Description & Requirements
WHAT MAKES US A GREAT PLACE TO WORK
We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.
WHO YOU’LL WORK WITH
You’ll join our Cyber Operations team within Bain’s Technology Services Group (TSG), working closely with IT, infrastructure, cloud, and engineering teams across a large and diverse global environment.
WHERE YOU’LL FIT WITHIN THE TEAM
As a Vulnerability Management Analyst, you’ll operate and drive the day-to-day maturity of our vulnerability and exposure management program across a large, diverse global environment spanning servers, endpoints, network devices, containers, and multi-cloud workloads.
You’ll run our core tooling stack hands-on — Qualys Vulnerability Management, Detection and Response (VMDR) for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation.
You’ll also lead a Continuous Threat Exposure Management (CTEM) program that turns findings from these tools into a single, risk-prioritized view of real exposure. Working closely with IT, infrastructure, cloud, and engineering teams, you’ll set remediation standards, drive accountability, guide junior analysts, and brief leadership on exposure and risk trends.
Location and working model: Mexico City, Mexico. This role follows a hybrid working model and requires you to work from Bain’s Polanco office at least two days per week.
WHAT YOU’LL DO
- Own and continuously mature the end-to-end vulnerability management lifecycle across the enterprise, including asset discovery, scanning, detection, validation, prioritization, remediation governance, rescanning, and closure verification.
- Operate and administer the core exposure tooling stack hands-on — Qualys VMDR for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation — including deployment, configuration, tuning, integration, and scanner, agent, and sensor health.
- Lead the Continuous Threat Exposure Management (CTEM) program, running the scoping, discovery, prioritization, validation, and mobilization cycles and correlating findings across host, cloud, and endpoint sources into a single de-duplicated, risk-ranked view of exposure.
- Prioritize vulnerabilities using the Common Vulnerability Scoring System (CVSS) combined with exploitability signals, including the Exploit Prediction Scoring System (EPSS) and CISA Known Exploited Vulnerabilities (KEV), threat intelligence, and asset and business criticality — focusing remediation on what is exploitable and material.
- Set and enforce remediation service-level agreements (SLAs) and drive accountability with IT, infrastructure, cloud, and engineering teams, translating findings into clear, actionable work and escalating aged or high-risk exposures.
- Partner with threat intelligence to correlate external threat activity with internal findings, translate emerging threats into targeted validation and remediation, and surface material risks for escalation.
- Define exception and risk-acceptance standards, review and adjudicate requests, and maintain defensible documentation to support audits, compliance, and leadership reporting.
- Build and automate dashboards, metrics, and executive reporting on exposure, scan coverage, vulnerability aging, and SLA adherence using native tool reporting, Excel, including pivot tables, and query or business intelligence tooling.
- Mentor junior analysts, set standards for triage, documentation, and reporting quality, and act as the escalation point for complex or contested findings.
- Advise on secure configuration, hardening, and overall program maturity, and communicate findings and recommendations clearly to audiences ranging from engineers to senior stakeholders.
ABOUT YOU
Required Qualifications
- Experience: You have 3–5 years of hands-on experience in vulnerability management, exposure management, or closely related security operations, including time in a lead capacity.
- Lifecycle and governance: You have a deep understanding of the vulnerability management lifecycle, risk-based remediation, and SLA governance across large, complex environments.
- Tooling — hands-on: You have direct, hands-on experience operating and administering Qualys VMDR, Wiz, and Tanium, including deployment, configuration, tuning, integration, and reporting. Hands-on depth with all three is required.
- CTEM: You have demonstrated experience running or materially contributing to a Continuous Threat Exposure Management program across its scoping, discovery, prioritization, validation, and mobilization phases.
- Risk prioritization: You are proficient in CVSS analysis combined with exploitability signals, including EPSS and CISA KEV, and threat-intelligence-driven, risk-based prioritization.
- Data and reporting: You have strong data and reporting skills, including Excel and pivot tables, native tool reporting, and ideally query or business intelligence tooling, enabling you to produce both technical and executive-level metrics.
- Environment breadth: You have proven experience securing large, diverse environments spanning Windows, Linux, network devices, endpoints, containers, and multi-cloud workloads.
- Threat awareness: You have strong working knowledge of threat intelligence sources and the ability to correlate external threat data with internal findings to drive prioritization.
- Communication and leadership: You have excellent written, verbal, and presentation skills, with the ability to influence remediation owners, brief senior leadership, and mentor junior analysts.
- English: Advanced English proficiency is required, with the ability to communicate effectively in professional and technical environments.
Preferred / Nice-to-Have
- Cloud and container security: Working knowledge of cloud security posture management (CSPM), cloud-native application protection platforms (CNAPP), and container/Kubernetes security concepts, ideally through Wiz or an equivalent platform.
- Benchmarking: Working knowledge of CIS Benchmarks and secure configuration and hardening standards.
- Automation: Exposure to scripting or automation, such as Python, PowerShell, tool APIs, or Power Query, to integrate tooling and streamline reporting or remediation workflows.
- Integrations: Experience integrating vulnerability and exposure tooling with IT service management (ITSM) platforms, such as ServiceNow, to automate remediation workflows.
Certifications
One or more relevant certifications are preferred, or a willingness to obtain them:
- Qualys VMDR Certification
- Wiz Certified or equivalent cloud security/CNAPP certification
- GIAC certification, such as GEVA or GCED, or Certified Ethical Hacker (CEH)
- CISSP, Tanium, or CompTIA Security+, or progress toward these certifications