Data First Jobs

Holistic Partners, Inc

Cyber Risk and Vulnerability Analyst

Contract · In Office · Chicago, Illinois (USA)

Posted Aug 17, 2026

Work Options
Cloud Stack
Industry
Job Type
Position Group
  • Job Opportunity: Senior Cyber Risk and Vulnerability Analyst
  • Location: Onsite 3 days a week (Monday-Wednesday) Chicago, Illinois
  • Duration: 12+ Months Contract
  • Key Responsibility
  • In-Office Requirement:
  • We would require this candidate to be in the office 2-3 days a week, preferably on days when the rest of the team is also in the office for collaborative purposes. (Mon-Thurs)
  • Job Description Summary:
  • We are seeking a skilled and motivated Senior Cyber Risk and Vulnerability Analyst to strengthen our cybersecurity risk management and vulnerability management capabilities.
  • This role will conduct security risk assessments, support risk quantification and reporting, coordinate vulnerability remediation, and provide security consultation to business and technology stakeholders.
  • The analyst will also contribute to security awareness and day-to-day operational security activities that help maintain a secure and resilient environment
  • Requirements:
  • Bachelor’s degree in cybersecurity, information technology, or a related field, or an equivalent combination of education and relevant experience.
  • Relevant security or cloud certifications, such as Security+, Microsoft Azure, or AWS certifications, are preferred.
  • Five or more years of relevant experience in cybersecurity, technology risk, vulnerability management, security governance, or a related field, including demonstrated experience conducting security risk assessments and coordinating remediation activities.
  • Security risk assessment experience: Working knowledge of NIST CSF, NIST SP 800-53, ISO 27001, CIS Controls, or comparable security and control frameworks.
  • Experience evaluating technical and administrative controls.
  • Experience applying qualitative or quantitative methods to assess, prioritize, and communicate security risk.
  • Strong documentation and report-writing skills.
  • Ability to communicate risk to non-technical audiences.
  • Experience with vulnerability scanning tools such as Nexpose, Qualys or Nessus or similar vulnerability management platforms
  • Vulnerability management or remediation-governance experience
  • Experience developing and tracking remediation plans in partnership with technical teams
  • Excellent analytical and problem-solving skills.
  • Be a clear and confident public speaker, able to tailor messaging around technical concepts to diverse audiences.
  • Ability to quickly learn new processes and tools
  • Ability to think critically, ask thoughtful questions, and challenge assumptions in a constructive manner.
  • Naturally curious and driven to understand how technologies, applications, and business processes operate.
  • Preferred:
  • Familiarity of Infrastructure, Container, SAST, DAST vulnerability remediation concepts from a vulnerability management remediation perspective is a plus.
  • This role will work with existing application security resources to enhance the existing vulnerability management program.
  • Experience with ServiceNow Vulnerability Response Module is a plus
  • Self-starter who can work independently as well as in a team setting
  • Experience analyzing security data in Tableau, Power BI, or comparable tools to identify trends, and develop metrics that support operational and strategic decision-making.
  • Key Responsibilities:
  • Strengthen and expand the organization's Cyber Risk Management capabilities through risk assessments, advisory services, governance activities, and reporting.
  • Support risk analysis, quantification, and reporting efforts to improve organizational understanding and prioritization of cybersecurity risk.
  • Support the development, operationalization, and ongoing maintenance of the Security Risk Register, including risk documentation, scoring, stakeholder consultation, remediation tracking, governance, and reporting.
  • Demonstrates intellectual curiosity and a desire to continuously learn, investigate security concerns, challenge assumptions, and identify emerging risks, threats, and opportunities for security improvement.
  • Work with existing staff to identify and create process improvements to the existing vulnerability management and security awareness programs
  • Work with remediation teams to create and track plans to address discovered vulnerabilities.
  • Identify and evaluate vulnerability metrics to determine areas of concern and improvement.
  • Develop, maintain, and adhere to documented procedures, standards, and operational processes.
  • Conduct security risk assessments of applications, technologies, vendors, projects, and business initiatives to evaluate security control effectiveness and identify areas of risk.
  • Contribute to Security Awareness efforts on an as needed basis.
  • Support misc. operational tasks via ticket system
  • We are looking for additional support in the below operational support areas:
  • Manage and resolve incoming service requests and incidents through a ticketing system.
  • Evaluate new technologies and solutions to ensure alignment with organizational security policies, standards, and risk tolerance before adoption.
  • Review and assess third-party SOC2 reports as part of vendor security evaluations.
  • Review and respond to phishing emails reported by users, and escalate if necessary.

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

Cyber Risk and Vulnerability Analyst

Holistic Partners, Inc

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.