North Logo

North

Vulnerability Management Analyst

Posted Yesterday
Remote
Hiring Remotely in US
70K-110K Annually
Mid level
Remote
Hiring Remotely in US
70K-110K Annually
Mid level
Identify, analyze, prioritize, and track vulnerabilities across cloud, container, data center, network, and endpoint environments using Wiz and Tenable. Partner with engineering, IT, cloud infrastructure, and operations teams to advocate remediation, monitor SLAs, report risk metrics, support PCI-DSS audits, and improve vulnerability management processes and automation.
The summary above was generated by AI

Vulnerability Management Analyst

North - Remote

North is seeking a detail-oriented Vulnerability Management Analyst to join our Cybersecurity team. In this role, you will help protect our payment processing platform, cloud environments, and internal infrastructure by identifying, analyzing, and prioritizing technical vulnerabilities.

Working closely with engineering, cloud infrastructure, and IT teams, you will leverage enterprise security tools (such as Wiz and Tenable) to track risk and diplomatically advocate for timely remediation. This role is ideal for an early-to-mid career cybersecurity professional with strong analytical and interpersonal skills who enjoys turning security data into actionable fixes.

What you'll do:

  • Vulnerability Identification & Scanning: Operate, maintain, and assist in configuring scanning platforms (Wiz, Tenable) across cloud assets, containers, data centers, network infrastructure, and endpoints.

  • Analysis & Prioritization: Review vulnerability data, reduce false positives, and prioritize risks based on business context, CVSS scores, threat intelligence, and payment industry risk factors.

  • Remediation Advocacy: Act as a liaison to engineering, IT, and operations teams to champion patching initiatives, explain technical risks, and follow up on overdue SLAs.

  • Tracking & Metrics: Track remediation progress, communicate risk posture to leadership, and maintain dashboards, reports, and key performance indicators (KPIs).

  • Compliance Support: Support security audit and compliance efforts (such as PCI-DSS) by providing evidence of regular vulnerability scanning and remediation.

  • Continuous Improvement: Refine vulnerability management processes, playbooks, and automated workflows to reduce exposure windows.

What we need from you: 

Education and Experience

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related technical field (or equivalent practical experience).

  • 3 years of hands-on experience in cybersecurity, IT, system administration, or risk management.

  • Hands-on experience operating enterprise scanning platforms, specifically Wiz and Tenable.

Knowledge, Skills & Abilities

  • Core Vulnerability Concepts: Solid understanding of the vulnerability management lifecycle, Common Vulnerabilities and Exposures (CVEs), CVSS scoring, and common attack vectors and vulnerability exploitation.

  • Tooling Familiarity: Exposure to enterprise scanner technologies (Tenable) and cloud security/exposure management tools (Wiz).

  • Analytical Mindset: Ability to analyze large datasets of vulnerability scans, identify trends, and translate raw data into clear, actionable reporting.

  • Interpersonal & Communication Skills: Excellent verbal and written communication skills while building relationships across teams and encouraging patch completion.

  • Technical Foundations: Understanding of core OS concepts (Windows, Linux), cloud security fundamentals (AWS, Azure, or GCP), and enterprise networking.

How to stand out (Preferred):

  • 5 years of relevant or hands-on experience in cybersecurity, IT, system administration, or risk management

  • Experience within fintech, payment processing, or another highly regulated, fast-paced environment.

  • Familiarity with payment industry standards and security frameworks (PCI-DSS, NIST Cybersecurity Framework, CIS Benchmarks).

  • Experience using ticketing and project tracking tools such as Jira to track vulnerability work items.

  • Basic scripting knowledge (Python, PowerShell, Bash, or API queries) to automate reporting or routine tasks. 

  • Certifications such as CompTIA Security+, Network+, or eJPT are a plus, but not required.

Salary range: $70,000-$110,000

Pay within this range varies by work location and on job-related knowledge, skills, and experience. We look forward to discussing your salary expectations and our full total rewards offerings throughout the interview process.

Please note: North is a US based company and no sponsorship is available for this position at this time.

Who we are: 

North, and our family of companies, are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company, we provide everything business owners need to get paid, whether they serve customers in a physical storefront, online, or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning, hands-on approach to personal service that our merchants won’t find anywhere else.

Let’s go North, together! Our most important resource is our people. Join our diverse team of innovators and do-ers and make your mark on the future of payments technology. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling. 

At North, we celebrate diversity and create an inclusive environment for everyone. We are an equal opportunity employer.

To learn more about North, and our family of companies, visit our website: north.com

North Westlake Village, California, USA Office

Westlake Village, CA, United States

Similar Jobs

Yesterday
In-Office or Remote
6 Locations
110K-120K Annually
Mid level
110K-120K Annually
Mid level
Hardware • Security • Software • Cybersecurity
Manage vulnerability management and continuous monitoring for a multi-cloud government-certified environment. Process vulnerabilities into POAMs, coordinate remediation with engineering teams, develop compliance metrics, prepare assessment artifacts, support FedRAMP changes, onboard product teams, improve processes using automation and AI agents, and maintain documentation. The role requires cybersecurity experience, vulnerability management expertise, government security framework knowledge, strong communication, and U.S. citizenship with clearance eligibility.
Top Skills: AzrampFedrampGoogle GeminiGoogle WorkspaceGovrampInformation Security ManualItsg-33Nist 800-53Tx-RampWiz
4 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
280K-280K Annually
Entry level
280K-280K Annually
Entry level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Develop and close enterprise public-sector business across state, local, and education accounts. Build executive relationships, lead account strategies, manage complex proofs of concept and trials, support RFP wins, exceed revenue quotas, and collaborate with sales engineering, product, software engineering, and partners to address customer needs and demonstrate integrated solutions.
Top Skills: AICustomer AnalyticsHardware And Software Integrations
6 Minutes Ago
Remote or Hybrid
United States
25-45 Hourly
Internship
25-45 Hourly
Internship
Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Systems Engineering Interns assist with designing and developing system solutions, gathering requirements, defining specifications, integrating and testing components, troubleshooting technical issues, and documenting engineering activities. The role provides hands-on aerospace experience, cross-functional collaboration, mentorship, and exposure to system design, integration, testing, modeling, and simulation.

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account