Logo for Revinate

Vulnerability/Threat Management Analyst

Role overview

Qualifications

  • Hands-on experience running vulnerability management in a business environment, ideally with Tenable.
  • Experience working in public cloud environments (AWS, Azure, or GCP).
  • Strong scripting skills for automating scan-to-ticket workflows (Python is a plus).
  • A working knowledge of offensive security techniques at the level of PenTest+ or OSCP.

Responsibilities

  • Run continuous vulnerability scanning in Tenable and Crowdstrike Falcon.
  • Prioritize findings by real-world risk using exploitability and threat intelligence.
  • Validate high-priority findings hands-on.
  • Automate the path from finding to ticket and push validated fixes through the remediation teams.

Key facts

Hard skills

Other skills

  • Security Policies
  • Problem Solving
  • Communication
  • Teamwork

About the company

Revinate logo

Revinate

Computer Software / SaaS

True to the industry we serve, we love to travel, work hard, help others, and make the most of every day. We’re a global team of mountain bikers, surfers, parents, golfers, Star Wars fans, hikers, chefs, and football fans (both kinds!) who are connected by a #OneRevinate spirit. You might find us in California, Oregon, London, Singapore, Amsterdam, or Barcelona — or wherever the world takes us — working across time zones and countries to delight our customers as they delight their guests. Life on the inside is fast, fun, contemplative, energizing — a few of the words Revinators have used to describe the environment here. Come in and take a closer look at the our culture and how it unfolds! Pub quizzes, 3rd Thursday meet-ups, culture club, Olympics at the park, cookouts — there is a lot happening. Come in, take a look, and you will see us laughing, caring, arguing, too, at times. It’s hard to forget a Revinator when you have met one! What’s your passion? We’d love to bring it to our team. Want more details? Here are some numbers: —> 480 Revinators worldwide. —> 4 international offices, located in California, Oregon, Amsterdam, and Singapore. And we support people working remotely as well. —> 12,000 worldwide implementations. We’d tell you about all the awards we won but we lost count. Awards like 4x Top Place to Work and 4x #1 CRM/Marketing product from HotelTechReport.

Company details

Company typeSME
IndustryComputer Software / SaaS
Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Company Overview

Revinate is the hotel data activation platform for hotels, groups, resorts, and enterprise brands.

Every hotel has that guest: years of stays, the same room, never skips the spa. But their story sits scattered across the PMS, the booking engine, the spa system, and whoever happened to be on shift. Revinate brings that story together. We connect and clean guest data from every system into Rich Guest Profile® data, then put it to work for the people who look after guests.

Reservations answers the phone already knowing the guest. Marketing sends the spa offer to the guest who raved about the spa. Behind it all, Ivy, our AI intelligence layer trained on 17 years of hospitality data, reads the patterns and handles the digital labor.

Revinate powers 1.1 billion Rich Guest Profile® data points across 12,500+ hotels, driving over $24 billion in direct revenue.

Get Revinate. Get superpowers.

  Revinate is proud to be a Great Place To Work Certified company! Check out what our employees say makes working here so great: Great Places To Work x Revinate   This is a remote position, and candidates must reside in the Greater Atlanta area.     

Role Overview

Revinate's security program is lean, built from the ground up, and growing, and we're looking for a Vulnerability Management Analyst to take ownership of one of its most important engines. Reporting directly to our Director of Security and based in Atlanta, you'll become the second dedicated member of the security team and the owner of our vulnerability management pipeline, from scan to ticket to fix. 

Your work will directly shrink the attack surface of a cloud-based hospitality SaaS platform trusted by more than 12,500 hotels. This is a defensive role at its core: you'll use offensive know-how to confirm whether findings are truly exploitable, but your success will be measured by complete scan coverage, clean prioritization, and vulnerabilities that actually get fixed. If you love building automation that turns noise into action, you'll have no shortage of meaningful work here.

Top Three Outcomes for Year One

  • Own the pipeline. Take full ownership of the vulnerability management pipeline already in place, with Tenable and CrowdStrike Falcon scan coverage across our cloud assets and no blind spots in the asset inventory.

  • Automate from finding to ticket. Build out Python automation that turns scan results into risk-prioritized, validated tickets, so remediation teams only see findings that truly matter and our existing backlog shrinks measurably.

  • Make the program measurable. Help define our vulnerability management standards and remediation SLAs, and deliver reporting that shows leadership exactly how the program is performing: coverage, time to remediate, SLA compliance, and risk trends.


