The Roles · Who defends it
Vulnerability analyst
Written from published sources
The analyst who looks for the weaknesses before an adversary does. The national framework describes the work as assessing systems and networks to identify deviations from acceptable configurations, and measuring how well a defence-in-depth architecture holds against known vulnerabilities. The output is a prioritised account of exposure, which somebody else then has to act on.
Who it receives from
- Asset management
- The inventory, at whatever accuracy the organisation maintains.
- Threat intelligence
- Which weaknesses are being used, which changes what matters first.
- Vendors
- Advisories, fixed releases and the details that make a finding actionable.
Who it serves
- The teams who own the systems
- A short, ordered list they can act on.
- Security leadership
- Exposure expressed as a trend rather than a snapshot.
- Audit and compliance
- Evidence that assessment happens and that findings close.
What the job turns on
The report is easy to produce and the remediation belongs to somebody else, which makes influence the actual skill. An analyst who arrives with two hundred findings ordered by scanner severity hands over a document; one who arrives with the six that are reachable from the internet, with the fixed version named and the window suggested, hands over a plan. The second gets fixed, and the difference is entirely in the preparation.