Ross Stores

Business Analyst

Ross Stores Dublin, California, United States · $85K–$136K/yr

Retail · 10,001+ employees

Jul 01
business-analyst Mid (2-5 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The IT Business Analyst will validate, prioritize, and drive the remediation of security vulnerabilities across the enterprise environment. They are responsible for optimizing patch management processes, developing standard operating procedures, and ensuring compliance with regulatory frameworks.

What they look for

Vulnerability remediation Security operations Linux operating systems Java vulnerability remediation Patch management Risk assessment Compliance monitoring Data analysis Reporting Communication Process optimization Audit support Technical documentation Problem solving Collaboration

Requirements

Candidates must have an undergraduate degree or equivalent experience and 3-5 years of experience in vulnerability remediation or security operations. Proficiency in Linux systems and strong analytical and communication skills are required for this role.

Full description

GENERAL PURPOSE: The IT Business Analyst (Vulnerability Remediation) helps protect our enterprise by validating, prioritizing, and driving remediation of security vulnerabilities across our environment – including Corporate HQ, stores, distribution centers, and supply chain systems. You will partner with Infrastructure and Application teams to reduce risk at scale, improve patch compliance, and ensure adherence to regulatory/industry frameworks (e.g., PCI-DSS, SOX).

This is a hands-on role focused on scan analysis, false-positive triage, remediation orchestration, and metrics. Ideal candidates are data-driven, comfortable with large enterprise environments, and proactive in turning findings into action.

Analysis includes security, system, and business impact at times. In security impact, the candidate must have a good understanding of the security implications of a patch although not a security SME. In system impact, the candidate must analyze and foresee the side effects of the patch.

This position, therefore, requires soft skills, such working as a team, verbal and written communications, understanding business issues, customer focus and listening to constructive feedback. One of the most important qualities is to optimize existing (patch) processes. The candidate must possess an innovative mindset.

The base salary range for this role is $84,700 – $136,150. The base salary range is dependent on factors including, but not limited to, experience, skills, qualifications, relevant education, certifications, seniority, and location. The range listed is just one component of the total compensation package for employees. Other rewards vary by position and location.

ESSENTIAL FUNCTIONS:

  • Assess drift scan results, primarily Linux, and document and test recommended

solutions.

  • Assist in developing and documenting remediation solution action plans.
  • Develop and optimize pre- and post- remediation standard operation procedures to

ensure proper implementation without any outages

  • Influence innovative opportunities intended to improve the patch management program

at Ross.

  • Support internal and external audit and assessment evidence supporting the vulnerability

remediation program.

  • Contribute to the continuous improvement of existing and development of new

operational dashboards.

  • Track remediation progress against established compliance timelines and communicate

remediation compliance metrics.

COMPETENCIES: People

  • Building Effective Teams
  • Developing Talent
  • Collaboration

Self

  • Leading by Example
  • Communicates Effectively
  • Ensures Accountability and Execution
  • Manages Conflict

Business

  • Business Acumen
  • Plans, Aligns and Prioritizes
  • Organizational Agility

With particular emphasis on the following specific position-related competencies:

  • Builds Trust and Credibility
  • Dealing with Ambiguity
  • Customer Focus
  • Approachability

QUALIFICATIONS AND SPECIAL SKILLS REQUIRED:

  • Undergraduate degree or equivalent work experience
  • 3-5 years of experience in vulnerability remediation management or security operations in

a mid-to-large enterprise.

  • A solid understanding of industry best practices for vulnerability remediation, specifically

processes supporting industry best practices

  • Technical experience with Linux Operating Systems and Java vulnerability remediation

principles.

  • Excellent understanding of Linux systems.
  • Excellent reporting and communication skills with the ability to present technical findings

to varied audiences.

  • Proficiency in collecting, analyzing and disseminating threat solutions
  • Excellent reporting and communication skills with the ability to present technical findings

to varied audiences.

PHYSICAL REQUIREMENTS/ADA: Job requires ability to work in an office environment, primarily on a computer. Requires sitting, standing, walking, hearing, talking on the telephone, attending in-person meetings, typing, and working with paper/files, etc. Consistent timeliness and regular attendance. Vision requirements: Ability to see information in print and/or electronically. This role requires regular in-office presence, including to engage in in-person team interaction, meetings and collaboration, and/or feedback. However, this role can perform duties effectively using a combination of in-office and remote work. #LI-Hybrid

SUPERVISORY RESPONSIBILITIES: None

DISCLAIMER: This job description is a summary of the primary duties and responsibilities of the job and position. It is not intended to be a comprehensive or all-inclusive listing of duties and responsibilities. Contents are subject to change at management’s discretion.

Ross is an equal employment opportunity employer. We consider individuals for employment or promotion according to their skills, abilities and experience. We believe that it is an essential part of the Company’s overall commitment to attract, hire and develop a strong, talented and diverse workforce. Ross is committed to complying with all applicable laws prohibiting discrimination based on race, color, religious creed, age, national origin, ancestry, physical, mental or developmental disability, sex (which includes pregnancy, childbirth, breastfeeding and medical conditions related to pregnancy, childbirth or breastfeeding), veteran status, military status, marital or registered domestic partnership status, medical condition (including cancer or genetic characteristics), genetic information, gender, gender identity, gender expression, sexual orientation, as well as any other category protected by federal, state or local laws.

Similar roles