Full-Time

Security Data and Risk Analyst

Python, Data Analytics, Risk Quantification

Ivanti

Ivanti

1,001-5,000 employees

IT asset management and security solutions

No salary listed

Remote in USA

Remote

Category
Software Engineering
Data & Analytics
Required Skills
Fedramp
Python
R
Vulnerability Analysis
Go
Risk Management
Data Analysis
Requirements
  • 5+ years Security experience with 3 or more of the following security items: Cybersecurity Reporting Automation, Security/Information Risk Management, Threat Analysis, and/or Vulnerability Management.
  • 5+ years Data Analytics experience.
  • 4+ years’ experience with Python automation with multiple versions of Python.
  • 3+ years Dashboard building or data analytics experience.
  • Ability to wrangle data to produce presentations, metrics, dashboards, OKRs.
  • Ability to articulate themes from security-centric frameworks, privacy-centric frameworks and regulatory sources.
  • Experience with information application security, system security and product/solution security.
  • Ability to work with FedRAMP data without the need for immigration support.
Responsibilities
  • Develop automation for data gathering, analysis and presentation using Python or Go or R.
  • Articulate risk and risk management as realistic, measurable harm; Create dynamic dashboards and presentations
  • Lead the execution of multiple functions: Taking ownership of and creating awareness around security-relevant key performance and key risk indicators
  • Create dynamic dashboards and presentations; Generating insights and supporting information for decisions to be made including wrangling data from complex data sets and data sources
  • Coordinate, chair and present data to management, leadership and C-suite stakeholders in their languages.
  • Educate as well as inform audiences of a wide variety of security and risk expertise, including building libraries of material to support understanding of benefits and costs of security management.
Desired Qualifications
  • Experience with business intelligence, visualization, statistical extraction.

Ivanti provides IT asset management and security solutions for ITSM and IT operations, helping organizations manage devices, apps, and security across networks. Its Neurons platform unifies automation and security across cloud, on-premises, or hybrid deployments, while Ivanti Neurons for ITSM handles incidents, requests, and changes within workflows. The company differentiates itself by combining ITAM, ITSM, and security automation on one flexible platform, reducing IT complexity across multi-device environments. Its goal is to improve productivity and security in modern workplaces by simplifying operations and turning data into actionable guidance.

Company Size

1,001-5,000

Company Stage

Debt Financing

Total Funding

$390.6M

Headquarters

South Jordan, Utah

Founded

1985

Simplify Jobs

Simplify's Take

What believers are saying

  • Continuous Compliance addresses patch backlogs by enforcing out-of-band remediation automatically.
  • Sovereign Cloud MDM targets regulated buyers needing verifiability, auditability, and resilience.
  • APAC leadership under Jai Sahney supports partner expansion and enterprise SaaS growth.

What critics are saying

  • CVE-2026-9614 lets low-privilege users reach admin status in Neurons for ITSM.
  • EPMM faces repeated active exploitation, including CVE-2026-1281, CVE-2026-1340, and CVE-2026-6973.
  • Recurring severe vulnerabilities can push regulated buyers toward competing platforms and rebuilds.

What makes Ivanti unique

  • Ivanti combines ITSM, ITAM, UEM, and security in one Neurons platform.
  • Its April 2026 launch added autonomous patch compliance and agentic AI self-service.
  • Beyond Technology and Mindware extend Ivanti’s regional delivery across MEA and South Asia.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Ivanti who can refer or advise you

Benefits

Flexible Work Hours

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
PlanetJon
Jun 3rd, 2026
Critical privilege escalation vulnerability identified in Ivanti Neurons for ITSM.

