Summary
Fortress Information Security is seeking a Cyber Operator to support a major client engagement's vulnerability management program. The role executes vulnerability monitoring, triage, remediation coordination, validation, risk-acceptance support, reporting, and operational communications while developing expertise in cybersecurity operations.
Responsibilities
- Independently execute the day-to-day workflows of an assigned area of the vulnerability management program — finding validation, applicability analysis, remediation packaging and coordination, remediation validation, risk-acceptance governance, critical-vulnerability escalation, or asset and inventory integrity — in alignment with established procedures, SLAs, and program standards
- Monitor scanning output, vendor advisories, threat feeds, and open-source intelligence to identify applicable and emerging vulnerabilities, escalating higher-severity or ambiguous findings to senior analysts and leads for prioritization
- Validate findings for applicability against advisories, product versions, and asset context; document valid, not-valid, or needs-research determinations with reviewer, date, and audit-sufficient evidence
- Package validated findings into business-unit summary reports and remediation action plans with named owners, due dates, and approval routing; onboard newly added systems and assess their findings
- Create and manage remediation tickets in enterprise ITSM platforms, identifying asset ownership from configuration management data; run the follow-up and escalation cadence, log status, and coordinate with business-unit owners through to confirmed closure
- Validate remediation using credentialed re-scans or business-unit-provided evidence, compare against required patch or configuration state, update product versions, and assemble closure evidence in approved, audit-ready repositories
- Support risk-acceptance and exception intake: screen requests for eligibility, issue and process business-unit questionnaires, route by risk tier, and maintain the record through extension and closure
- Support critical and emerging-vulnerability escalation: participate in coordinated response sessions, track escalated remediation asset-by-asset, and capture owners, action items, and decisions
- Maintain accurate records across the platform and supporting systems, and perform routine data-quality reviews, flagging inconsistencies for resolution
- Own recurring reporting deliverables — remediation tracker updates, business-unit communications, validation and response readouts, monthly leadership reports, and executive-facing presentations — within expected turnaround, including same-business-day delivery for high-severity events
- Exercise editorial judgment when refining operational communications for clarity, tone, and audience, escalating substantive technical-content changes for senior review
- Use approved AI-assisted tools for research, drafting, summarization, and documentation with human review of all outputs
- Build proficiency across program workflows and tooling, and support additional operational activities and projects as assigned
- Other duties as assigned
Skills
- 1–3 years of experience in cybersecurity, vulnerability management, IT operations, SOC operations, technical writing, communications, program support, or a related field; relevant internship experience, coursework, or completion of a cybersecurity boot camp will be considered
- Working familiarity with cybersecurity concepts including vulnerabilities, patching, CVEs, CVSS scoring, and risk fundamentals; formal training or self-study accepted
- Strong written and verbal communication skills, including the ability to produce clear, organized, audience-calibrated written deliverables and audit-ready documentation
- Proficiency with Microsoft Office tools including Word, Excel, PowerPoint, Outlook, and SharePoint
- Strong organizational habits with attention to detail and reliable follow-through
- Ability to manage multiple ongoing workstreams and meet deadlines in a structured, fast-paced operational environment
- Comfort working collaboratively with both technical and non-technical colleagues, with the willingness to learn new tools, platforms, and workflows and apply them consistently
- Ability to leverage AI tools and independently use and refine prompts to enhance the quality, efficiency, and insight of regular work processes
- Associate's degree or equivalent professional work experience required
- Hands-on or coursework exposure to enterprise vulnerability scanning platforms (Tenable, Qualys, Rapid7, or similar) and enterprise ITSM or ticketing platforms (ServiceNow, Jira, or similar)
- Experience producing structured written deliverables, executive-facing presentations, or operational reports on a recurring schedule, including work alongside technical teams in a support, coordination, or communications capacity
- Familiarity with SharePoint, Confluence, or similar collaboration and documentation platforms, and with Power BI, Tableau, or similar reporting and dashboard tools
- Exposure to regulated industries such as utilities, energy, defense, healthcare, or financial services, including NERC-CIP environments
- Cybersecurity-related certifications (CompTIA Security+, Network+, CySA+, or equivalent)
- Familiarity with prioritizing findings by more than base severity score — asset criticality, exposure, and compensating controls
- Exposure to evidence handling for regulatory audit (NERC CIP, BCSI), including timestamped artifacts, non-editable formats, and controlled storage locations
- Bachelor's degree preferred
Qualifications
Must Haves
- 1–3 years of experience in cybersecurity, vulnerability management, IT operations, SOC operations, technical writing, communications, program support, or a related field; relevant internship experience, coursework, or completion of a cybersecurity boot camp will be considered
- Working familiarity with cybersecurity concepts including vulnerabilities, patching, CVEs, CVSS scoring, and risk fundamentals; formal training or self-study accepted
- Strong written and verbal communication skills, including the ability to produce clear, organized, audience-calibrated written deliverables and audit-ready documentation
- Proficiency with Microsoft Office tools including Word, Excel, PowerPoint, Outlook, and SharePoint
- Strong organizational habits with attention to detail and reliable follow-through
- Ability to manage multiple ongoing workstreams and meet deadlines in a structured, fast-paced operational environment
- Comfort working collaboratively with both technical and non-technical colleagues, with the willingness to learn new tools, platforms, and workflows and apply them consistently
- Ability to leverage AI tools and independently use and refine prompts to enhance the quality, efficiency, and insight of regular work processes
- Associate's degree or equivalent professional work experience required
Nice to Haves
- Hands-on or coursework exposure to enterprise vulnerability scanning platforms (Tenable, Qualys, Rapid7, or similar) and enterprise ITSM or ticketing platforms (ServiceNow, Jira, or similar)
- Experience producing structured written deliverables, executive-facing presentations, or operational reports on a recurring schedule, including work alongside technical teams in a support, coordination, or communications capacity
- Familiarity with SharePoint, Confluence, or similar collaboration and documentation platforms, and with Power BI, Tableau, or similar reporting and dashboard tools
- Exposure to regulated industries such as utilities, energy, defense, healthcare, or financial services, including NERC-CIP environments
- Cybersecurity-related certifications (CompTIA Security+, Network+, CySA+, or equivalent)
- Familiarity with prioritizing findings by more than base severity score — asset criticality, exposure, and compensating controls
- Exposure to evidence handling for regulatory audit (NERC CIP, BCSI), including timestamped artifacts, non-editable formats, and controlled storage locations
- Bachelor's degree preferred
Benefits
- Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families
- Company paid life, short- and long-term disability insurance
- Employee Assistance Program
- 401(k) match
- Flexible Paid Time Off
- Parental Leave
- Professional growth opportunities through succession planning, up-skilling, and certifications
- Tuition and certification reimbursement
- Employee Referral Programs
- Company Sponsored Events