Vulnerability Management Analyst
Real portfolio pieces built during the course, not a certificate for its own sake. Each one is work you can show.
- Remediation prioritiesA monthly scan of 4,212 findings turned into an order of work: each group ranked by exploitation, exposure and business importance rather than base score, with the action, owner and deadline for each.
- Risk exception recordAn exception a risk owner can sign: the finding, why it cannot be fixed yet, specific compensating controls, the residual risk, the honest effect on the Cyber Essentials renewal, who accepts it and when it expires.
- Exposure response recordThe first hours after a flaw is exploited with no patch: the real exposure including a device missing from the register, the mitigation applied, the compromise check, the suppliers' alternative route, and who was told.
- Monthly vulnerability reportA monthly report that shows whether real risk is falling: exploited exposed findings, the 14-day fix rate and the gap before the Cyber Essentials renewal, scan coverage and the devices unseen, and the open exception, with total findings demoted to context.
What you'll learn
Course content · 7 modules, 20 lessons
Sign up to unlock every lesson - the titles below show exactly what is inside.
What a vulnerability finding is, what the scores do and do not tell you, and the UK standard most small and mid-sized firms are held to.
Requirements
- No prior experience in this field is required to start.
- A computer with a reliable internet connection.
- Comfortable using a web browser - no software to install.
Description
Every CertClue course follows the same seven-part shape: fundamentals, the role translated out of job-posting language, a real working day, the job's recurring rhythms, a multi-day simulation, the portfolio you build along the way, and a handoff into your next move. Here is what that looks like for vulnerability management analyst.
Who this course is for
Anyone aiming to become a vulnerability management analyst, including career changers with no background in it yet. This is the entry rung of a realistic ladder:
Runs the scanning cycle, prioritises findings by exploitation and exposure, works with IT teams to get them fixed, verifies the fixes, and reports whether real risk is falling.
Designs the vulnerability management programme: coverage, service levels, exception governance and tooling, and leads analysts through it.
Owns how the organisation finds and fixes weaknesses across its estate, leads the teams that do it, and answers to the board for security risk.
Where it leads
This course prepares you for the CompTIA CySA+ role or credential path. Named for preparation only - no partnership or endorsement is implied.
No reviews yet. Reviews come from learners who have taken the course, so this stays empty until someone leaves one.
Sign in to leave a review.