Critical privilege escalation vulnerability identified in Ivanti Neurons for ITSM. June 3, 2026 Ivanti has issued an urgent security advisory regarding a high-severity vulnerability discovered within its Neurons for ITSM platform. This flaw provides a direct pathway for authenticated users to bypass established security boundaries, effectively escalating their permissions to full administrative status. Identified as CVE-2026-9614, the vulnerability is categorized under CWE-284: Improper Access Control. With a significant CVSS score of 8.8, the flaw represents a substantial risk to both cloud-hosted and on-premises environments, as it targets the very platform enterprises rely on to manage their IT infrastructure and service workflows. Technical analysis: the mechanics of the bypass. At its core, the vulnerability is rooted in an architectural weakness where the application fails to perform rigorous authorization checks during specific high-privilege requests. This breakdown in the logic of Role-Based Access Control (RBAC) allows a user with minimal, low-privileged credentials to execute commands or access data intended strictly for system administrators. The technical profile of the attack is particularly concerning. Analyzing the CVSS:3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), PlanetJon can see that the exploit requires low complexity (AC:L) and zero user interaction (UI:N). This means a malicious actor - or even a compromised internal account - can move from a standard user role to a "super-user" role autonomously, without needing to trick an administrator via phishing or social engineering. The potential impact of a successful breach is profound. An attacker gaining administrative control could: * Exfiltrate sensitive enterprise configuration data and intellectual property. * Manipulate critical IT workflows and service tickets to mask malicious activity. * Leverage the ITSM platform as a beachhead to move laterally through the wider enterprise network. Remediation and patching roadmap. According to the official Ivanti security advisory, the vulnerability impacts on-premises versions 2025.4 and earlier, as well as cloud-based versions 2026.1 and prior. For On-Premises Administrators: Immediate action is required. Ivanti has released targeted patches to close this loophole. Organizations should upgrade to one of the following versions immediately: * 2025.4 Patch 1 * 2025.3 Patch 1 * 2025.2 Patch 1 For Cloud Customers: The remediation process is handled via Ivanti's managed service updates. The fix was rolled out across versions 2026.1 Patch 9 and 2026.2 Patch 1 between May 24 and May 25, 2026. Cloud users should verify their current version to ensure they are running the updated build. Defense-in-Depth recommendations. While Ivanti reports no evidence of active exploitation in the wild at this time, the ease of exploitation makes this a high-priority target for threat actors looking to establish persistence within a network. To bolster your security posture, PlanetJon recommend the following defensive layers: * Immediate Patching: Prioritize the deployment of the aforementioned patches for all on-premises instances. * Access Restriction: Implement strict network segmentation and limit access to the ITSM interface to authorized segments or via secure VPN/Zero Trust gateways. * Log Auditing: Conduct a retrospective audit of system logs, specifically looking for unusual privilege changes or administrative actions performed by non-admin accounts. * Principle of Least Privilege: Regularly review user roles and permissions to ensure no accounts possess more access than is strictly necessary for their function. In the modern threat landscape, IT management tools are high-value targets. Maintaining the integrity of these platforms through proactive patching and continuous monitoring is not just a maintenance task - it is a critical component of enterprise defense.

PR Newswire
Apr 1st, 2026
Ivanti appoints Jai Sahney as senior vice president for Asia Pacific & Japan

Ivanti, a global enterprise IT and security software company, has appointed Jai Sahney as Senior Vice President for Asia Pacific and Japan. Sahney will focus on accelerating growth across the region, strengthening customer and partner engagement, and building a high-performance team aligned with Ivanti's strategy. Sahney brings nearly 30 years of experience in enterprise software and SaaS, most recently leading APAC business at Omnissa. He previously held senior positions at VMware, Dell Technologies and Cisco Systems, where he led SaaS transitions and built partner ecosystems whilst delivering regional growth. The appointment reinforces Ivanti's commitment to the APJ region as customers work to unify IT and security operations and move from AI experimentation to measurable outcomes.

SecurityWeek
Mar 11th, 2026
Fortinet, Ivanti, Intel Patch High-Severity Vulnerabilities

Fortinet, Ivanti, Intel patch high-severity vulnerabilities. The bugs could lead to arbitrary code execution, privilege escalation, or authentication rate-limit bypass. | March 11, 2026 (8:10 AM ET) Fortinet, Ivanti, and Intel on Tuesday rolled out security fixes for dozens of vulnerabilities, including high-severity bugs that could be exploited for arbitrary code execution, privilege escalation, or security protection bypasses. Fortinet announced patches for 22 security defects across its products, including high-severity flaws in FortiWeb, FortiSwitchAXFixed, FortiManager, and FortiClientLinux. The FortiWeb, FortiSwitchAXFixed, and FortiManager issues could be exploited by remote, unauthenticated attackers to bypass the authentication rate limit or execute unauthorized code or commands. The FortiClientLinux weakness, described as a Symlink following vulnerability, could allow local attackers to escalate their privileges to root. On Tuesday, Fortinet also addressed medium- and low-severity flaws that could lead to data tampering, security protection bypasses, arbitrary code execution, information disclosure, denial-of-service (DoS), arbitrary command execution, privilege escalation, or social engineering attacks. Fortinet made no mention of any of these vulnerabilities being exploited in the wild. Ivanti rolled out fixes for a high-severity security defect in Desktop and Server Management (DSM) before version 2026.1.1 that could allow attackers to elevate their privileges, noting that it is not aware of the flaw being exploited. Intel published an advisory describing nine vulnerabilities in the UEFI for some Intel reference platforms, including five high-severity bugs that could lead to local code execution, privilege escalation, and information disclosure. UEFI firmware updates were released for over 45 Intel processor models affected by these security defects. None of these appears to have been exploited in the wild. Ionut Arghire is an international correspondent for SecurityWeek.

