Find Jobs
Find Jobs Near You – Available Work in Your Location
Cyber Threat and Vulnerability Analyst
Career Insights for Cyber Crime Analyst / Investigator
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Florida data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Crime Analyst or Investigator investigates a number of crimes, ranging from recovering file systems on computers that have been hacked or damaged to investigating crimes against children. Recovers data from computers that can be used in prosecuting crimes in court. Computer crime investigators must also write reports for and testify in court. Also may work for large corporations to test security systems that are currently in place. Investigators do this by trying various ways to hack into the corporation's computer networks. At corporations, computer crime investigators also maximize optimal computer system performance levels.
$105,761 / year median in Florida
+8% projected growth
Job Description
ROLE:
The Threat and Vulnerability Management Analyst is responsible for identifying, prioritizing, and coordinating the remediation of security weaknesses across HEICO's applications, endpoints, networks, and cloud environments. This role acts as a critical link between threat intelligence and the systems teams executing remediation. In addition to standard vulnerability management, this position proactively validates external defenses through security configuration testing and monitors for sensitive data exposure to ensure a robust overall data security posture.ESSENTIAL DUTIES AND RESPONSIBILITIES
Scanning & Identification Run regular vulnerability scans across on-premises, hybrid, and cloud environments. Configure, maintain, and tune scanning tools to ensure accurate coverage and minimize false positives. Data Security & Access Monitoring Monitor for excessive or inappropriate access to sensitive data and verify compliance with data protection standards; collaborate with the GRC and Compliance functions to ensure findings are tracked and remediated appropriately. Assess data flows and access permissions to identify over-privileged accounts and potential data exposure risks. Active Defense Validation & Testing Conduct targeted external penetration and security configuration tests to validate the strength of perimeter defenses; penetration testing tools are used primarily to validate vulnerability scan results rather than conduct full-scope red-team engagements. Replicate common threat actor techniques to identify and document exploitable paths within the infrastructure. Analysis & Prioritization Triage incoming vulnerability reports, threat intelligence feeds, and security testing findings. Analyze risks using severity metrics combined with internal business context to prioritize remediation efforts. Remediation Coordination Collaborate closely with IT, DevOps, and systems administrators to guide, track, and validate patching and configuration hardening efforts. Assist in organizing patch cycles and developing response plans for zero-day vulnerabilities. Reporting & Tracking Generate executive and technical dashboards tracking remediation progress, vulnerability aging, and team KPIs. Maintain up-to-date documentation on vulnerability standards, exception requests, and remediation playbooks.REQUIREMENTS
Education:
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; or an equivalent combination of education and professional experience.Experience:
Minimum two (2) to four (4) years of dedicated experience in cybersecurit y, with a strong focus on threat and vulnerability management. Hands-on experience with industry-standard vulnerability scanners (such as Tenable Nessus, Qualys, or Rapid7) and cloud security platforms. Direct experience performing security validation using standard penetration testing tools (such as Metasploit, OWASP ZAP, or Burp Suite) primarily to validate scan findings and confirm exploitability — not as a full-scope red-team practitioner. Familiarity with Data Security Posture Management (DSPM) platforms (such as LightBeam) and data loss prevention methodologies. Familiarity with risk frameworks (CVSS, MITRE ATT&CK, NIST, or OWASP). Exceptional communication skills with the ability to translate complex technical vulnerabilities and configuration issues into clear, actionable business risks for non-security teams.Desired Qualifications:
Proficiency with Python or PowerShell to automate reporting and scanning tasks. Experience managing vulnerabilities within containerized environments (Kubernetes/Docker) and cloud-native workloads. Exposure to Industrial Control Systems (ICS) or Operational Technology (OT) networks. Professional certifications such as CompTIA CySA+, PenTest+, CEH, or similar.Benefits:
401(k) 401(k) matching Dental insurance Employee assistance program Employee discount Flexible schedule Flexible spending account Health insurance Health savings account Paid time off Professional development assistance Referral program Tuition reimbursement Vision insuranceWork Location:
In personBenefits
- Paid Time Off (PTO)
- Financial Aid/Assistance
- Professional Development
- 401(k) Plans