Connexus Credit Union Logo

Connexus Credit Union

Vulnerability Management Analyst

Posted 9 Days Ago
Remote
Hiring Remotely in USA
Mid level
Remote
Hiring Remotely in USA
Mid level
The Vulnerability Management Analyst will conduct regular vulnerability scans, analyze results, prioritize vulnerabilities, track remediation, and ensure compliance with regulations while partnering with various teams to mitigate risks.
The summary above was generated by AI

Connexus Credit Union - Who We Are:

Serving members across all 50 states, Connexus Credit Union is a member-focused cooperative that is proud to return profits to member-owners through high yields for checking accounts and deposit products, as well as competitive rates on our loans. We are a remote first employer with the majority of our employees residing in the upper Midwest.

As an employer we foster collaboration and high performance to achieve excellence. We holistically care for and develop our employees to thrive personally and professionally. We are proud to share our success with our employees and those we serve.

Connexus offers an Amazing Benefits package:

  • 25 days of paid time off and 10 paid holidays

  • 16 hours of paid Volunteer Time Off

  • 401K Retirement with up to 6% employer match

  • Excellent Health, Dental, Vision insurance, including multiple plan options

  • Health Savings Account with generous employer contributions

  • Employer paid Life insurance, Short-Term and Long-Term Disability

  • Tuition Reimbursement from $4,000 - $7,000 per calendar year

  • Robust Learning and Development program that includes an annual professional development stipend

Responsibilities:

  • Conduct regular vulnerability scanning of networks, servers, endpoints, cloud environments, and applications using approved tools.      

  • Analyze scan results to identify false positives, determine exploitability, and assess business and regulatory risk.

  • Prioritize vulnerabilities based on CVSS scores, threat intelligence, asset criticality, and financial institution risk impact.           

  • Track vulnerabilities through remediation, validation, and closure using ticketing or governance platforms.       

  • Perform re-scans to validate remediation effectiveness. 

  • Ensure vulnerability management practices align with:

    • FFIEC Cybersecurity Assessment Tool (CAT)

    • NCUA or banking regulatory guidance

    • GLBA Safeguards Rule

    • Internal Information Security and Risk Management policies      

  • Prepare documentation, metrics, and evidence for internal audits, regulatory exams, and third-party assessments.  

  • Support risk acceptance decisions by documenting compensating controls and residual risk.               

  • Partner with IT infrastructure, application development, cloud, and network teams to remediate identified risks.            

  • Translate technical vulnerabilities into clear business risk language for leadership and non-technical stakeholders.         

  • Provide guidance on secure configuration, patching, and vulnerability mitigation strategies.

  • Participate in security incident response activities when vulnerabilities are exploited or pose imminent risk.              

  • Monitor emerging threats, zero-day vulnerabilities, and industry advisories relevant to financial services.          

  • Contribute to vulnerability management policies, standards, and procedures.               

  • Assist with penetration testing coordination and result analysis.              

  • Collect, organize, and maintain security control evidence and artifacts for monthly continuous monitoring deliverables and assessment/authorization activities, ensuring alignment with required frameworks.              

  • Maintain accurate system inventory and authorization boundary documentation to ensure scanning scope aligns with approved system boundaries.            

  • Analyze scan results for false positives, document justifications, and prepare deviation requests with supporting risk assessments.

  • Participate in change management processes to ensure continuous monitoring activities align with system changes and maintain compliance posture.

  • Support and maintain enterprise vulnerability management tools (such as Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring timely updates and patches.               

  • Run regular and on-demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation. 

  • Track and document vendor dependencies, operational requirements, and open vulnerabilities, producing clear monthly reports and updates.      

  • Contribute to improving internal standards and processes, including maintaining documentation, training materials, and standard operating procedures.             

  • Run the daily vulnerability management program operations, work closely with the patch management analyst in identifying and patching vulnerabilities, and actively participate in weekly vulnerability management team meetings.              

  • Comply with all Federal Regulations as they pertain to your job duties, including BSA.             

Position Requirements:

  • This position is Remote.

  • Bachelor's degree or commensurate experience is Required.

  • 3+ years professional work experience in vulnerability management, security operations, or IT risk within a regulated environment is Required.

  • Hands-on experience with vulnerability scanning tools, such as: Tenable (Nessus, Tenable.io), Qualys, Rapid7 or similar platforms is Required.  

  • Prior financial industry regulations and frameworks (FFIEC, NCUA, GLBA, NIST) is Required.

  • Strong knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS) and risk prioritization frameworks is Required.

  • Global Information Assurance Certification (GIAC), GIAC Security Essentials Certification (GSEC) or Enterprise Vulnerability Assessor Certification (GEVA) is Required.

Connexus Credit Union's Employer Recognitions:

  • 2026 Best Place to Work in IT, Computer World

Equal Opportunity Employer/Disabled/Veterans/41 CFR 60–1.4, 41 CFR 60-1.35

Top Skills

Burp
Microsoft Defender
Nessus
Prisma
Qualys
Rapid7
Tenable

Similar Jobs

19 Minutes Ago
In-Office or Remote
Austin, TX, USA
120K-140K Annually
Mid level
120K-140K Annually
Mid level
Big Data • Information Technology • Software • Analytics • Energy
The Cloud Security Integration Engineer manages security integrations of third-party platforms and internal systems, overseeing cloud security posture and incident response across AWS, Azure, and GCP environments, while collaborating on secure architecture with DevOps.
Top Skills: AWSAzureCspmEdrFido2GCPIdentity ManagementPasskeysSIEMVulnerability Management
An Hour Ago
Easy Apply
Remote or Hybrid
Austin, TX, USA
Easy Apply
135K-205K Annually
Senior level
135K-205K Annually
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
The Senior Security Engineer I will build and maintain core security infrastructure, collaborate with global teams, mentor junior engineers, and drive security initiatives.
Top Skills: Aws LambdaCrowdstrikePythonTerraformTinesZscaler
An Hour Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
As a Staff Data Platform Engineer, you will oversee the strategy, architecture, and operation of data and AI platforms, mentor teams, and resolve complex challenges using advanced data solutions.
Top Skills: AirflowBigQueryDatabricksDataflowDataprocGCPGoogle Cloud StorageKafkaKubernetesMcpRagSpark

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account