Cryptika Cybersecurity
Jan 30th, 2026
Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks

Critical Ivanti Endpoint Manager 0-day RCE vulnerabilities actively exploited in attacks. Two critical code-injection vulnerabilities have been disclosed in the Endpoint Manager Mobile (EPMM) platform, which are currently being actively exploited in real-world attacks. The security flaws, tracked as CVE-2026-1281 and CVE-2026-1340, allow unauthenticated attackers to execute arbitrary code remotely on vulnerable systems. The vulnerabilities carry a maximum CVSS severity score of 9.8 and affect multiple versions of EPMM, including 12.5.0.0, 12.6.0.0, and 12.7.0.0. According to Ivanti's security advisory published on January 29, 2026, the company is aware of a limited number of customer environments that have already been compromised at the time of disclosure. Active exploitation confirmed. Both vulnerabilities stem from code-injection weaknesses (CWE-94) that can be exploited without authentication or user interaction. The attack vector is network-based and low-complexity, enabling threat actors to compromise vulnerable EPMM instances remotely with minimal effort. Successful exploitation grants attackers complete control over the confidentiality, integrity, and availability of affected systems. Ivanti has released version-specific RPM patches to address the security flaws. At the same time, customers await the permanent fix scheduled for version 12.8.0.0 in Q1 2026. The temporary patches require no system downtime and do not impact feature functionality. However, administrators must reapply the RPM script after version upgrades. Organizations running EPMM should immediately apply the version-specific RPM patches available through Ivanti's support portal. Customers using versions 12.5.0.x through 12.7.0.x require RPM 12.x.0.x, while those on 12.5.1.0 or 12.6.1.0 should deploy RPM 12.x.1.x. The company emphasizes that only one patch is needed based on the deployed version. Ivanti recommends security-conscious organizations consider rebuilding EPMM environments and migrating data to replacement systems as the most conservative remediation approach. The company has provided technical analysis documentation with forensic guidance, though reliable indicators of compromise remain unavailable as investigations continue. Notably, other Ivanti products including Endpoint Manager (EPM), Neurons for MDM, and Sentry appliances are not affected by these vulnerabilities. Follow Cryptika on Google News, LinkedIn, and X for daily cybersecurity updates. Contact Cryptika to feature your stories. The post critical Ivanti Endpoint Manager 0-day RCE vulnerabilities actively exploited in attacks appeared first on cyber security News. Ivanti MobileIron API Access Flaw let Attackers Access Sensitive InformationAugust 3, 2023In "Cybersecurity News - Original News Source is cybersecuritynews.com"

PR Newswire
Jan 27th, 2026
Ivanti launches agentic AI and autonomous endpoint management to transform enterprise IT operations

Ivanti, a global enterprise IT and security software company, has unveiled AI-driven enhancements to its Neurons platform, introducing agentic AI capabilities, autonomous endpoint management and advanced asset visibility features. The updates include persona-based AI agents for IT service management that provide autonomous, goal-directed support through natural language interaction. The agentic AI customer preview launches in Q1 2026, with general availability later in the year. Ivanti's Autonomous Endpoint Management combines digital employee experience, unified endpoint management and security, using AI-powered automation to manage and protect devices. The company has also enhanced asset visibility through Ivanti Neurons for Discovery, offering comprehensive asset intelligence with embedded licence management and unified risk insights. Over 34,000 customers, including 85 Fortune 100 companies, use Ivanti's solutions.