Vulnerability Management Risk Advisor Delivery Excellence & Client Success NYC Hybrid $130,000 Apply Ideal candidate The ideal candidate is a highly motivated and proactive Vulnerability Management professional with 5+ years of hands-on experience in cybersecurity operations or related security analysis roles. They possess a strong understanding of vulnerability assessment methodologies, CISA KEV catalogs, risk scoring, and threat intelligence, coupled with practical experience using tools like Rapid7 InsightVM, CrowdStrike, Shodan, or Prisma. This individual is a quick problem-solver, adept at analyzing complex security data, developing practical solutions, and effectively communicating findings to both technical and non-technical audiences. A standout candidate will demonstrate a proven track record of working independently with minimal supervision, exhibiting excellent written and verbal communication skills, and thriving in a fast-paced, multi-agency environment. Job description The Vulnerability Management Risk Advisor plays a critical role in supporting NYC’s cybersecurity posture by analyzing vulnerability data and providing risk-focused guidance to assigned city agencies. This position is part of a team of VM analysts responsible for monitoring the threat landscape, prioritizing vulnerabilities, and advising agency stakeholders on remediation strategies. This role requires a highly motivated VM professional, who can quickly analyze complex vulnerability data, follow operational guidance, create documentation, and work effectively with multiple vulnerability management tools. The ideal candidate is a proactive problem-solver who can work autonomously while contributing to team objectives in a fast-paced, multi-agency environment. vulnerability management cybersecurity operations vulnerability assessment methodologies CISA KEV catalogs risk scoring threat intelligence Rapid7 InsightVM CrowdStrike Falcon Shodan Prisma Cloud written communication verbal communication
What you'll do
- Analyze vulnerability scan data from tools like Rapid7 InsightVM and CrowdStrike Falcon to identify and prioritize risks across multiple NYC city agencies
- Monitor CISA KEV catalogs and threat intelligence feeds to contextualize active exploitation risk and drive remediation prioritization
- Advise agency stakeholders on vulnerability remediation strategies, translating complex technical findings into actionable guidance for both technical and non-technical audiences
- Develop and maintain vulnerability management documentation including risk reports, remediation roadmaps, and operational runbooks
- Perform attack surface analysis using tools such as Shodan and Prisma Cloud to identify externally exposed or cloud-based risks
- Track remediation progress across assigned agencies and escalate high-severity findings in accordance with operational SLAs
- Contribute to team-wide VM operations including threat landscape monitoring, metric reporting, and process improvement initiatives
Mission
Municipal government vulnerability management and risk advisory across multi-agency environment
Required skills
- vulnerability management
- vulnerability assessment methodologies
- risk scoring
- threat intelligence
- Rapid7 InsightVM
- CISA KEV catalog
- CrowdStrike Falcon
- cybersecurity operations