Fortress Information Security logo
Fortress Information Security
Posted 46 days agoVerified live 4h ago

Cyber Operator

Brief overview

Remote
UndergradOr in progress
$55k–$75k/yrStated range
1+ yrsMinimum
4 H-1B approvalsDept. of Labor
2 green cardsCertified filings
Vulnerability ManagementPatch ManagementCVSS ScoringMicrosoft OfficeSharePointTenableQualysRapid7ServiceNowJiraRisk ManagementNERC CIPWritten and Verbal Communication

About the company

Fortress Information Security logo
Fortress Information Securityfortressinfosec.com

Fortress protects governments, critical infrastructure, supply chains, and digital assets from advanced cyber threats.

Visa sponsorship history

3 years sponsoring, last filed FY2025

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
4H-1B approved
100%approval rate
1new H-1B hires
2PERM certified
$105,341median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20231
20242
20251
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231
20241
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20252
Top sponsored roles
Software EngineerDeveloper

Job description

Summary

Fortress Information Security is seeking a Cyber Operator to support a major client engagement's vulnerability management program. The role executes vulnerability monitoring, triage, remediation coordination, validation, risk-acceptance support, reporting, and operational communications while developing expertise in cybersecurity operations.

Responsibilities

  • Independently execute the day-to-day workflows of an assigned area of the vulnerability management program — finding validation, applicability analysis, remediation packaging and coordination, remediation validation, risk-acceptance governance, critical-vulnerability escalation, or asset and inventory integrity — in alignment with established procedures, SLAs, and program standards
  • Monitor scanning output, vendor advisories, threat feeds, and open-source intelligence to identify applicable and emerging vulnerabilities, escalating higher-severity or ambiguous findings to senior analysts and leads for prioritization
  • Validate findings for applicability against advisories, product versions, and asset context; document valid, not-valid, or needs-research determinations with reviewer, date, and audit-sufficient evidence
  • Package validated findings into business-unit summary reports and remediation action plans with named owners, due dates, and approval routing; onboard newly added systems and assess their findings
  • Create and manage remediation tickets in enterprise ITSM platforms, identifying asset ownership from configuration management data; run the follow-up and escalation cadence, log status, and coordinate with business-unit owners through to confirmed closure
  • Validate remediation using credentialed re-scans or business-unit-provided evidence, compare against required patch or configuration state, update product versions, and assemble closure evidence in approved, audit-ready repositories
  • Support risk-acceptance and exception intake: screen requests for eligibility, issue and process business-unit questionnaires, route by risk tier, and maintain the record through extension and closure
  • Support critical and emerging-vulnerability escalation: participate in coordinated response sessions, track escalated remediation asset-by-asset, and capture owners, action items, and decisions
  • Maintain accurate records across the platform and supporting systems, and perform routine data-quality reviews, flagging inconsistencies for resolution
  • Own recurring reporting deliverables — remediation tracker updates, business-unit communications, validation and response readouts, monthly leadership reports, and executive-facing presentations — within expected turnaround, including same-business-day delivery for high-severity events
  • Exercise editorial judgment when refining operational communications for clarity, tone, and audience, escalating substantive technical-content changes for senior review
  • Use approved AI-assisted tools for research, drafting, summarization, and documentation with human review of all outputs
  • Build proficiency across program workflows and tooling, and support additional operational activities and projects as assigned
  • Other duties as assigned

