Endpoint Security Analyst

Job description

Endpoint Cybersecurity Vulnerability Remediation Analyst

Position Summary

The Endpoint Cybersecurity Vulnerability Remediation Analyst is responsible for identifying, analyzing, prioritizing, and remediating cybersecurity vulnerabilities across enterprise workstation and server environments.

This position serves as a key operational link between Cybersecurity and IT Operations, with a strong focus on converting vulnerability findings into measurable remediation results. The analyst will regularly review vulnerability and exposure data from CrowdStrike Falcon, validate findings, determine appropriate remediation actions, and work directly with endpoint, server, application, and infrastructure teams to ensure vulnerabilities are resolved within established Operational Level Agreements (OLAs).

This is a hands-on, mid-level technical position requiring strong troubleshooting, vulnerability management, Windows administration, patching, and automation skills.

Key Responsibilities

Vulnerability Analysis & Prioritization

  • Review vulnerability reports, dashboards, and exposure data generated through CrowdStrike Falcon and related cybersecurity tools.
  • Analyze open vulnerabilities affecting enterprise Windows, Linux, and MacOS workstations and servers.
  • Validate vulnerability findings to determine affected systems, software versions, available patches, configuration changes, and other remediation options.
  • Prioritize remediation based on:

o CVSS severity

o Active or known exploitation

o CrowdStrike risk/exposure information

o Internet-facing exposure

o Asset criticality

o Business impact

o Age of the vulnerability

o Established organizational OLAs

  • Identify vulnerabilities that require immediate escalation due to active exploitation or significant organizational risk.
  • Distinguish between vulnerabilities requiring operating system patches, application updates, configuration changes, software removal, or compensating controls.

Vulnerability Remediation

  • Take direct ownership of assigned vulnerabilities from identification through successful remediation.
  • Deploy and coordinate security patches for Windows workstations and servers, Linux servers, and MacOS devices.
  • Remediate vulnerabilities associated with operating systems, browsers, third-party applications, utilities, drivers, and common enterprise software.
  • Use Microsoft Intune, Azure Update Manager, SCCM, Patch My PC, PowerShell, and other enterprise management tools to deploy and automate remediation.
  • Work with server administrators and infrastructure teams when remediation requires server patching, configuration changes, application upgrades, or maintenance windows.
  • Troubleshoot failed patches and unsuccessful remediation attempts.
  • Develop remediation solutions for vulnerabilities where traditional patching is not available.
  • Remove or upgrade obsolete, unsupported, and vulnerable software when appropriate.
  • Validate that remediation actions have successfully eliminated or mitigated the identified vulnerability.
  • Ensure remediation activities minimize disruption to business operations.

OLA & Vulnerability Backlog Management

  • Monitor vulnerability aging and ensure assigned vulnerabilities are remediated within established OLAs.
  • Maintain visibility into vulnerabilities approaching or exceeding OLA thresholds.
  • Proactively escalate vulnerabilities that are at risk of missing remediation targets.
  • Investigate vulnerabilities that remain open after remediation attempts and determine the root cause.
  • Assist with reducing the organization’s existing vulnerability backlog.
  • Identify recurring vulnerabilities and recommend systemic solutions rather than repeatedly addressing individual systems.
  • Track remediation progress and provide accurate status information to Cybersecurity and IT leadership.
  • Support exception and risk-acceptance processes when vulnerabilities cannot be remediated within established timeframes.

Automation & Continuous Improvement

  • Develop PowerShell scripts and other automation to improve vulnerability remediation at scale.
  • Automate repetitive activities such as software detection, version validation, application removal, patch deployment, configuration changes, and remediation verification.
  • Develop Intune remediation scripts and deployment packages where appropriate.
  • Identify opportunities to move from manual remediation to automated and policy-driven remediation.
  • Analyze recurring vulnerability trends and recommend improvements to endpoint and server configuration standards.
  • Create reusable remediation procedures for commonly identified vulnerabilities.

Reporting & Metrics

Assist with tracking and reporting key vulnerability-management metrics, including:

  • Total open vulnerabilities
  • Critical and High vulnerabilities
  • Vulnerabilities by workstation/server
  • Vulnerabilities by application or technology
  • Vulnerabilities within OLA
  • Vulnerabilities exceeding OLA
  • Vulnerability backlog
  • Average vulnerability age
  • Mean Time to Remediate (MTTR)
  • Remediation success rate
  • Reopened or recurring vulnerabilities
  • Vulnerability reduction trends

Provide technical explanations for vulnerabilities that remain unresolved and recommend corrective actions.

