This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This role will be responsible for assessing the security vulnerabilities & threats identified by the infrastructure scan. He should work with appropriate teams across the businesses and associated 3rd parties to ensure appropriate remediation plans are defined and implemented. This position is a part of the Vulnerability Management service acting as the primary support to the lead for the Vulnerability Management team and own identifying, quantifying, and managing cyber vulnerabilities across Organization, in conjunction with other parts of the supportive teams.
Job Responsibility:
Assessing the security vulnerabilities & threats identified by the infrastructure scan
Work with appropriate teams across the businesses and associated 3rd parties to ensure appropriate remediation plans are defined and implemented
Perform information system security vulnerability scanning to discover and analyze vulnerabilities and characterize risks to networks, operating systems, applications, databases, and other information system components
Perform compliance scanning to analyze configurations and facilitate implementation of configurations and hardening settings for networks, operating systems, applications, databases, and other information system components
Maintaining appropriate documentation that defines the Threat & Vulnerability Management Program, Policy and Procedures
Participated in the calls to resolve information security incidents, including internal events and targeted threats
Research, evaluate, and assess emerging cyber security threats, incidents, and vulnerabilities
Work with the stakeholders to develop and maintain a vulnerability intelligence process that monitors for emerging systems vulnerabilities
Prioritize the remediation of vulnerabilities based on their characteristics, such as threat intelligence, business criticality, and exploit maturity
Define minimum standards in relation to threat management and monitoring compliance across the businesses
Take responsibility for scheduling, detecting, and analyzing vulnerabilities and vulnerability-related activity affecting the organization domain
Help create prioritized overviews of cyber vulnerabilities by putting them in the context of IT services and business applications, leading to remediation actions by the respective parties
Conduct deep-dive analysis on attacks and share actionable data with partner teams
Ensure the accurate and timely release of vulnerability metrics
Report on areas of non-compliance against Policy and/or Group Standards
Requirements:
6+ years Security-Threat and Vulnerability-Vulnerability Remediation to include Researching, evaluating, scanning, reporting out on cyber security threats, incidents, and vulnerabilities (automated asset discovery, vulnerability management, threat prioritization, and remediation)
Must have Hands-on experience working with Vulnerability assessment tool, Qualys VMDR.
Must have client-facing experience
Nice to have:
Prisma Cloud experience is an advantage to have
These other Vulnerability tools is highly ideal: Nexpose, Nessus, vulnerability response (ServiceNow), and/or Splunk
Strategic thinker with attention to technical detail
Strong communication and leadership skills
Collaborative mindset with a focus on enablement and mentorship
What we offer:
medical, dental, and vision insurance
flexible spending or health savings account
life and AD&D insurance
short and long term disability coverage
paid time off
employee assistance
participation in a 401k program with company match
additional voluntary or legally-required benefits
incentive compensation based on individual and/or company performance