Vacancy expired!
The Vulnerability Management Analyst is part of our Security Operations ('SecOps') team. This role is responsible for coordinating and maintaining vulnerability management for IT systems, assessing technology and suppliers, and working with teams to remediate issues. We're looking for an enthusiastic, hardworking, and creative team member to keep our company secure.
Studies have shown that women and people of color are less likely to apply for jobs unless they believe they meet every one of the qualifications in a job description. Our top priority is finding the best candidate for the job and if you are interested in the position, we would encourage you to apply, even if you don't believe you meet every one of the qualifications below.- Using vulnerability testing tools for systems vulnerabilities and working with security service providers, scheduling and creating scans, working with tech teams to remediate issues
- Document, prioritize and formally report asset and vulnerability state, along with remediation recommendations and validation
- Working with clients to resolve public facing vulnerabilities in our applications and associated infrastructure
- Regularly research and learn new TTPs in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary
- Create metrics for management reporting
- Coordinate with internal and external auditors
- Coordinate Security RFP responses
- Maintain document repository and audit book
- Monitor for new vulnerabilities (US-CERT, NVD, CVE, Twitter)
- Maintains monthly status reports for RFPs/Vulnerabilities/Security Training
- Maintains ticketing system
- Tracks and coordinates SecOps projects
- Develop and maintain a calendar for the above activities
- Improve SecOps efficiency, maintain workflows and collaboration
- Participates in finding process improvement opportunities, provides solutions and participates in implementation of changes.
- Familiarity with vulnerability assessment tools and manual testing practices (Qualys, InsightVM, Metasploit)
- 1-3 years performing vulnerability management
- Ability to plan, organize, prioritize and independently solve problems seeking help when necessary
- Strong communication skills, very proactive and results oriented
- Knowledge of software development processes and concepts
- Understanding of OWASP, USCERT, NIST, ISO 27001/270002 a plus
- Ability to meet deadlines.
- Familiarity with Linux
- Proficient with Microsoft Office
- Ability to stay calm under pressure and the ability to set customer expectations and clearly follow through to meet them.
- ID: #49037657
- State: New York New york city 10012 New york city USA
- City: New york city
- Salary: USD TBD TBD
- Job type: Permanent
- Showed: 2023-02-06
- Deadline: 2023-04-07
- Category: Et cetera