The Cyber Security Specialist is responsible for supporting and operating the organization's Vulnerability Management Program. This role focuses on identifying, assessing, prioritizing, tracking, and validating remediation of vulnerabilities across endpoints, servers, cloud environments, network devices, applications, and other enterprise technology assets. The Cyber Security Specialist works closely with Security, Infrastructure, Network, Cloud, Application, IT Operations, and Compliance teams to reduce risk, improve remediation performance, maintain audit-ready evidence, and strengthen the organization's overall security posture.
Vulnerability Management - Primary Focus
-
Administer and support enterprise vulnerability management tools.
-
Perform scheduled and ad hoc vulnerability scans across endpoints, servers, cloud resources, databases,
-
network devices, and externally exposed assets.
-
Review scan results, validate findings, identify duplicates or false positives, and ensure vulnerabilities are
-
accurately categorized.
-
Prioritize vulnerabilities using CVSS, CISA Known Exploited Vulnerabilities (KEV), exploitability, asset criticality, internet exposure, business impact, and threat intelligence.
-
Create and track remediation tickets with appropriate technology owners and support teams.
-
Monitor remediation service-level targets for Critical, High, Medium, and Low vulnerabilities.
-
Validate remediation through re-scans, patch verification, configuration checks, and closure evidence.
-
Maintain vulnerability exception records, risk acceptance documentation, false positive decisions, and compensating control evidence.
-
Identify recurring vulnerabilities and assist with root cause analysis to reduce repeat findings.
Reporting, Metrics, and Documentation
-
Prepare vulnerability reports, dashboards, scorecards, and remediation status updates for security leadership
-
and technical teams.
-
Track vulnerability aging, backlog, SLA compliance, overdue remediation, recurrence trends, and risk reduction
-
progress.
-
Maintain vulnerability management procedures, runbooks, standards, remediation guidance, and evidence
-
repositories.
-
Support audit and compliance requests by providing scan records, remediation evidence, exception approvals,
-
and control performance documentation.
Security Administration and Operational Support
-
Support security tool administration activities related to asset coverage, scan configuration, tagging, grouping, and reporting accuracy.
-
Assist with security investigations were vulnerabilities, missing patches, weak configurations, or exposed services may contribute to risk.
-
Review hardening standards, configuration baselines, and patch compliance information to help reduce exposure.
-
Monitor emerging vulnerabilities, vendor advisories, zero-day activity, and threat intelligence to help determine organizational impact.
Collaboration and Remediation Coordination
-
Partner with Infrastructure, Network, Cloud, Application, Endpoint, and third-party support teams to drive timely remediation.
-
Communicate vulnerability risk and remediation expectations clearly to technical and non-technical stakeholders.
-
Participate in change management, patch planning, and remediation meetings as needed.
-
Escalate overdue, high-risk, or repeatedly recurring vulnerabilities to management for visibility and action.