Skills

  • 1–3 years of experience in cybersecurity, vulnerability management, IT operations, SOC operations, technical writing, communications, program support, or a related field; relevant internship experience, coursework, or completion of a cybersecurity boot camp will be considered
  • Working familiarity with cybersecurity concepts including vulnerabilities, patching, CVEs, CVSS scoring, and risk fundamentals; formal training or self-study accepted
  • Strong written and verbal communication skills, including the ability to produce clear, organized, audience-calibrated written deliverables and audit-ready documentation
  • Proficiency with Microsoft Office tools including Word, Excel, PowerPoint, Outlook, and SharePoint
  • Strong organizational habits with attention to detail and reliable follow-through
  • Ability to manage multiple ongoing workstreams and meet deadlines in a structured, fast-paced operational environment
  • Comfort working collaboratively with both technical and non-technical colleagues, with the willingness to learn new tools, platforms, and workflows and apply them consistently
  • Ability to leverage AI tools and independently use and refine prompts to enhance the quality, efficiency, and insight of regular work processes
  • Associate's degree or equivalent professional work experience required
  • Hands-on or coursework exposure to enterprise vulnerability scanning platforms (Tenable, Qualys, Rapid7, or similar) and enterprise ITSM or ticketing platforms (ServiceNow, Jira, or similar)
  • Experience producing structured written deliverables, executive-facing presentations, or operational reports on a recurring schedule, including work alongside technical teams in a support, coordination, or communications capacity
  • Familiarity with SharePoint, Confluence, or similar collaboration and documentation platforms, and with Power BI, Tableau, or similar reporting and dashboard tools
  • Exposure to regulated industries such as utilities, energy, defense, healthcare, or financial services, including NERC-CIP environments
  • Cybersecurity-related certifications (CompTIA Security+, Network+, CySA+, or equivalent)
  • Familiarity with prioritizing findings by more than base severity score — asset criticality, exposure, and compensating controls
  • Exposure to evidence handling for regulatory audit (NERC CIP, BCSI), including timestamped artifacts, non-editable formats, and controlled storage locations
  • Bachelor's degree preferred

Qualifications

Must Haves

  • 1–3 years of experience in cybersecurity, vulnerability management, IT operations, SOC operations, technical writing, communications, program support, or a related field; relevant internship experience, coursework, or completion of a cybersecurity boot camp will be considered
  • Working familiarity with cybersecurity concepts including vulnerabilities, patching, CVEs, CVSS scoring, and risk fundamentals; formal training or self-study accepted
  • Strong written and verbal communication skills, including the ability to produce clear, organized, audience-calibrated written deliverables and audit-ready documentation
  • Proficiency with Microsoft Office tools including Word, Excel, PowerPoint, Outlook, and SharePoint
  • Strong organizational habits with attention to detail and reliable follow-through
  • Ability to manage multiple ongoing workstreams and meet deadlines in a structured, fast-paced operational environment
  • Comfort working collaboratively with both technical and non-technical colleagues, with the willingness to learn new tools, platforms, and workflows and apply them consistently
  • Ability to leverage AI tools and independently use and refine prompts to enhance the quality, efficiency, and insight of regular work processes
  • Associate's degree or equivalent professional work experience required

Nice to Haves

  • Hands-on or coursework exposure to enterprise vulnerability scanning platforms (Tenable, Qualys, Rapid7, or similar) and enterprise ITSM or ticketing platforms (ServiceNow, Jira, or similar)
  • Experience producing structured written deliverables, executive-facing presentations, or operational reports on a recurring schedule, including work alongside technical teams in a support, coordination, or communications capacity
  • Familiarity with SharePoint, Confluence, or similar collaboration and documentation platforms, and with Power BI, Tableau, or similar reporting and dashboard tools
  • Exposure to regulated industries such as utilities, energy, defense, healthcare, or financial services, including NERC-CIP environments
  • Cybersecurity-related certifications (CompTIA Security+, Network+, CySA+, or equivalent)
  • Familiarity with prioritizing findings by more than base severity score — asset criticality, exposure, and compensating controls
  • Exposure to evidence handling for regulatory audit (NERC CIP, BCSI), including timestamped artifacts, non-editable formats, and controlled storage locations
  • Bachelor's degree preferred

Benefits

  • Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families
  • Company paid life, short- and long-term disability insurance
  • Employee Assistance Program
  • 401(k) match
  • Flexible Paid Time Off
  • Parental Leave
  • Professional growth opportunities through succession planning, up-skilling, and certifications
  • Tuition and certification reimbursement
  • Employee Referral Programs
  • Company Sponsored Events

More jobs like this