Associate, Vulnerability Assessment
Job description
About the role
Coalfire is seeking an entry-level professional to join our security team to help clients identify and mitigate digital risks. You will perform hands-on assessments, analyze scan results, and guide organizations through the remediation process to improve their overall security posture. In this role, you will serve as the primary technical contact for clients during vulnerability assessment engagements, translating complex technical findings into actionable recommendations. You will own the end-to-end lifecycle of scanning and manual validation for assigned projects, ensuring accuracy and thoroughness in every engagement. This position provides a foundation for building a long-term career in cybersecurity risk and vulnerability management within a growing security practice. You will collaborate closely with senior consultants and subject matter experts to expand your knowledge and contribute to client success. This role is ideal for a motivated individual who is detail-oriented and eager to develop practical skills in a client-facing security environment.
Key facts
What you'll do
- Operate and refine vulnerability scanning tools including Tenable, Qualys, Nexpose, Prisma Cloud, and Burp to ensure comprehensive coverage.
- Translate technical findings into clear guidance that helps clients understand and fix web application and host-based security gaps.
- Conduct manual validation procedures to confirm that identified vulnerabilities have been successfully remediated.
- Analyze and interpret raw scan data to generate reports that highlight credential success results, complete asset inventories, and active threats.
- Assess client justifications for risk adjustments, identify false positives, and evaluate vendor dependencies to ensure accurate risk reporting.
- Coordinate with internal delivery teams to uphold project standards and meet client expectations within established timelines.
- Support the development and maintenance of system inventories, boundary diagrams, and Plans of Action and Milestones (POA&M) where required.
- Apply security frameworks and regulatory requirements such as NIST, ISO, COBIT, and HIPAA/HITECH to assessment activities and documentation.
- Assist in evaluating compliance with frameworks including FedRAMP, FISMA, SOC, HIPAA, and HITRUST based on client engagement needs.
- Document configurations, verify implementation against baselines such as CIS and STIG, and recommend improvements aligned with best practices.
Requirements
- Bring less than 2 years of professional experience in vulnerability assessment, creating an entry point for career development.
- Demonstrate practical experience with at least one major scanning platform such as Tenable, Qualys, Nexpose, Prisma Cloud, or Burp.
- Hold a Bachelor degree in Computer Science, Information Technology, Cybersecurity, or show an equivalent combination of education and relevant work history.
- Show a clear understanding of vulnerability management lifecycles, including identification, scanning, analysis, and structured reporting.
- Exhibit familiarity with established industry best practices for security management and control implementation.
- Show proficiency with security frameworks and regulations such as NIST, ISO, COBIT, and HIPAA/HITECH in prior academic or professional settings.
- Maintain at least one of the following certifications: Security+, CCSK, AWS Cloud Practitioner, SSCP, GSEC, CEH, Cloud+, SC-900, ISC2 CC, AZ-900, Cloud Essentials+, or GCP.
- Legally authorized to work in the United States for the duration of this full-time engagement without requiring company sponsorship.
Nice to have
- Accumulate experience working with at least 3 frameworks such as FedRAMP, FISMA, SOC, HIPAA, or HITRUST in previous roles or academic projects.
- Develop system inventories, boundary diagrams, and Plans of Action and Milestones (POA&M) as part of vulnerability assessment deliverables.
- Apply knowledge of cloud environments including AWS, GCP, and Azure during assessment and remediation activities.
- Leverage knowledge of configuration baselines such as CIS and STIG to evaluate system security settings.
- Demonstrate scripting proficiency in languages such as Python, Bash, or PowerShell to automate repetitive tasks and enhance efficiency.
Practical notes
This is a regular full-time position based in the United States. Coalfire provides a flexible work model that supports remote or office-based arrangements depending on role requirements and team structure. The company offers paid parental leave, flexible time off policies, reimbursement for certification and training, and mental health support resources to promote work-life balance. Candidates who require reasonable accommodations during the hiring process due to disability or other needs may contact HumanResourcesMB@coalfire.com for assistance. Coalfire is committed to equal opportunity employment and welcomes diverse candidates to join its security practice.