Vulnerability Management Analyst
Bain & Company · Boston, United States +2 · 1h ago
WHAT MAKES US A GREAT PLACE TO WORK
We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.
WHO YOU’LL WORK WITH
You’ll join our Cyber Operations team within Bain’s Technology Services Group (TSG), working closely with IT, infrastructure, cloud, and engineering teams across a large and diverse global environment.
WHERE YOU’LL FIT WITHIN THE TEAM
As a Vulnerability Management Analyst, you’ll operate and drive the day-to-day maturity of our vulnerability and exposure management program across a large, diverse global environment spanning servers, endpoints, network devices, containers, and multi-cloud workloads.
You’ll work hands-on with our core tooling stack, including Qualys Vulnerability Management, Detection and Response (VMDR) for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation.
You’ll also lead a Continuous Threat Exposure Management (CTEM) program that turns findings from these tools into a single, risk-prioritized view of real exposure. Working closely with IT, infrastructure, cloud, and engineering teams, you’ll set remediation standards, drive accountability, guide junior analysts, and brief leadership on exposure and risk trends.
WHAT YOU’LL DO
Own and continuously improve the end-to-end vulnerability management lifecycle across the enterprise, including asset discovery, scanning, detection, validation, prioritization, remediation governance, rescanning, and closure verification.
Operate and administer our core exposure management tools, Qualys VMDR, Wiz, and Tanium, including deployment, configuration, tuning, integration, and scanner, agent, and sensor health.
Lead the Continuous Threat Exposure Management (CTEM) program, coordinating scoping, discovery, prioritization, validation, and mobilization activities while consolidating findings into a single, risk-ranked view of exposure.
Prioritize vulnerabilities using the Common Vulnerability Scoring System (CVSS), Exploit Prediction Scoring System (EPSS), CISA Known Exploited Vulnerabilities (KEV), threat intelligence, and business criticality.
Establish and enforce remediation service-level agreements (SLAs), partnering with IT, infrastructure, cloud, and engineering teams to drive accountability and resolve high-risk exposures.
Collaborate with threat intelligence teams to connect emerging threats with internal vulnerabilities and guide targeted remediation efforts.
Define and maintain exception and risk-acceptance standards, ensuring appropriate documentation for audits, compliance, and leadership reporting.
Develop and automate dashboards and reporting on vulnerability exposure, scan coverage, remediation progress, vulnerability aging, and SLA adherence using native reporting tools, Excel, and business intelligence solutions.
Mentor junior analysts, establish standards for triage and reporting, and serve as an escalation point for complex findings.
Provide recommendations on secure configurations, system hardening, and overall vulnerability management program maturity, communicating effectively with both technical teams and senior stakeholders.
ABOUT YOU
Required Qualifications
Experience: 3–5 years of hands-on experience in vulnerability management, exposure management, or closely related security operations, including experience in a lead capacity.
Vulnerability Management: Deep understanding of the vulnerability management lifecycle, risk-based remediation, and SLA governance across large, complex environments.
Security Tooling: Direct hands-on experience operating and administering Qualys VMDR, Wiz, and Tanium, including deployment, configuration, tuning, integration, and reporting. Experience with all three platforms is required.
CTEM: Demonstrated experience running or materially contributing to a Continuous Threat Exposure Management program, including scoping, discovery, prioritization, validation, and mobilization.
Risk Prioritization: Proficiency in CVSS analysis, EPSS, CISA KEV, and threat-intelligence-driven vulnerability prioritization.
Data & Reporting: Strong reporting and analytical capabilities, including Excel, pivot tables, and native security tool reporting, with the ability to produce technical and executive-level metrics.
Technical Environment: Experience securing complex environments spanning Windows, Linux, network devices, endpoints, containers, and multi-cloud workloads.
Threat Intelligence: Strong understanding of threat intelligence sources and the ability to correlate external threats with internal findings.
Communication & Leadership: Excellent written, verbal, and presentation skills, with the ability to influence stakeholders, communicate risks to leadership, and mentor junior analysts.
English: Advanced English proficiency, with the ability to communicate effectively in professional and technical environments.
Preferred Qualifications
Knowledge of cloud security posture management (CSPM), cloud-native application protection platforms (CNAPP), and container or Kubernetes security concepts, ideally using Wiz or equivalent technologies.
Familiarity with CIS Benchmarks, secure configuration practices, and system hardening standards.
Experience with scripting and automation using Python, PowerShell, tool APIs, or Power Query.
Experience integrating vulnerability management tools with IT service management platforms, such as ServiceNow, to automate remediation workflows.
Preferred Certifications
One or more of the following certifications, or a willingness to obtain them:
Qualys VMDR Certification
Wiz certification or equivalent cloud security/CNAPP certification
GIAC certification, such as GEVA or GCED, or Certified Ethical Hacker (CEH)
CISSP, Tanium, or CompTIA Security+, or progress toward these certifications
WORKING MODEL
This role follows a hybrid model, requiring in-office presence at least one day per week at our Boston, Chicago, or Dallas office, depending on the selected location.
U.S. COMPENSATION INFORMATION
Compensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).
Some local governments in the United States require a good-faith, reasonable salary range to be included in job postings for open roles. The estimated annualized compensation for this role is as follows:
In Boston, Massachusetts, the good-faith, reasonable annualized full-time salary range for this role is between 67k and 80k.
In Chicago, Illinois, the good-faith, reasonable annualized full-time salary range for this role is between 64k and 77k.
In Dallas, Texas, the good-faith, reasonable annualized full-time salary range for this role is between 61k and 73k.
Placement within these ranges will vary based on several factors including, but not limited to experience, education, licensure/certifications, training, and skill level.
Annual discretionary performance bonus
This role may also be eligible for other elements of discretionary compensation
4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start date
Bain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.
Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheck
Generous paid time off, including parental leave, sick leave and paid holidays
Fully vested 401(k) company contribution
Paid Life and Long-Term Disability insurance
Annual fitness reimbursements