Vulnerability/Threat Management Analyst

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Atlanta, GA, USA
In-Office or Remote
95K-130K Annually
Entry level
Marketing Tech • Software • Travel • Hospitality
The Role
Own the vulnerability management pipeline for a cloud-based hospitality SaaS platform. Responsibilities include maintaining Tenable and CrowdStrike Falcon scan coverage, prioritizing and validating vulnerabilities, automating scan-to-ticket workflows with Python and Jira, coordinating remediation, tracking SLAs, reporting program health, and participating in security incident response on-call rotation.
Summary Generated by Built In
Company Overview

Revinate is the hotel data activation platform for hotels, groups, resorts, and enterprise brands.

Every hotel has that guest: years of stays, the same room, never skips the spa. But their story sits scattered across the PMS, the booking engine, the spa system, and whoever happened to be on shift. Revinate brings that story together. We connect and clean guest data from every system into Rich Guest Profile® data, then put it to work for the people who look after guests.

Reservations answers the phone already knowing the guest. Marketing sends the spa offer to the guest who raved about the spa. Behind it all, Ivy, our AI intelligence layer trained on 17 years of hospitality data, reads the patterns and handles the digital labor.

Revinate powers 1.1 billion Rich Guest Profile® data points across 12,500+ hotels, driving over $24 billion in direct revenue.

Get Revinate. Get superpowers.

 
Revinate is proud to be a Great Place To Work Certified company! Check out what our employees say makes working here so great: Great Places To Work x Revinate
 
This is a remote position, and candidates must reside in the Greater Atlanta area. 
 
 
Role Overview

Revinate's security program is lean, built from the ground up, and growing, and we're looking for a Vulnerability Management Analyst to take ownership of one of its most important engines. Reporting directly to our Director of Security and based in Atlanta, you'll become the second dedicated member of the security team and the owner of our vulnerability management pipeline, from scan to ticket to fix. 

Your work will directly shrink the attack surface of a cloud-based hospitality SaaS platform trusted by more than 12,500 hotels. This is a defensive role at its core: you'll use offensive know-how to confirm whether findings are truly exploitable, but your success will be measured by complete scan coverage, clean prioritization, and vulnerabilities that actually get fixed. If you love building automation that turns noise into action, you'll have no shortage of meaningful work here.

Top Three Outcomes for Year One
  • Own the pipeline. Take full ownership of the vulnerability management pipeline already in place, with Tenable and CrowdStrike Falcon scan coverage across our cloud assets and no blind spots in the asset inventory.

  • Automate from finding to ticket. Build out Python automation that turns scan results into risk-prioritized, validated tickets, so remediation teams only see findings that truly matter and our existing backlog shrinks measurably.

  • Make the program measurable. Help define our vulnerability management standards and remediation SLAs, and deliver reporting that shows leadership exactly how the program is performing: coverage, time to remediate, SLA compliance, and risk trends.

What You'll Do

  • Run continuous vulnerability scanning in Tenable and Crowdstrike Falcon to make sure every asset across our public cloud environment is inventoried, covered, and assessed.

  • Prioritize findings by real-world risk, using exploitability, threat intelligence, and asset context rather than CVSS severity scores alone, so we never send teams chasing vulnerabilities that can't actually be exploited.

  • Validate high-priority findings hands-on, whether by spinning up a test virtual machine in our cloud VPC or using AI-assisted tooling to confirm exploitability in our test environments.

  • Automate the path from finding to ticket with existing tools, push validated fixes through remediation teams via our ticketing workflow (Jira), and follow up to make sure SLAs are met.

  • Help define vulnerability management standards and report on program health, and participate in the mandatory on-call rotation for security incident response alongside the Director of Security and our AI-driven SOC alert analyst.

What You'll Bring

  • Hands-on, real-world experience running vulnerability management in a business environment, ideally with Tenable (experience with Qualys, Rapid7 InsightVM, or Kenna also translates).
  • Experience working in public cloud environments (AWS, Azure, or GCP), including the ability to stand up test infrastructure to validate findings.

  • Strong scripting skills for automating scan-to-ticket workflows (Python is a plus).

  • A working knowledge of offensive security techniques, at the level of PenTest+ or OSCP, sufficient to confirm whether a finding is genuinely exploitable.

  • Experience with remediation ticketing workflows (Jira) and endpoint security tooling; hands-on time with CrowdStrike Falcon Complete will make you stand out.

