Vulnerability Management Analyst (Cloud & DevSecOps)
Vulnerability Management Analyst (Cloud & DevSecOps) - 100% remote (CST)Optomi, in partnership with a large, global organization ($28B+ in annual revenue!) is seeking an experienced Vulnerability Management Analyst to support enterprise vulnerability identification, risk prioritization, remediation, and reporting across traditional and cloud-based environments.The ideal candidate will bring a strong foundation in enterprise vulnerability management, along with practical experience supporting AWS environments, containers/Kubernetes, and DevSecOps workflows. The Vulnerability Management Analyst will work closely with infrastructure, cloud, application, and DevOps teams to analyze vulnerabilities, determine risk, provide remediation guidance, and drive findings through resolution.This role is best suited for a vulnerability management professional who understands modern cloud and application environments but does not necessarily need to be a dedicated cloud or DevSecOps engineer.The strongest candidate will be a Vulnerability Management professional first, with enough cloud and DevSecOps experience to effectively manage vulnerabilities in a modern AWS environment.Deep expertise in cloud architecture, Kubernetes engineering, or CI/CD pipeline development is not required. Instead, the successful candidate should understand these technologies well enough to identify and analyze vulnerabilities, communicate technical risk, and partner effectively with the engineering teams responsible for remediation.Key ResponsibilitiesPerform hands-on vulnerability management activities across enterprise infrastructure, applications, and cloud environments.Analyze vulnerability findings and determine appropriate risk and remediation priority based on severity, exploitability, asset criticality, exposure, and other relevant risk factors.Manage vulnerabilities through the full lifecycle, including identification, analysis, prioritization, remediation coordination, exception management, validation, and closure.Support vulnerability management activities across AWS infrastructure and cloud workloads.Partner with Cloud Engineering, Infrastructure, DevOps, Application Development, and Security teams to drive timely remediation.Analyze vulnerabilities affecting containers and Kubernetes environments and work with engineering teams to address identified risks.Support the integration of vulnerability scanning and security controls into CI/CD and DevSecOps workflows.Provide technical remediation guidance to infrastructure, cloud, and application teams.Analyze and coordinate response to critical vulnerabilities, zero-days, and emerging threats.Leverage vulnerability management and cloud security platforms to identify and prioritize security exposure.Track vulnerability remediation progress, exceptions, SLAs, and risk trends.Develop vulnerability metrics, dashboards, and reporting for technical teams and security leadership.Identify opportunities to automate vulnerability management processes, reporting, enrichment, and remediation workflows.Utilize APIs and scripting where appropriate to improve the scalability and efficiency of vulnerability management operations.Required Qualifications5+ years of hands-on experience in Vulnerability Management, Vulnerability Assessment, or Exposure Management.Strong understanding of the end-to-end vulnerability management lifecycle.Hands-on experience with enterprise vulnerability management platforms such as Tenable, Qualys, Rapid7, CrowdStrike, Wiz, or comparable technologies.Experience analyzing and prioritizing vulnerabilities beyond scanner severity alone, incorporating factors such as exploitability, exposure, business/asset criticality, and threat context.Demonstrated experience partnering with technical teams to drive vulnerabilities from identification through remediation and validated closure.Strong understanding of vulnerability remediation across operating systems, infrastructure, applications, and cloud workloads.Practical vulnerability management or security experience within AWS environments.Working knowledge of containers and Kubernetes and experience addressing vulnerabilities affecting containerized workloads.Understanding of CI/CD and DevSecOps processes, including how vulnerability and security scanning can be incorporated into development and deployment workflows.Experience responding to critical and zero-day vulnerabilities.Strong troubleshooting, analytical, and communication skills.Preferred QualificationsHands-on experience with CrowdStrike, particularly Falcon Cloud Security or vulnerability/exposure management capabilities.Experience with cloud-native vulnerability management, CNAPP, CSPM, or exposure management platforms.Experience with AWS services such as EC2, ECR, EKS, IAM, and other cloud-native technologies.Experience with container image scanning and Kubernetes vulnerability management.Familiarity with SAST, SCA, IaC scanning, or other DevSecOps security controls.Experience using Python, PowerShell, APIs, or other automation technologies to improve vulnerability management processes.Familiarity with risk-prioritization methodologies and technologies including CVSS, EPSS, CISA KEV, threat intelligence, and asset criticality.Experience working in large-scale or highly regulated enterprise environments.