Build solutions/capabilities within scope of Vulnerability Management to further improve the program.
Assess and triage vulnerabilities, evaluate risk scenarios, security deviations, and partner with engineering teams to drive vulnerability remediation.
Act as SME and support day to day administrative and operational activities for vulnerability management.
Respond to emerging security threats and lead vulnerability assessment discussions.
Recognize and identify potential areas where existing security policies and procedures require change, or where new ones need to be developed.
Understand security requirements, develop and maintain security policies, standards and controls.
Create and maintain operating procedures and flowcharts that illustrate the policies.
Understand data relationship between different sources to identify data quality issues and propose solutions.
Perform tool configurations, customizations, metrics definition, analysis, and reporting.
Identify solutions to improve security automation and integration and coordinate the effort to implement those solutions.
Research different product offerings to address given business needs and maintain a reasonable understanding of competing/complementary products in the marketplace.
Translate business needs and articulate discoveries into user stories or work items for development teams.
Be involved in the design of software solutions to ensure they are practical, sustainable, secure and address user needs.
Engage with technical staff, auditors and leadership, onboard users to tools, provide user support, perform user acceptance tests, and troubleshoot tool issues.
Automate repeatable scenarios using programing or scripting languages.
Requirements
University degree in Cyber Security, Computer Science, Information Systems, or a related field; or equivalent work experience.
5+ years of professional experience.
Proficient in industry best practices in cyber security and security engineering related to vulnerability management, attack surface management and software development.
Experience with risk based vulnerability management, security concepts, and prioritization.
Experience with an enterprise security vulnerability scanning, assessment and reporting.
Ability to communicate risk and urgency to leadership, program, and technical staff.
Understanding of control frameworks such as ISAE, PCI-DSS, and ESMIG.
Understanding of ServiceNow Platform
CMDB, Vulnerability Response, and GRC.
Understanding of Container and Cloud technologies.
Experience within the security automation domain, reporting, and API integrations.
Ability to build dashboards for analysis and reporting (Tableau, PowerBI, Excel, or others).
Tech Stack
Cloud
Cyber Security
ServiceNow
Tableau
Benefits
We give you the freedom to be yourself.
A diverse and inclusive environment in which everyone’s voice counts and where you can reach your full potential.
Committed to an inclusive and accessible recruitment process.