What You'll Do
  • Run continuous vulnerability scanning in Tenable and Crowdstrike Falcon to make sure every asset across our public cloud environment is inventoried, covered, and assessed.

  • Prioritize findings by real-world risk, using exploitability, threat intelligence, and asset context rather than CVSS severity scores alone, so we never send teams chasing vulnerabilities that can't actually be exploited.

  • Validate high-priority findings hands-on, whether by spinning up a test virtual machine in our cloud VPC or using AI-assisted tooling to confirm exploitability in our test environments.

  • Automate the path from finding to ticket with existing tools, push validated fixes through remediation teams via our ticketing workflow (Jira), and follow up to make sure SLAs are met.

  • Help define vulnerability management standards and report on program health, and participate in the mandatory on-call rotation for security incident response alongside the Director of Security and our AI-driven SOC alert analyst.


  • What You'll Bring
  • Hands-on, real-world experience running vulnerability management in a business environment, ideally with Tenable (experience with Qualys, Rapid7 InsightVM, or Kenna also translates).
  • Experience working in public cloud environments (AWS, Azure, or GCP), including the ability to stand up test infrastructure to validate findings.

  • Strong scripting skills for automating scan-to-ticket workflows (Python is a plus).

  • A working knowledge of offensive security techniques, at the level of PenTest+ or OSCP, sufficient to confirm whether a finding is genuinely exploitable.

  • Experience with remediation ticketing workflows (Jira) and endpoint security tooling; hands-on time with CrowdStrike Falcon Complete will make you stand out.

  • Certifications such as CompTIA CySA+ or GIAC GEVA (most valued), or Security+, GSEC, PenTest+, OSCP, or SSCP. Certifications are a plus, not a requirement, and no degree is required. Proven hands-on experience matters most to us.

  • A background in security compliance, security operations, or application security. On a lean team, the ability to wear more than one hat goes a long way.


  • People Describe You As
  • A self-starter. Hand you the documentation for a pipeline someone else built, and you'll read it, ask the right questions, and then run with it without needing step-by-step direction.

  • Someone who closes the loop. Finding the vulnerability is only half the job for you. You get real satisfaction from seeing the fix shipped and the dashboard trend in the right direction.

  • An automator at heart. When you see the same manual task twice, you're already writing the script so no one has to do it a third time.

  • Calm and dependable under pressure. When the on-call page comes in, you stay focused, triage methodically, and communicate clearly.

  • A pragmatic partner. You can explain to an engineering team why one fix matters now and another can wait, and they trust your judgment because your tickets are always worth their time.

  • Interview Process  We're excited you're considering a career with Revinate! Our goal is to ensure this is the right opportunity for you, while also determining if you're the right fit for our team. The interview process for this role is designed to be a two-way street, where you'll get to know us just as we get to know you.   - Recruiter Screen - 30 min Google Meet  - Hiring Manager Interview - 45 min Google Meet - Video - Cross Collaboration - 30 min Google Meet - Video        Revinate values the flexibility of a hybrid workforce and the benefits of localized hiring. We focus on specific cities to foster local communities and enhance team cohesion, allowing employees to collaborate, attend local events, and build a strong sense of community and company culture. Candidates must be located in the country location listed in the job application. Thank you!   Revinate is not open to third party solicitation or resumes for our posted FTE positions. Resumes received from third party agencies that are unsolicited will be considered complementary.   Important Security Alert We have been made aware of fraudulent activities involving individuals impersonating our HR team and offering fake job opportunities. Please be vigilant and ensure your safety by verifying all job offers.   For Authentic Opportunities: Only refer to our official careers page on our company website. Your security is our priority. If you encounter any suspicious activity, please report it immediately. Stay safe and secure! You can confirm or inquire with any questions by reaching out to recruiting@revinate.com       AI and Hiring  Please note that interviews at Revinate will be recorded using brighthire.ai. As we continue to build more structure into our interview processes -- the best way to eliminate unconscious bias! We are encouraging our interviewers to focus more on our candidates and the conversation than taking notes. Instead, we can rely on brighthire.ai to do the note taking for us. If you’re uncomfortable with recording your interview, please let us now. We’ll opt you out.      #LI-Remote #LI-AE1

    Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    ·

    Vulnerability Management Analyst Related jobs

    Other jobs at Revinate

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.