Documentation

  • Maintain clear documentation of vulnerability remediation procedures.
  • Document root causes and resolutions for complex or recurring vulnerabilities.
  • Develop knowledge articles and technical procedures that can be reused by Service Desk, Infrastructure, and Cybersecurity teams.
  • Maintain documentation for automated remediation scripts and deployment packages.
  • Document exceptions, dependencies, remediation failures, and required follow-up activities.

Required Qualifications

  • 3–5 years of experience in cybersecurity, vulnerability management, endpoint management, Windows administration, systems administration, or a related IT discipline.
  • Hands-on experience remediating vulnerabilities in enterprise environments.
  • Experience working with vulnerability management or endpoint security platforms such as CrowdStrike Falcon.
  • Strong knowledge of Windows 10/11 and Windows Server environments.
  • Experience with Microsoft Intune or comparable endpoint management platforms.
  • Experience deploying operating system and third-party application patches.
  • Working knowledge of Microsoft Entra ID and enterprise endpoint management.
  • Intermediate PowerShell scripting skills.
  • Understanding of:

o CVE and CVSS

o Vulnerability severity and risk prioritization

o Patch management

o Endpoint security

o Configuration vulnerabilities

o Zero-day and actively exploited vulnerabilities

o Compensating controls

o Risk acceptance and vulnerability exceptions

  • Strong troubleshooting and root-cause-analysis skills.
  • Ability to manage multiple remediation efforts while meeting established OLAs.

Preferred Qualifications

  • Experience with CrowdStrike Falcon Exposure Management / Spotlight.
  • Experience with Microsoft Intune Remediations.
  • Experience automating software deployment and vulnerability remediation.
  • Experience with enterprise server patching processes.
  • Familiarity with vulnerability and security frameworks such as NIST, CIS Controls, and CISA Known Exploited Vulnerabilities (KEV).
  • Experience working within an ITIL-based IT Service Management environment.
  • Experience integrating vulnerability remediation with an ITSM platform.
  • Security certifications such as Security+, CySA+, SSCP, GSEC, or equivalent are preferred but not required.

Key Competencies

The successful candidate should demonstrate:

  • Ownership – Takes responsibility for vulnerabilities through verified closure rather than simply identifying or assigning issues.
  • Technical Problem Solving – Can determine why a vulnerability exists and identify the most effective remediation.
  • Automation Mindset – Looks for opportunities to remediate hundreds of systems rather than addressing devices individually.
  • Risk Awareness – Understands that vulnerability severity alone does not determine business risk.
  • Urgency – Recognizes when active exploitation or critical exposure requires accelerated remediation.
  • Collaboration – Works effectively across Cybersecurity, Service Desk, Infrastructure, Endpoint Engineering, and application teams.
  • Continuous Improvement – Identifies systemic improvements that prevent vulnerabilities from repeatedly returning.

Measures of Success

Performance for this position will be measured primarily by risk reduction and remediation effectiveness, including:

  • Percentage of Critical and High vulnerabilities remediated within OLA
  • Reduction in vulnerability backlog
  • Reduction in vulnerabilities exceeding OLA
  • Mean Time to Remediate (MTTR)
  • First-attempt remediation success rate
  • Reduction in recurring vulnerabilities
  • Percentage of remediation activities automated
  • Accuracy and completeness of remediation documentation

Primary Objective

Drive measurable reduction of cybersecurity risk by ensuring workstation and server vulnerabilities are prioritized, remediated, validated, and closed within established OLAs.

Job details

Job type Contract

Location United States, United States

Reference JOB-5515

Apply now

"*" indicates required fields

Step 1 of 3

Accepted file types: pdf, doc, docx, txt, Max. file size: 4 MB.
If hired, will you now or in the future require sponsorship for employment visa status (e.g., H-1B visa)?
Employment with Tier4 Group and our clients may be contingent upon successfully passing a background check, in compliance with applicable laws. Do you consent to a background check if offered employment?
Are you legally authorized to work in the United States?*