Fortress is building a pipeline of qualified candidates for an upcoming Cyber Operator opening. While this role is not immediately open, we expect to fill it soon and want to connect with strong candidates now so we can move quickly when it does. Thank you for your understanding! Cyber Operator Location: Remote Compensation: $55,271- $75,369 per year, depending on experience and qualifications. Employment Type: Full-Time What you can expect as the Cyber Operator at Fortress... The Cyber Operator supports the day-to-day execution of vulnerability management workflows for a major client engagement, contributing across the full lifecycle of vulnerability monitoring, triage, remediation coordination, validation, and operational communications. This role partners with senior analysts and client stakeholders to identify emerging vulnerabilities, coordinate remediation activity, maintain accurate records within the vulnerability management platform, and translate technical activity into clear, audit-ready written deliverables for both technical and leadership audiences. It is a compelling opportunity for someone looking to build foundational expertise in vulnerability management and cybersecurity operations while developing the technical judgment, operational discipline, and communication skills needed to take on greater responsibility over time. Responsibilities Include Independently execute the day-to-day workflows of an assigned area of the vulnerability management program — finding validation, applicability analysis, remediation packaging and coordination, remediation validation, risk-acceptance governance, critical-vulnerability escalation, or asset and inventory integrity — in alignment with established procedures, SLAs, and program standards. Monitor scanning output, vendor advisories, threat feeds, and open-source intelligence to identify applicable and emerging vulnerabilities, escalating higher-severity or ambiguous findings to senior analysts and leads for prioritization. Validate findings for applicability against advisories, product versions, and asset context; document valid, not-valid, or needs-research determinations with reviewer, date, and audit-sufficient evidence. Package validated findings into business-unit summary reports and remediation action plans with named owners, due dates, and approval routing; onboard newly added systems and assess their findings. Create and manage remediation tickets in enterprise ITSM platforms, identifying asset ownership from configuration management data; run the follow-up and escalation cadence, log status, and coordinate with business-unit owners through to confirmed closure. Validate remediation using credentialed re-scans or business-unit-provided evidence, compare against required patch or configuration state, update product versions, and assemble closure evidence in approved, audit-ready repositories. Support risk-acceptance and exception intake: screen requests for eligibility, issue and process business-unit questionnaires, route by risk tier, and maintain the record through extension and closure. Support critical and emerging-vulnerability escalation: participate in coordinated response sessions, track escalated remediation asset-by-asset, and capture owners, action items, and decisions. Maintain accurate records across the platform and supporting systems, and perform routine data-quality reviews, flagging inconsistencies for resolution. Own recurring reporting deliverables — remediation tracker updates, business-unit communications, validation and response readouts, monthly leadership reports, and executive-facing presentations — within expected turnaround, including same-business-day delivery for high-severity events. Exercise editorial judgment when refining operational communications for clarity, tone, and audience, escalating substantive technical-content changes for senior review. Use approved AI-assisted tools for research, drafting, summarization, and documentation with human review of all outputs. Build proficiency across program workflows and tooling, and support additional operational activities and projects as assigned. Other duties as assigned. Minimum Qualifications 1–3 years of experience in cybersecurity, vulnerability management, IT operations, SOC operations, technical writing, communications, program support, or a related field; relevant internship experience, coursework, or completion of a cybersecurity boot camp will be considered. Working familiarity with cybersecurity concepts including vulnerabilities, patching, CVEs, CVSS scoring, and risk fundamentals; formal training or self-study accepted. Strong written and verbal communication skills, including the ability to produce clear, organized, audience-calibrated written deliverables and audit-ready documentation Proficiency with Microsoft Office tools including Word, Excel, PowerPoint, Outlook, and SharePoint. Strong organizational habits with attention to detail and reliable follow-through Ability to manage multiple ongoing workstreams and meet deadlines in a structured, fast-paced operational environment. Comfort working collaboratively with both technical and non-technical colleagues, with the willingness to learn new tools, platforms, and workflows and apply them consistently. Ability to leverage AI tools and independently use and refine prompts to enhance the quality, efficiency, and insight of regular work processes. Preferred Skills Hands-on or coursework exposure to enterprise vulnerability scanning platforms (Tenable, Qualys, Rapid7, or similar) and enterprise ITSM or ticketing platforms (ServiceNow, Jira, or similar). Experience producing structured written deliverables, executive-facing presentations, or operational reports on a recurring schedule, including work alongside technical teams in a support, coordination, or communications capacity. Familiarity with SharePoint, Confluence, or similar collaboration and documentation platforms, and with Power BI, Tableau, or similar reporting and dashboard tools. Exposure to regulated industries such as utilities, energy, defense, healthcare, or financial services, including NERC-CIP environments. Cybersecurity-related certifications (CompTIA Security+, Network+, CySA+, or equivalent). Familiarity with prioritizing findings by more than base severity score — asset criticality, exposure, and compensating controls. Exposure to evidence handling for regulatory audit (NERC CIP, BCSI), including timestamped artifacts, non-editable formats, and controlled storage locations. Education Associate’s degree or equivalent professional work experience required. Bachelor's degree preferred. Employee Benefits: Competitive pay structure Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families Company paid life, short- and long-term disability insurance Employee Assistance Program 401(k) match Flexible Paid Time Off Parental Leave Employment Perks: We provide each employee with professional growth opportunities through succession planning, up-skilling, and certifications Tuition and certification reimbursement Employee Referral Programs Company Sponsored Events Fortress is proud to be an Equal Opportunity Employer. All employees and applicants will receive consideration for employment without regard to age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. Fortress Information Security takes part in the E-Verify process for all new hires. For positions located in the US, the following conditions apply. If you are made a conditional offer of employment, you will have to undergo a drug test. ADA Disclaimer: In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis.
Senior Cyber Operator
Fortressinfosec
Director Regional Development
Saint Mary
Technology Installer | Network Solutions
CBIZ
Manager, Engineering - Quality
ICU Med
Field Engineer Fire Equipment
UL Solutions
Real Estate Architect
UL Solutions