ForgeApply · Job listing
Information Security Analyst (Vulnerability Management)
Jda
Tailor your resume for this Jda job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Jda's site. Free trial, no card required.
About this role
Role: Information Security Analyst ( VTM/Vulnerability Management ) Location: Dallas, TX (Must be local to Dallas and able to come onsite to the Dallas office twice per month – hybrid/work from home) Synonymous Business Title (s): Lead SIEM Analyst, Lead Security Administrator Requirement: US Citizen (Must Hold OR Be Willing to Obtain a Government Clearance)
About BY Defense Solutions:
Blue Yonder Defense Solutions, LLC., a Blue Yonder company, is the leader in supply chain autonomous planning. Our innovative solutions empower businesses to optimize their supply chains, enhance customer experiences, and drive sustainable growth. We are committed to delivering cutting-edge technology and unparalleled expertise to help our defense and humanitarian-aid clients navigate the complexities of the modern supply chain.
Overview:
Blue Yonder Defense Solutions (BYDS) is seeking an Information Security Analyst to support the organization's cybersecurity operations, vulnerability management program, compliance initiatives, and risk management activities. This role plays a critical part in identifying, analyzing, and remediating security vulnerabilities across cloud and on-premises environments while helping maintain compliance with government and industry security requirements.
The successful candidate will support compliance with ISO/IEC 27001, the Department of Defense Cybersecurity Maturity Model Certification (CMMC) Level 2, NIST (National Institute of Standards and Technology) Special Publication 800-171 and Special Publication 800-53, along with other cybersecurity standards applicable to U.S. Government contractors. The role supports a cloud-first environment utilizing Microsoft Azure, Oracle Cloud Infrastructure (OCI), and Microsoft 365 and will work closely with IT, engineering, and business stakeholders to strengthen Blue Yonder Defense Solutions overall security posture.
Security Tech Stack/Tools:
Cloud & Identity Platforms • Azure AD / Entra ID, AWS IAM, Oracle IAM • Federation & SSO: SAML, OAuth, OIDC, SCIM
Security, Monitoring & Scanning • SIEM/EDR/XDR (CrowdStrike, Splunk, Elastic etc.) • Defender for Endpoint, Defender for Cloud, Oracle Vulnerability Manager, Amazon Inspector, Tenable, OpenVAS • Identity threat analytics and access risk tooling
Automation & Dev Integration PowerShell, Python, REST / SCIM / Graph / SOAP APIs
Security Compliance • NIST (National Institute of Standards and Technology) SP 800-171 and SP 800-53 • Cybersecurity Maturity Model Certification (CMMC) Level 2 • ISO/IEC 27001 Information Security Management Standard • CIS (Center for Internet Security) Benchmarks • FedRAMP (Federal Risk and Authorization Management Program) fundamentals
What You’ll Be Doing: • Conduct regular vulnerability scans across cloud and on-premises assets using industry-standard tools. • Analyze scan results, assess risk, prioritize findings, and recommend remediation activities based on business impact. • Collaborate with IT, infrastructure, and development teams to track, prioritize, and remediate security vulnerabilities. • Develop and maintain automation scripts and reporting processes to support vulnerability management activities. • Support incident response efforts by providing vulnerability context, risk analysis, and remediation guidance. • Document vulnerability management processes, findings, remediation activities, and security recommendations. • Assist with compliance initiatives by providing evidence, reporting, and support for ISO 27001, CMMC Level 2, NIST 800-171, and NIST 800-53 requirements. • Stay current with emerging threats, vulnerability trends, cybersecurity technologies, and industry best practices. • Participate in ongoing efforts to strengthen BYDS's security posture across cloud and enterprise environments
What We’re Looking For:
Required Qualifications • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field; equivalent professional experience considered in lieu of degree. • 5+ years of cybersecurity, vulnerability management, security operations, or information security experience. • Experience supporting government, defense contractor, or Defense Industrial Base (DIB) environments. • Working knowledge of Cybersecurity Maturity Model Certification (CMMC) Level 2 and NIST SP 800-171 and/or NIST SP 800-53 frameworks. • Hands-on experience with vulnerability scanning tools, vulnerability assessment, remediation, and risk prioritization. • Experience securing cloud-based environments, including Microsoft Azure, Oracle Cloud Infrastructure (OCI), AWS, and/or Microsoft 365. • Strong communication, documentation, and cross-functional collaboration skills.
Preferred Qualifications • Experience supporting ISO/IEC 27001 compliance programs and audits. • Familiarity with vulnerability management solutions such as Tenable, OpenVAS, Qualys, Rapid7, Amazon Inspector, Microsoft Defender, or similar tools. • Experience supporting incident response and security investigations. • Experience working within highly regulated environments subject to government or defense cybersecurity requirements. • Industry certifications such as Security+, CySA+, SSCP, GSEC, SC-200, AZ-500, or equivalent cybersecurity certifications.
Preferred Certifications • One or more industry-recognized cybersecurity certifications such as Security+, CySA+, SSCP, GSEC, Microsoft Security (SC-200/AZ-500), or equivalent. • Certifications or training related to ISO 27001, NIST SP 800-171, or NIST SP 800-53 are a plus.
Soft Skills • Strong analytical, troubleshooting, and problem-solving skills. • Excellent written, verbal, and technical documentation skills. • Ability to manage multiple priorities while maintaining attention to detail. • Ability to communicate effectively with both technical and non-technical stakeholders. • Collaborative mindset with a commitment to continuous learning and professional growth.
#LI-Hybrid #LI-MH1
-----------------
Salary insight
The midpoint of this range ($111k) is about 23% below the median disclosed salary for Dallas roles listed on ForgeApply ($144k across 517 jobs).
See full Security Engineer salary data for Dallas →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Jda role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Security Engineer, Vulnerability Management — 1password · Remote
- Vulnerability Assessment Analyst — Accenturefederalservices · Columbia, MD
- Cyber Vulnerability Analyst — Parsons · US - MD, Annapolis Junction
- Staff Security Engineer, Vulnerability Management — Coreweave · Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA
- Information Security Analyst — Spacex · Starbase, TX
- Information Security Analyst — Spacex · Hawthorne, CA
- Senior Staff Security Engineer, Vulnerability Management — Zocdoc · Remote
- Senior Security Software Engineer, Vulnerability Management — Roblox · San Mateo, CA, United States
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Dallas · More jobs at Jda · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)