DescriptionSeize the opportunity to enhance cybersecurity utilizing your skills in threat analysis and incident response to protect vital data and systems.
As a Security Operations Senior Associate in Cyber Security and Technology Controls you will play an important role in safeguarding the organizations digital assets and infrastructure by proactively detecting assessing and responding to threats vulnerabilities and security incidents. Drawing on your knowledge of security principles practices and theories you will collaborate with crossfunctional teams to develop a coordinated approach to security and educate employees on best practices policies and procedures. Your work will have a direct impact on departmental outcomes as you plan and ensure progress identify gaps in information and conduct analyses to solve complex cybersecurity problems. By utilizing your advanced analytical technical and problemsolving skills you will contribute to the continuous improvement of our cybersecurity posture and help maintain the integrity confidentiality and availability of sensitive data and systems.
Job responsibilities
- Review new vulnerabilities published from multiple sources and identify those that may pose risk to the firm.
- Identify the impacted assets and/or application(s) at risk via various internal tools with a focus on OSS (Open Source Scanning) of 3rd party applications. Document the vulnerability providing a detailed write up on the risk and exposure.
- Confirm any risk mitigation factors and define the remediation activity if known. Assess exploit code and/or conceptual code to determine attack vectors.
- Recommend any risk mitigation factors and define the remediation activity if known.
- Assess security researcher identified vulnerabilities to provide recommendations on remediation and identify additional risk.
- Be operationally focused and enjoy working in a dynamic environment with the daytoday focus on quick and timely risk reduction activities.
- Drive the global teams daily workflow undertaking daily caseload analysis and prioritization.
- Represent the global team and be the technical lead on major incidents impacting the Vulnerability Management space.
- Demonstrate the ability to develop and form strong working relationships with the partnering Cyber Operations functions and key technology leaders in the region. Be a selfstarter who will take the initiative while being able to work independently and challenge the status quo
Required qualifications capabilities and skills
- Formal training or certification on Cyber Operations/Vulnerability Management and 3 years applied experience.
- Ability to demonstrate comprehension of the endtoend Vulnerability Management workflow (to include industry standards such as CVE CPE CVSS).
- Proven experience in command & control practices like Incident Management and/or Cyber incident response methodologies.
- Strong and broad understanding of Cyber Security Controls (Physical Logical Processes and Procedures)
- Strong and broad understanding of leading vendor products/applications e.g. Oracle Java VMWare F5 Citrix Microsoft; to include product lifecycle & release schedules.
- Strong and broad understanding of opensource software deployment in a large technology estate.
- Strong understanding of Cloud and Public/Private Cloud environments.
- