tier4 groupWashington, DC
Endpoint Security Analyst 5515
Endpoint Security Analyst 5515
Endpoint Security Analyst 5515
tier4 groupWashington, DC
yesterday
Information Security AnalystsNetwork and Computer Systems AdministratorsInformation Security Engineers
Computer Systems Design ServicesOther Computer Related ServicesComputer Facilities Management Services
Apply for this role →Position Summary:
The Endpoint Cybersecurity Vulnerability Remediation Analyst is responsible for identifying, analyzing, prioritizing, and remediating cybersecurity vulnerabilities across enterprise workstation and server environments. This position serves as a key operational link between Cybersecurity and IT Operations, with a strong focus on converting vulnerability findings into measurable remediation results. The analyst will regularly review vulnerability and exposure data from CrowdStrike Falcon, validate findings, determine appropriate remediation actions, and work directly with endpoint, server, application, and infrastructure teams to ensure vulnerabilities are resolved within established Operational Level Agreements (OLAs).This is a hands-on, mid-level technical position requiring strong troubleshooting, vulnerability management, Windows administration, patching, and automation skills.
Key Responsibilities
Vulnerability Analysis & Prioritization:
Review vulnerability reports, dashboards, and exposure data generated through CrowdStrike Falcon and related cybersecurity tools.
Analyze open vulnerabilities affecting enterprise Windows, Linux, and MacOS workstations and servers.
Validate vulnerability findings to determine affected systems, software versions, available patches, configuration changes, and other remediation options.
Prioritize remediation based on:o CVSS severityo Active or known exploitationo CrowdStrike risk/exposure informationo Internet-facing exposureo Asset criticalityo Business impacto Age of the vulnerabilityo Established organizational OLAsIdentify vulnerabilities that require immediate escalation due to active exploitation or significant organizational risk.
Distinguish between vulnerabilities requiring operating system patches, application updates, configuration changes, software removal, or compensating controls.
Vulnerability Remediation:
Take direct ownership of assigned vulnerabilities from identification through successful remediation.
Deploy and coordinate security patches for Windows workstations and servers, Linux servers, and MacOS devices.
Remediate vulnerabilities associated with operating systems, browsers, third-party applications, utilities, drivers, and common enterprise software.
Use Microsoft Intune, Azure Update Manager, SCCM, Patch My PC, PowerShell, and other enterprise management tools to deploy and automate remediation.
Work with server administrators and infrastructure teams when remediation requires server patching, configuration changes, application upgrades, or maintenance windows.
Troubleshoot failed patches and unsuccessful remediation attempts.
Develop remediation solutions for vulnerabilities where traditional patching is not available.
Remove or upgrade obsolete, unsupported, and vulnerable software when appropriate.
Validate that remediation actions have successfully eliminated or mitigated the identified vulnerability.
Ensure remediation activities minimize disruption to business operations.
OLA & Vulnerability Backlog Management:
Monitor vulnerability aging and ensure assigned vulnerabilities are remediated within established OLAs.
Maintain visibility into vulnerabilities approaching or exceeding OLA thresholds.
Proactively escalate vulnerabilities that are at risk of missing remediation targets.
Investigate vulnerabilities that remain open after remediation attempts and determine the root cause.
Assist with reducing the organization's existing vulnerability backlog.
Identify recurring vulnerabilities and recommend systemic solutions rather than repeatedly addressing individual systems.
Track remediation progress and provide accurate status information to Cybersecurity and IT leadership.
Support exception and risk-acceptance processes when vulnerabilities cannot be remediated within established timeframes.
Automation & Continuous Improvement:
- Develop PowerShell scripts and other automation to improve vulnerability remediation at scale.
- Automate repetitive activities such as software detection, version validation, application removal, patch deployment, configuration changes, and remediation verification.
- Develop Intune remediation scripts and deployment packages where appropriate.
- Identify opportunities to move from manual remediation to automated and policy-driven remediation.
- Analyze recurring vulnerability trends and recommend improvements to endpoint and server configuration standards.
- Create reusable remediation procedures for commonly identified vulnerabilities.
