yoinka

Vulnerability Management Analyst

Bain & Company

Mexico CityMidH-1B sponsor company
Sign in to applyVerified 3h ago
Location
Mexico City
Work model
On-Site
Level
Mid
H-1B history
27 approvals (FY2023)

About this role

Description & Requirements

WHAT MAKES US A GREAT PLACE TO WORK We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally. WHO YOU’LL WORK WITH You’ll join our Cyber Operations team within Bain’s Technology Services Group (TSG), working closely with IT, infrastructure, cloud, and engineering teams across a large and diverse global environment. WHERE YOU’LL FIT WITHIN THE TEAM As a Vulnerability Management Analyst, you’ll operate and drive the day-to-day maturity of our vulnerability and exposure management program across a large, diverse global environment spanning servers, endpoints, network devices, containers, and multi-cloud workloads. You’ll run our core tooling stack hands-on — Qualys Vulnerability Management, Detection and Response (VMDR) for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation. You’ll also lead a Continuous Threat Exposure Management (CTEM) program that turns findings from these tools into a single, risk-prioritized view of real exposure. Working closely with IT, infrastructure, cloud, and engineering teams, you’ll set remediation standards, drive accountability, guide junior analysts, and brief leadership on exposure and risk trends. Location and working model: Mexico City, Mexico. This role follows a hybrid working model and requires you to work from Bain’s Polanco office at least two days per week. WHAT YOU’LL DO Own and continuously mature the end-to-end vulnerability management lifecycle across the enterprise, including asset discovery, scanning, detection, validation, prioritization, remediation governance, rescanning, and closure verification. Operate and administer the core exposure tooling stack hands-on — Qualys VMDR for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation — including deployment, configuration, tuning, integration, and scanner, agent, and sensor health. Lead the Continuous Threat Exposure Management (CTEM) program, running the scoping, discovery, prioritization, validation, and mobilization cycles and correlating findings across host, cloud, and endpoint sources into a single de-duplicated, risk-ranked view of exposure. Prioritize vulnerabilities using the Common Vulnerability Scoring System (CVSS) combined with exploitability signals, including the Exploit Prediction Scoring System (EPSS) and CISA Known Exploited Vulnerabilities (KEV), threat intelligence, and asset and business criticality — focusing remediation on what is exploitable and material. Set and enforce remediation service-level agreements (SLAs) and drive accountability with IT, infrastructure, cloud, and engineering teams, translating findings into clear, actionable work and escalating aged or high-risk exposures. Partner with threat intelligence to correlate external threat activity with internal findings, translate emerging threats into targeted validation and remediation, and surface material risks for escalation. Define exception and risk-acceptance standards, review and adjudicate requests, and maintain defensible documentation to support audits, compliance, and leadership reporting. Build and automate dashboards, metrics, and executive reporting on exposure, scan coverage, vulnerability aging, and SLA adherence using native tool reporting, Excel, including pivot tables, and

Listing verified 3h ago. Applications go through the company's official careers site.

← Back to Yoinka

Vulnerability Management Analyst at Bain & Company, Mexico City | Yoinka