Vulnerability Management Analyst I
Omaha, NE Temporary $45.00 - $48.00/hr Onsite

Job Description

We are seeking an experienced Vulnerability Management Analyst to support the continued development and execution of our Vulnerability Management program. This contractor will initially focus on reducing the current backlog of overdue vulnerability remediation items while also helping improve the overall process for assigning, tracking, validating, and reporting vulnerabilities across the organization.

This role is W2 hourly with Roth Staffing, with all work taking place for our client in Omaha, NE. No 3rd party candidates will be considered. The role is slated to run for 6 months, but could be extended.

The W2 hourly rate range is: $45.00 - $47.91.

The successful candidate will work closely with Vulnerability Management, infrastructure, application, security, service management, and technology ownership teams. This role requires someone who can quickly understand a complex technology environment, work independently, coordinate across multiple teams, and bring structure and accountability to a high-volume backlog.

This is a hands-on operational and process-focused role. The contractor will not necessarily perform all technical remediation directly but will be responsible for helping ensure vulnerabilities are assigned to the correct owners, remediation plans are established, progress is accurately documented, and overdue items are appropriately escalated.

Key Responsibilities

  • Review and triage the existing backlog of overdue vulnerability remediation tickets.
  • Validate vulnerability findings, affected assets, application ownership, support-team ownership, remediation status, and target completion dates.
  • Work with infrastructure, application, cloud, database, middleware, endpoint, and other technology teams to coordinate remediation activities.
  • Identify tickets that have been incorrectly assigned or that require involvement from multiple support teams.
  • Help break down complex or multi-team remediation efforts into clearly defined, trackable actions.
  • Ensure vulnerability tickets contain complete and accurate information, including affected hosts, vulnerability details, ownership, remediation requirements, due dates, exceptions, and status updates.
  • Follow up with assigned teams to obtain remediation plans, target dates, implementation evidence, and validation of completion.
  • Coordinate with vulnerability scanning and security teams to confirm whether vulnerabilities have been successfully remediated or require additional action.
  • Identify recurring ownership, CMDB, assignment-group, asset-management, and process gaps that contribute to overdue vulnerabilities.
  • Support improvements to ServiceNow workflows, reporting, ticket structures, dashboards, and operating procedures.
  • Assist with defining and documenting Vulnerability Management roles, responsibilities, escalation paths, service-level expectations, and governance processes.
  • Develop regular backlog reporting for technology leaders, including aging, ownership, risk severity, remediation progress, blockers, and overdue trends.
  • Escalate high-risk, significantly overdue, or stalled remediation items through the appropriate management channels.
  • Support vulnerability exception and risk-acceptance processes where remediation cannot be completed within the required timeframe.
  • Help establish repeatable processes that can be transitioned to internal team members at the conclusion of the engagement.
  • Maintain clear documentation of decisions, actions, dependencies, and process improvements.

Required Qualifications

  • Three or more years of experience in Vulnerability Management, cybersecurity operations, IT risk, infrastructure security, IT service management, or a related technology operations role.
  • Experience managing or coordinating the remediation of vulnerabilities across multiple technical teams.
  • Strong working knowledge of vulnerability-management concepts, including severity ratings, risk prioritization, remediation timelines, exceptions, compensating controls, and validation.
  • Experience working with enterprise vulnerability-scanning platforms such as Tenable, Qualys, Rapid7, CrowdStrike or a comparable tool.
  • Experience using ServiceNow or another enterprise IT service-management platform to manage tickets, assignments, workflows, and reporting.
  • Ability to interpret vulnerability findings and communicate remediation requirements to technical and nontechnical stakeholders.
  • Strong organizational skills and the ability to manage a large volume of open actions, owners, dependencies, and deadlines.
  • Demonstrated ability to follow up with stakeholders, remove blockers, and escalate issues appropriately.
  • Strong written and verbal communication skills.
  • Experience creating operational reports, dashboards, metrics, and executive-level summaries.
  • Ability to work independently, establish priorities, and deliver results with limited oversight.
  • Strong proficiency with Microsoft Excel and other Microsoft 365 tools.

Preferred Qualifications

  • Experience working within a large, regulated enterprise, preferably in financial services, insurance, healthcare, or another highly regulated industry.
  • Familiarity with ServiceNow Vulnerability Response, Configuration Management Database, asset-management, or related ServiceNow modules.
  • Experience improving vulnerability-management workflows or operating models.
  • Understanding of infrastructure and application technologies, including Windows, Linux, databases, middleware, cloud services, network devices, and end-user computing.
  • Experience working with audit, compliance, risk, or governance teams.
  • Experience supporting process documentation, procedure development, or responsibility-assignment models.

Initial Priorities

  • During the initial phase of the engagement, the contractor will be expected to:
  • Review and categorize the existing overdue Vulnerability Management backlog.
  • Confirm technical and business ownership of affected assets and applications.
  • Correct inaccurate ticket assignments and identify remediation dependencies.
  • Establish remediation plans and target dates with the responsible teams.
  • Create a consistent process for tracking progress and escalating stalled items.
  • Identify systemic issues contributing to the backlog, including CMDB, ownership, workflow, reporting, and accountability gaps.
  • Recommend practical improvements to the ongoing Vulnerability Management operating process.
  • Develop documentation and reporting that can be maintained by the internal team.

Measures of Success

Success in this role will be measured through:

    • Reduction in the number and age of overdue vulnerability tickets.
    • Improved accuracy of ticket ownership and assignment.
    • Increased percentage of vulnerabilities with documented remediation plans and target dates.
    • Timely escalation of high-risk or stalled remediation items.
    • Improved visibility into remediation status, risk, blockers, and dependencies.
    • Documented improvements to Vulnerability Management workflows and procedures.
    • Creation of a sustainable process that can be transitioned to the internal team.

Must Have

  • Experience managing or coordinating the remediation of vulnerabilities across multiple technical teams.
  • Experience using ServiceNow or another enterprise IT service-management platform to manage tickets, assignments, workflows, and reporting.
  • Experience working with enterprise vulnerability-scanning platforms such as Tenable, Qualys, Rapid7, CrowdStrike or a comparable tool.
  • Strong working knowledge of vulnerability-management concepts, including severity ratings, risk prioritization, remediation timelines, exceptions, compensating controls, and validation.
  • Three or more years of experience in Vulnerability Management, cybersecurity operations, IT risk, infrastructure security, IT service management, or a related technology operations role.

All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.

Job Reference: JN -082026-428718