ARUP Laboratories Logo

ARUP Laboratories

Vulnerability Analyst IV

Posted 18 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Lead enterprise vulnerability management: research and validate vulnerabilities, prioritize remediation, perform risk assessments, exploit development and pen-testing, support SOC incident response, produce reports and training, and collaborate with IT/Dev teams to reduce cyber risk.
The summary above was generated by AI

Schedule:
Monday - Friday (40 hrs/wk)
8:00 AM - 5:00 PM

Department: IT General - 210

Primary Purpose:

The Vulnerability Analyst conducts extensive research on newly discovered vulnerabilities in operating systems, application software, infrastructure, and firewalls.  Serves as a senior technical leader within the Security Operations Center (SOC), responsible for overseeing enterprise-wide vulnerability management strategies. This role investigates, analyzes, and develops methods for exploiting such vulnerabilities. The analyst performs Security Impact Analysis (SIA) to determine how proposed or completed changes to information systems affect overall security. This process involves assessing potential vulnerabilities and risks introduced by modifications to components such as operating systems, networks, software, and security controls. The Vulnerability Analyst reports directly to the Security Operations Center (SOC) Manager.

About ARUP:

ARUP Laboratories is a national clinical and anatomic pathology reference laboratory and an enterprise of the University of Utah and its Department of Pathology. Based in Salt Lake City, Utah.

ARUP proudly hires top talent to create a work environment of diversity, professional growth and continuous development.  Our workforce is committed to the important service we provide to over one million patients each month.  We always strive for excellence and have a strong desire to have involvement with the advances in medicine and the role laboratory services plays within each patient’s life. We never forget that there is a patient behind every specimen we receive.

We are looking for individuals who want to contribute to ARUP's culture of accountability, integrity, service, and excellence.  Consider joining our dynamic team.

Essential Functions:

Lead advanced cyber vulnerability assessments of applications, systems, vendor IT networks, and cloud architecture.

Analyze and validate scan results, correlate findings, and determine severity and risk impact to prioritize remediation efforts.

Maintain and update vulnerability tracking systems, dashboards, and compliance reports.

Develop and present reports, briefs, and metrics to communicate vulnerability status, remediation progress, and compliance standing to leadership.

Stay informed about emerging vulnerabilities, CVEs, threat intelligence, and cybersecurity best practices.

Conduct comprehensive risk assessments of IT systems, applications, and business processes, recommending improvements to security controls.

Maintain detailed risk registers by analyzing threat intelligence and vulnerability data to identify emerging risks.

Develop and perform cybersecurity risk assessments and mitigation strategies.

Collaborate with administrators, DevOps teams, researchers, Change Approval Board (CAB), and IT Tech Debt Committee to identify, prioritize, and remediate vulnerabilities.

Lead efforts with remediation teams, system owners, and senior security staff to track and resolve identified vulnerabilities.

Apply advanced techniques threat modeling, penetration testing, and exploit development techniques to identify risks across on-premises and cloud environments.

Contribute to recurring cyber vulnerability updates and prepare executive-level summaries of findings for senior leadership.

Provide subject matter expert support in incident response investigations and provide technical recommendations to strengthen system defenses.

Develop and deliver training and awareness programs for team members and stakeholders on vulnerability identification, remediation, and secure system design practices.

Provide expert support to the Security Operations Center (SOC) Tier 1 and Tier 2 Analyst teams as needed in performing threat detection and incident response.

Physical Requirements:

Stooping: Bending body downward and forward by bending spine at the waist.

Reaching: Extending hand(s) and arm(s) in any direction.

Mobility: The person in this position needs to occasionally move between work sites and inside the office to access file cabinets, office machinery, etc.

Communication: The person in this position will work in a highly collaborative environment which requires frequent, clear, and professional communication with others.

PPE: Biohazard laboratory environment that requires use of personal protective equipment in accordance with CDC and OSHA regulations and company policies. 

ARUP Policies and Procedures: To conduct self in compliance with all ARUP Policies and Procedures.

Sedentary Work: Exerting up to 10 pounds of force occasionally and/or negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.  

Fine Motor Control: Picking, pinching, typing or otherwise working on computer equipment. 

Vision: Having close, far, and peripheral visual acuity to perform a variety of tasks such as making general observations of depth and distance.

Qualifications Education Required Bachelor's Degree or better. Preferred Master's Degree or better. Experience Required Bachelor’s degree in Cybersecurity, Information Technology, or related field Six (6) years of cybersecurity experience, including at least 4 years focused on vulnerability analysis, penetration testing, or cyber risk management Strong understanding of security frameworks (e.g., NIST, MITRE ATT&CK) Experience with vulnerability scanning tools Experience with EDR solutions Excellent communication, analytical, and problem-solving skills Deep knowledge of NIST, ISO/IEC 27001, HITRUST frameworks Preferred Relevant certifications (e.g., CISSP, CISM, CEH, CND, GCIA, GCIH) Experience in healthcare or laboratory environments preferred Master’s degree in Cybersecurity, Information Technology, or related field Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Similar Jobs

17 Minutes Ago
In-Office or Remote
United States
Entry level
Entry level
Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
Handle inbound and outbound mortgage collections calls, review account status, collect payments, evaluate customer finances, negotiate repayment solutions, and document account actions. Ensure compliance with customer information security, debt collection, and mortgage regulations while meeting quality, productivity, and operational targets. The role includes extensive training and operates on a hybrid schedule with three days onsite and two days remote in Irving, Texas.
Top Skills: Ai SimulationsDigital Phone SystemsExcelMicrosoft WordMsp/Black Knight
An Hour Ago
Remote or Hybrid
179K-322K Annually
Senior level
179K-322K Annually
Senior level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Leads a specialized casualty claims team managing severe-exposure portfolios, complex litigation, coverage issues, reserves, settlements, vendors, and claim-handling protocols. Partners with legal, underwriting, actuarial, reinsurance, and other stakeholders to develop strategies, monitor litigation trends, address legal system abuse, manage financial outcomes, and improve operational performance. Coaches claims leaders, oversees staffing and portfolio capacity, and presents strategic recommendations to executives and business partners.
Top Skills: Guidewire Claims System
2 Hours Ago
Remote or Hybrid
Seattle, WA, USA
83K-157K Annually
Senior level
83K-157K Annually
Senior level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Own model observability for Auto Physical Damage data science products, including traditional ML and GenAI/LLM systems. Build monitoring pipelines, dashboards, metrics, thresholds, alerts, and remediation documentation. Detect drift, performance degradation, anomalies, and data-quality issues; support MLOps, LLMOps, governance, compliance, and audit reporting. Analyze business outcomes, identify improvement opportunities, and communicate model health findings to technical and non-technical stakeholders.
Top Skills: AWSAzureEmblemExcelGCPLlmopsMlopsPowerPointPythonSASSQLStreamlitTableauVBA

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account