  • Certifications such as CompTIA CySA+ or GIAC GEVA (most valued), or Security+, GSEC, PenTest+, OSCP, or SSCP. Certifications are a plus, not a requirement, and no degree is required. Proven hands-on experience matters most to us.

  • A background in security compliance, security operations, or application security. On a lean team, the ability to wear more than one hat goes a long way.

People Describe You As

  • A self-starter. Hand you the documentation for a pipeline someone else built, and you'll read it, ask the right questions, and then run with it without needing step-by-step direction.

  • Someone who closes the loop. Finding the vulnerability is only half the job for you. You get real satisfaction from seeing the fix shipped and the dashboard trend in the right direction.

  • An automator at heart. When you see the same manual task twice, you're already writing the script so no one has to do it a third time.

  • Calm and dependable under pressure. When the on-call page comes in, you stay focused, triage methodically, and communicate clearly.

  • A pragmatic partner. You can explain to an engineering team why one fix matters now and another can wait, and they trust your judgment because your tickets are always worth their time.

Skills Required

  • Hands-on experience running vulnerability management in a business environment
  • Experience with Tenable or comparable tools such as Qualys, Rapid7 InsightVM, or Kenna
  • Experience working in public cloud environments, including AWS, Azure, or GCP
  • Ability to stand up test cloud infrastructure to validate vulnerability findings
  • Strong scripting skills for scan-to-ticket workflow automation; Python preferred
  • Working knowledge of offensive security techniques comparable to PenTest+ or OSCP
  • Experience with Jira remediation ticketing workflows
  • Experience with endpoint security tooling
  • Background in security compliance, security operations, or application security
  • CompTIA CySA+ or GIAC GEVA certification
  • Security+, GSEC, PenTest+, OSCP, or SSCP certification
  • CrowdStrike Falcon Complete experience
  • College degree

Revinate Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Revinate and has not been reviewed or approved by Revinate.

  • Healthcare Strength — Health coverage includes medical, dental, and vision with full employee premium coverage in the U.S., alongside mental-health resources. This breadth of coverage is described as a standout element of the package.
  • Retirement Support — Retirement programs include a 401(k) match in the U.S. and pension or CPF equivalents in other regions. This support contributes meaningfully to long-term rewards.
  • Wellbeing & Lifestyle Benefits — Work-life practices include generous PTO or flex time, a remote-first setup with no-meeting Fridays, a monthly WFH stipend, and a 4.5-day workweek on many teams. These elements enhance day-to-day flexibility and balance.

Revinate Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Mateo, CA
225 Employees
Year Founded: 2009

What We Do

Revinators are everywhere, pursuing their passions, laughing, caring, arguing too, at times. It is hard to forget a Revinator when you have met one. Mountain bikers, surfers, sunflower plant nurturers, golfers in California, Oregon, London, Singapore, Amsterdam, Bali. What ties us together then? Energy. And a determination that we can transform the hospitality industry - beyond what we have already done. We don’t just believe that, we have demonstrated that already. Come in, look closer and you will see what we mean. We are here to show hoteliers that when they access the data they own and leverage it to drive deeper connections with their guests, they are going to drive direct revenue in spades. We have the skill to wield the technology to deliver results. Want to understand that better? See what’s cooking under the hood? Or maybe you need a slice of our energy? Connect with us. We are looking for more Revinators to join us. Want more details right here, right now? Here are some numbers then. --> 480. The number of people around the world who will answer “Yes!” if you asked, “Any Revinators here?” --> 4. We have global offices in California, Oregon, Amsterdam and Singapore. And we support people working remotely. --> $100M. We are going to walk past that annual revenue figure soon. Watch us (or join us maybe). And we are profitable too. We’d tell you about all the awards we won but we lost count. Awards like 4 X Top Place to Work. 4 x #1 CRM/Marketing product from Hotel Tech Report.

Gallery

Gallery

Similar Jobs

In-Office or Remote
Atlanta, GA, USA
206 Employees
95K-130K Annually

Enverus Logo Enverus

Senior Analyst, Cost Optimization Services - 26389

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
7 Locations
1800 Employees
110K-150K Annually

MetLife Logo MetLife

Consultant

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
100K-130K Annually

BlackLine Logo BlackLine

Pricing Advisory Manager

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Remote or Hybrid
USA
1810 Employees
124K-155K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account