CallTek logo

Vulnerability Management/Compliance Analyst

Posted 27 days ago

RemotePhilippines

The Vulnerability Management / Compliance Analyst supports the Team by strengthening the recurring vulnerability management lifecycle. This assists with Qualys scan operations, vulnerability triage, ticket preparation, SLA tracking, exception register maintenance, and audit evidence organization. The role is operational and evidence-focused, intended to reduce workload from the Jr. Purple Teamer while maintaining strict supervision from the Team Manager.

Key Responsibilities:

Qualys Vulnerability Management Support:

  • Support recurring Qualys scanning cycles across approved BPO environments.
  • Validate scan completion, scan coverage, authentication status, agent status, and asset participation.
  • Identify missing, stale, duplicate, or inactive assets requiring cleanup or IT follow-up.
  • Export vulnerability data and prepare operational reports for review.

Vulnerability Triage and Prioritization Support:

  • Perform initial triage of vulnerabilities by severity, asset criticality, age, exploitability, and compliance relevance.
  • Identify obvious false positives, duplicate findings, superseded vulnerabilities, and stale detections.
  • Escalate critical and high-risk vulnerabilities for Manager or Jr. Analyst review.
  • Support prioritization of vulnerabilities affecting PCI, CDE, identity infrastructure, internet-facing systems, servers, workstations, and network devices.

Ticket Preparation and SLA Tracking:

  • Prepare remediation tickets with asset details, QID/CVE references, evidence, affected ports/services, remediation guidance, and due dates.
  • Track remediation SLAs for Critical, High, Medium, and compliance-relevant vulnerabilities.
  • Maintain weekly overdue vulnerability lists and escalation candidates.
  • Support follow-up with IT teams by providing clear technical context and evidence.

Agent Coverage and Scan Health Reporting:

  • Track Qualys agent coverage, inactive agents, non-reporting systems, unauthenticated scans, and scanning gaps.
  • Compare Qualys coverage against available asset inventories, EDR/Endpoint Management tools, CMDB data, or other approved sources. o Prepare coverage gap reports by BPO, site, account, asset type, and owner where data is available.

Exception Management and Risk Acceptance Support:

  • Maintain the vulnerability exception register with finding details, business owner, justification, expiration date, review date, and evidence.
  • Identify exceptions that are expired, missing justification, missing owner, or lacking compensating evidence.
  • Prepare exception documentation for Manager, GRC, and business owner review.
  • Do not approve exceptions or risk acceptance independently.

Compliance Evidence Management:

  • Organize evidence for ASV scans, internal authenticated vulnerability scans, pentest retests, segmentation tests, and remediation validation. o Maintain repository structure for PCI, ISO 27001, SOC2, and HIPAA evidence.
  • Ensure evidence packages include dates, scope, affected assets, results, remediation proof, and responsible parties
  • Support audit readiness by keeping evidence complete, traceable, and reviewable.


Operational Metrics and Reporting:

  • Prepare recurring metrics for vulnerability age, MTTR, closure rate, reopened vulnerabilities, overdue findings, patch coverage, and agent coverage.
  • Produce BPO-level vulnerability summaries for internal review.
  • Support executive reporting with validated data, but not own the final management narrative.

Process Improvement:

  • Document recurring pain points in the vulnerability management process.
  • Recommend improvements for ticketing, evidence handling, ownership tracking, SLA escalation, dashboarding, and scanner coverage.
  • Support the Team Manager and Jr. Analyst in standardizing the “Finding-to-Close” workflow.

Requirements

  • Bachelor's degree in Information Technology, Cybersecurity, or related field.
  • Experience with Qualys VMDR or equivalent vulnerability management platforms.
  • Strong understanding of CVE, CVSS, vulnerability lifecycle, remediation tracking, and false positive handling.
  • Working knowledge of Windows, Linux, servers, workstations, network devices, patching, and asset inventories.
  • Strong Excel, Power Query, Power BI, or dashboarding skills.
  • Familiarity with Jira, ServiceNow, or similar ticketing platforms.
  • Understanding of PCI DSS, ISO 27001, SOC2, HIPAA, and audit evidence expectations is preferred.
  • Preferred certifications: Security+, Qualys VMDR training, ISO 27001 Foundation, PCI awareness, or equivalent experience.
Job details
Workplace
Remote
Location
Philippines

For more than two decades, CallTek has been a global leader in delivering secure, compliant, and reliable white-label technical support services. As a Managed Service Provider (MSP), we offer 24/7 engineering, software development, field service, and customer support to technology operators and service providers worldwide. Our team of over 10,000 skilled professionals manages more than 20,000 buildings and one million enterprise network appliances globally. We are dedicated to security and privacy, adhering to the highest industry standards, including PCI-DSS, ISO 27001, SOC 2, and GDPR. This commitment ensures that our partners' data is protected, and their operations are compliant with global regulations. CallTek combine our expertise as an MSP with innovative technology. We’ve developed proprietary platforms such as Odyssey CX , powered by artificial intelligence (AI) and natural language processing (NLP), to provide advanced solutions that integrate seamlessly with your existing systems to provide you deep customer insights. Our dedication to excellence extends to our 24/7 Live Customer Support and Field Service teams, who are available across 35,000 zip codes, including certified low-voltage Ekahau technicians ready to resolve break-fix jobs and perform Wireless Site Surveys. Headquartered in Irvine, CA, CallTek has a global footprint with offices in nine countries, including the Dominican Republic, Colombia, Egypt, Guatemala, Honduras, India, Mexico, the Philippines, and the United States. Recognized for our unwavering commitment to security, privacy, and innovation, CallTek was named one of the Best Employers by The Philippine Daily Inquirer in 2023 and 2004. For more information on how CallTek can securely support your business with cutting-edge solutions, visit calltekinc.com.

Employees
518
Industry
IT Services and IT Consulting
Headquarters
Irvine, California
Founded
2004
Company location
4605 BARRANCA PKWY STE 101G, Irvine, California 92604, US

Key team members

Ahmed El Sayed

Ahmed El Sayed

Shirlene Shelley Zamora Tabernero

Shirlene Shelley Zamora Tabernero

Kevin Spruill CECP

Kevin Spruill CECP

Joshua Bergen CHAE, CHTP

Joshua Bergen CHAE, CHTP

Apply smarter with Jobr

Jobr aggregates jobs directly from company career portals — no middlemen. Our team applies on your behalf with AI-tailored resumes, reviewed by a human before submission.

Direct from company career pages
AI-personalised cover letters
Human review before every submit
Application tracking & follow-ups