- Reporting & Metrics
- Assist with tracking and reporting key vulnerability-management metrics, including:
- Total open vulnerabilities
- Critical and High vulnerabilities
- Vulnerabilities by workstation/server
- Vulnerabilities by application or technology
- Vulnerabilities within OLAVulnerabilities exceeding OLAVulnerability backlog
- Average vulnerability age
- Mean Time to Remediate (MTTR)
- Remediation success rate
- Reopened or recurring vulnerabilities
- Vulnerability reduction trends
- Provide technical explanations for vulnerabilities that remain unresolved and recommend corrective actions.
Documentation:
- Maintain clear documentation of vulnerability remediation procedures.
- Document root causes and resolutions for complex or recurring vulnerabilities.
- Develop knowledge articles and technical procedures that can be reused by Service Desk, Infrastructure, and Cybersecurity teams.
- Maintain documentation for automated remediation scripts and deployment packages.
- Document exceptions, dependencies, remediation failures, and required follow-up activities.
- Required Qualifications3–5 years of experience in cybersecurity, vulnerability management, endpoint management, Windows administration, systems administration, or a related IT discipline.
- Hands-on experience remediating vulnerabilities in enterprise environments.
- Experience working with vulnerability management or endpoint security platforms such as CrowdStrike Falcon.
- Strong knowledge of Windows 10/11 and Windows Server environments.
- Experience with Microsoft Intune or comparable endpoint management platforms.
- Experience deploying operating system and third-party application patches.
- Working knowledge of Microsoft Entra ID and enterprise endpoint management.
- Intermediate PowerShell scripting skills.
- Understanding of:o CVE and CVSSo Vulnerability severity and risk prioritizationo Patch managemento Endpoint securityo Configuration vulnerabilitieso Zero-day and actively exploited vulnerabilitieso Compensating controlso Risk acceptance and vulnerability exceptions
- Strong troubleshooting and root-cause-analysis skills.
- Ability to manage multiple remediation efforts while meeting established OLAs.
Preferred Qualifications:
Experience with CrowdStrike Falcon Exposure Management / Spotlight.
Experience with Microsoft Intune Remediations.
Experience automating software deployment and vulnerability remediation.
Experience with enterprise server patching processes.
Familiarity with vulnerability and security frameworks such as NIST, CIS Controls, and CISA Known Exploited Vulnerabilities (KEV).Experience working within an ITIL-based IT Service Management environment.
Experience integrating vulnerability remediation with an ITSM platform.
Security certifications such as Security+, CySA+, SSCP, GSEC, or equivalent are preferred but not required.
Key Competencies: The successful candidate should demonstrate:
- Ownership – Takes responsibility for vulnerabilities through verified closure rather than simply identifying or assigning issues.
- Technical Problem Solving – Can determine why a vulnerability exists and identify the most effective remediation.
- Automation Mindset – Looks for opportunities to remediate hundreds of systems rather than addressing devices individually.
- Risk Awareness – Understands that vulnerability severity alone does not determine business risk.
- Urgency – Recognizes when active exploitation or critical exposure requires accelerated remediation.
- Collaboration – Works effectively across Cybersecurity, Service Desk, Infrastructure, Endpoint Engineering, and application teams.
- Continuous Improvement – Identifies systemic improvements that prevent vulnerabilities from repeatedly returning.
- Measures of Success
- Performance for this position will be measured primarily by risk reduction and remediation effectiveness, including:
- Percentage of Critical and High vulnerabilities remediated within OLAReduction in vulnerability backlog
- Reduction in vulnerabilities exceeding OLAMean Time to Remediate (MTTR)
- First-attempt remediation success rate
- Reduction in recurring vulnerabilities
- Percentage of remediation activities automated
- Accuracy and completeness of remediation documentation
- Primary Objective
- Drive measurable reduction of cybersecurity risk by ensuring workstation and server vulnerabilities are prioritized, remediated, validated, and closed within established OLAs.
Also on the board Same function, level within a rung
Level
Senior
Location
Washington, DC
Occupation
Information Security Analysts
Industry
Computer Systems Design Services
Posted
yesterday