- This position is a part of the Vulnerability Management service acting as the primary support to the lead for the Vulnerability Management team and own identifying, quantifying, and managing cyber vulnerabilities across Organization, in conjunction with other parts of the supportive teams
|
- The role will be responsible for assessing the security vulnerabilities & threats identified by the infrastructure scan.
This person should work with appropriate teams across the businesses and associated 3rd parties to ensure appropriate remediation plans are defined and implemented
|
- Hands-on experience working with Vulnerability assessment tools like Qualys, Nexpose, Nessus & vulnerability response (ServiceNow), Splunk
|
- Perform information system security vulnerability scanning to discover and analyze vulnerabilities and characterize risks to networks, operating systems, applications, databases, and other information system components
|
- Perform compliance scanning to analyze configurations and facilitate implementation of configurations and hardening settings for networks, operating systems, applications, databases, and other information system components
|
- Maintaining appropriate documentation that defines the Threat & Vulnerability Management Program, Policy and Procedures
|
- Participated in the calls to resolve information security incidents, including internal events and targeted threats
|
- Research, evaluate, and assess emerging cyber security threats, incidents, and vulnerabilities
|
- Work with the stakeholders to develop and maintain a vulnerability intelligence process that monitors for emerging systems vulnerabilities
|
- Prioritize the remediation of vulnerabilities based on their characteristics, such as threat intelligence, business criticality, and exploit maturity
|
- Define minimum standards in relation to threat management and monitoring compliance across the businesses
|
- Take responsibility for scheduling, detecting, and analyzing vulnerabilities and vulnerability-related activity affecting the organization domain
|
- Help create prioritized overviews of cyber vulnerabilities by putting them in the context of IT services and business applications, leading to remediation actions by the respective parties
|
- Conduct deep-dive analysis on attacks and share actionable data with partner teams
|
- Ensure the accurate and timely release of vulnerability metrics
|
- Report on areas of non-compliance against Policy and/or Group Standards
|