Senior Vulnerability Analyst
Job Summary
At SITA we keep airports moving airlines flying smoothly and borders open. Our technology and communication innovations power the success of the global air travel industry.
Youll find us in 95% of international airports working closely with over 2500 transportation and government clients. Each partnership brings unique challenges and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We dont just move the world forwardwere proud to be recognized as aGreat Place to Workby our employees and certified in most of our growing locations.
Here we feel empowered supported and inspired to grow.
Are you ready to love your job The adventure begins right here with you at SITA.
- ABOUT THE ROLE & TEAM
As CTEM Analyst you will support the organizations Continuous Threat Exposure Management program by identifying validating prioritizing and tracking security exposures across the enterprise. You will play a key role in reducing organizational risk by analyzing vulnerabilities misconfigurations attack paths and threat intelligence to ensure remediation efforts focus on the most impactful exposures.
You will be accountable for maintaining exposure visibility supporting risk-based prioritization coordinating remediation activities and providing meaningful reporting and metrics that drive exposure reduction and security improvement initiatives.
Reporting to the Hiring Manager Title you will be part of the Cybersecurity & Risk Management Team responsible for strengthening the organizations security posture through proactive exposure management attack surface reduction and continuous risk assessment.
WHAT YOU WILL DO- Maintain visibility of the enterprise exposure inventory across cloud environments identities endpoints applications infrastructure and external attack surfaces.
- Perform vulnerability assessments to identify vulnerabilities security weaknesses misconfigurations and other security exposures.
- Analyze vulnerability asset threat intelligence attack-path and configuration data to identify areas of elevated risk.
- Prioritize exposures using business risk exploitability asset criticality and threat intelligence to support risk-based decision making.
- Validate exposures to determine realistic exploitation potential while following approved and safe assessment practices.
- Coordinate remediation activities with infrastructure cloud application and technology teams to ensure timely risk reduction.
- Support attack-path analysis and exposure reduction initiatives across enterprise environments.
- Track remediation progress exception requests compensating controls and risk acceptance decisions.
- Develop CTEM dashboards executive summaries operational metrics and regular reporting for leadership and stakeholders.
- Support purple team exercises tabletop activities security assessments and control validation initiatives to improve organizational resilience.
- quiredWHO YOU ARE
- You have 3-5 years of experience in vulnerability management exposure management cloud security security operations or risk management.
- You have experience managing the end-to-end vulnerability and exposure lifecycle including discovery prioritization remediation coordination validation exception management and closure.
- You are familiar with vulnerability scanners cloud security posture management platforms attack surface management tools and CMDB or asset inventory solutions.
- You have experience correlating threat intelligence vulnerabilities misconfigurations asset criticality and business context to support risk-based prioritization.
- You possess strong knowledge of vulnerability management and exposure management principles methodologies and best practices.
- You understand exposure prioritization frameworks and methodologies including CVSS EPSS CISA Known Exploited Vulnerabilities (KEV) exploitability analysis and asset criticality.
- You have a good understanding of attack-path analysis across identity cloud endpoint and network environments.
- You understand SOC detection requirements security monitoring concepts and the MITRE ATT&CK framework.
- You are proficient in data analysis and reporting tools such as Excel Power BI KQL SQL Python or similar technologies.
- You possess strong analytical stakeholder management communication coordination and reporting skills.
NICE-TO-HAVE- Experience supporting Continuous Threat Exposure Management (CTEM) initiatives in large enterprise environments.
- Familiarity with cloud-native security tools across Microsoft Azure Microsoft 365 AWS or hybrid cloud environments.
- Experience participating in purple team exercises threat-informed defense activities or attack simulation and control validation programs.
EDUCATION & QUALIFICATIONS- Bachelors degree in Information Technology Cybersecurity Computer Science or a related field or equivalent practical experience.
- At least one industry-recognized cybersecurity certification such as Security CySA GSEC SC-200 AZ-500 CISSP or a vendor-specific vulnerability/exposure management certification.
Were all about diversity. We operate in 200 countries and speak 60 different languages and cultures. Were really proud of our inclusive environment. Our offices are comfortable and fun places to work and we make sure you get to work from home too. Find out what its like to join our team and take a step closer to your best life ever.
Flex Week: Work from home up to 2 days/week (depending on your teams needs)
Flex Day: Make your workday suit your life and plans.
Flex-Location: Take up to 30 days a year to work from any location in the world.
Employee Wellbeing: We have got you covered with our Employee Assistance Program (EAP) for you and your dependents 24/7 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs.
Professional Development: At SITA we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning Microsofts Enterprise Skills Initiative and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling Harvard Business Publishing for people leadership Stanford for strategic development and many others we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way.
Competitive Benefits: Competitive benefits that make sense with both your local market and employment status.
SITA is an Equal Opportunity Employer. We value a diverse support of our Employment Equity Program we encourage women aboriginal people members of visible minorities and/or persons with disabilities to apply and self-identify in the application process.
Required Experience:
Senior IC
About Company
At SITA we lead one of the most exciting and advanced industries in the world. With us, there are no limits for people looking to explore the edges of possibility and beyond. We are the world’s leading specialist in air transport communications and information technology. Around the ... View more