Open-Source Risk Realignment Analyst

04 Mar 2025

Vacancy expired!

Company Overview: Req ID: 229226 NTT DATA Services strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a TEMP IT Computer Prof Specialist to join our team in REMOTE, Kentucky (US-KY), United States (US). Job Description: Description The Open-Source Risk Realignment Analyst is responsible for helping the Cyber Security Engineering team to assess and realign vulnerabilities in open-source components. Risk realignment involves taking the base score for the vulnerability and analyzing it in the context of the application that will be using the vulnerable component, for example if the base score for the vulnerability is Critical but the application is internally facing only, then the risk may be realigned to reflect a High or Medium severity, depending on the data classification that the application maintains ( Public , Internal , Confidential or Restricted ). The role will be responsible for managing components in open-source tools including JFrog Artifactory and Xray, re-rating vulnerability severity using our published risk realignment process, and managing VITs in Service Now. In this role you will be a key player in helping the Cyber Security Engineering team enable new process as we move to support business development teams in determining what vulnerabilities need to be addressed with highest urgency. Responsibilities Tasks for this role include: Process open source related requests in service now Use risk realignment process to calculate adjusted vulnerability severity (process diagram is a published document and base vulnerability scores are available in Artifactory) Create vulnerability tracking item (VIT) in service now Create repository in Artifactory and publish vulnerable open source component to the new repo Close out VITs and remove vulnerable open source component from repo once development team achieves remediation Required Qualifications At least 1 years experience with exposure to Open Source components and tools Knowledge of open source vulnerabilities and risk remediation Comfortable following published process for risk realignment Comfortable providing remediation advice to developer teams Experience with DevSecOps, Software Development Life Cycle (SDLC), Agile (Scrum/Kanban) Excellent communication skills, can navigate organization structures and processes Preferred Qualifications Experience with Open Source components, tools and vulnerability management Experience with JFrog Artifactory and Xray Experience using Service Now About NTT DATA Services: NTT DATA Services is a recognized leader in IT and business services, including cloud, data and applications, headquartered in Texas. As part of NTT DATA, a $30 billion trusted global innovator with a combined global reach of over 80 countries, we help clients transform through business and technology consulting, industry and digital solutions, applications development and management, managed edge-to-cloud infrastructure services, BPO, systems integration and global data centers. We are committed to our clients long-term success. Visit or LinkedIn to learn more. NTT DATA Services is an equal opportunity employer and considers all applicants without regarding to race, color, religion, citizenship, national origin, ancestry, age, sex, sexual orientation, gender identity, genetic information, physical or mental disability, veteran or marital status, or any other characteristic protected by law. We are committed to creating a diverse and inclusive environment for all employees. If you need assistance or an accommodation due to a disability, please inform your recruiter so that we may connect you with the appropriate team.

  • ID: #49401200
  • State: Kentucky Remote 40202 Remote USA
  • City: Remote
  • Salary: BASED ON EXPERIENCE
  • Job type: Contract
  • Showed: 2023-03-04
  • Deadline: 2023-05-02
  • Category: Et cetera