanding of vulnerability scanning, risk scoring (CVSS), and remediation prioritization
Familiarity with cloud environments (AWS, Azure, and/or GCP) and common misconfigurations
Understanding of data governance, access controls, and permissions models
Strong analytical and problem-solving skills with attention to detail
Ability to communicate findings clearly to both technical and non-technical stakeholders
Familiarity with security frameworks (NIST, CIS Benchmarks, ISO 27001) a plus