SailPoint Logo

SailPoint

Vulnerability Management Analyst

Posted 2 Hours Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in United States
Mid level
Remote or Hybrid
Hiring Remotely in United States
Mid level
The Vulnerability Management Analyst will assess and prioritize vulnerabilities in IT assets, collaborate with cross-functional teams, and enhance security processes, ensuring regulatory compliance and risk management.
The summary above was generated by AI

Cybersecurity Vulnerability Management Analyst

 

SailPoint’s Cybersecurity organization is seeking a Cybersecurity Vulnerability Management Analyst with a passion for cybersecurity. This role ensures the continuous discovery, accurate assessment, risk-based prioritization, and successful remediation of vulnerabilities and misconfigurations across all IT assets, directly reducing the organization's exposure and maintaining regulatory compliance.
 
We are seeking a colleague with demonstrable technical expertise, strong business acumen, and a proven track record of working in security programs in complex environments. The ideal candidate will be part of the team securing SailPoint’s production environments from misconfigurations and software vulnerabilities, cross-functional collaboration, and ensuring that products meet the highest standards of security, availability, and trust.
 
Our new Vulnerability Management Analyst will join a growing and capable threat and vulnerability management team of both emerging and established talent. This potential team member will be comfortable with the 4 I’s at SailPoint (individual, Impact, Innovation, and
Integrity) even if they’re new to the concept. They will embrace new challenges, and by being their authentic self they will be a positive contributor to an already positive work culture and environment.
 
This is a challenging and impactful role where you will have the opportunity to work with a variety of stakeholders, including our fantastic colleagues in IT, DevOps, Product engineering, Security engineering, and Compliance.
 
This role reports directly to the Head of Vulnerability Management and will be remote.
 
Key Requirements:
  • 3-5 years experience, preferably in vulnerability management.
  • Strong engineering experience with cloud, containers, open-source code, deployment and misconfigurations.
  • Intermediate experience with scripting languages (e.g., Python, PowerShell) for automating data ingestion, reporting, or integrating VM data into other security tools (SIEM/SOAR).
  • Experience with regulatory frameworks (e.g., NIST, ISO 27001, SOC, GDPR) and providing evidence for compliance and audit needs.
  • Experience tracking trends and configure systems as required to reduce false positives from true events.
  • Process Improvement: Drive continuous improvement in the efficiency of vulnerability remediation through automation, ticketing system integration (e.g., Jira), and process streamlining.
  • Influence & Collaboration – Demonstrable experience building strong partnerships in a matrixed organization.
  • Technical – Intermediate understanding of product security issues (like XXE, SSRF, Injections, etc.), modern software development (fully automated CI/CD, REST, OAuth2) including multi-cloud (AWS, Azure, GCP, Containers, Kubernetes) architectures, particularly Amazon Web Services, Kubernetes, and Docker.
  • Risk-Based Decision Making – Experience making informed decisions through balancing business priorities, technical constraints, and risk exposure.
  • Certifications like CISSP, CISA, CySA+, AWS Certs, or CCNSE, or other relevant certifications are preferred.
  • If the candidate does not have the AWS Certified Cloud Practitioner or AWS Certified Cloud Security – Specialty, they must take these certifications within first year of employment.
Core Responsibilities:
  • Collaborating in the enterprise-wide product security and resilience strategy, aligning with business goals and regulatory requirements.
  • Partnering with Dev/Ops, engineering, product management, and infrastructure teams to integrate vulnerability management practices into production environments.
  • Identifying risk in a production environment comprised of a sophisticated SaaS architecture consisting of dozens of microservices
  • Maintain knowledge of the threat landscape for prioritization of vulnerabilities, attack techniques, tool/exploit development, cyber threat intelligence analysis and adversarial tactics.
  • Explaining risks, identifing dependencies, and facilitating the remediation process by providing necessary details and context.
  • Enforce a prioritization framework that utilizes risk context beyond standard CVSS scores, factoring in asset criticality, exposure to the public internet, and internal threat intelligence (e.g., active exploitation in the wild).
  • Drive the adoption of security automation, vulnerability management with product teams.
  • Providing program performance reporting and metrics per business unit and product.

Benefits and Compensation listed vary based on the location of your employment and the nature of your employment with SailPoint.

As a part of the total compensation package, this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission, along with potential eligibility for equity participation. SailPoint maintains broad salary ranges for its roles to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect SailPoint’s differing products, industries, and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. We estimate the base salary, for US-based employees, will be in this range from (min-mid-max, USD):

$76,400 - $109,200 - $142,000

Base salaries for employees based in other locations are competitive for the employee’s home location.

Benefits Overview

1. Health and wellness coverage: Medical, dental, and vision insurance

2. Disability coverage: Short-term and long-term disability

3. Life protection: Life insurance and Accidental Death & Dismemberment (AD&D)

4. Additional life coverage options: Supplemental life insurance for employees, spouses, and children

5. Flexible spending accounts for health care, and dependent care; limited purpose flexible spending account

6. Financial security: 401(k) Savings and Investment Plan with company matching

7. Time off benefits: Flexible vacation policy

8. Holidays: 8 paid holidays annually

9. Sick leave

10. Parental support: Paid parental leave

11. Employee Assistance Program (EAP) and Care Counselors

12. Voluntary benefits: Legal Assistance, Critical Illness, Accident, Hospital Indemnity and Pet Insurance options

13. Health Savings Account (HSA) with employer contribution

SailPoint is an equal opportunity employer and we welcome all qualified candidates to apply to join our team.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other category protected by applicable law.  

Alternative methods of applying for employment are available to individuals unable to submit an application through this site because of a disability. Contact [email protected] or mail to 11120 Four Points Dr, Suite 100, Austin, TX 78726, to discuss reasonable accommodations.  NOTE: Any unsolicited resumes sent by candidates or agencies to this email will not be considered for current openings at SailPoint.

Top Skills

AWS
Azure
Docker
GCP
JIRA
Kubernetes
Powershell
Python
SIEM
Soar

Similar Jobs at SailPoint

Yesterday
Remote or Hybrid
2 Locations
Senior level
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The Sr. HR Business Partner will collaborate with leadership to develop HR strategies, enhance organizational effectiveness, analyze data for workforce improvement, and manage change initiatives in a dynamic environment.
Top Skills: HrisMS Office
Yesterday
Remote or Hybrid
United States
Senior level
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The Senior Machine Learning Engineer will design and optimize ML models, manage end-to-end ML projects, and enhance SailPoint's AI capabilities while collaborating with various teams to integrate AI features into products.
Top Skills: AirflowAws SagemakerCloudbeesDbtGoJenkinsKafkaPythonPyTorchQlikScikit-LearnShell/BashSnowflakeSparkSQLTableauTensorFlow
Yesterday
Remote or Hybrid
United States
Senior level
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The Engagement Manager oversees multiple projects, manages client relationships, and ensures delivery of SailPoint solutions, focusing on project management and sales efforts.
Top Skills: Project ManagementSaaSSoftware

What you need to know about the Sydney Tech Scene

From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account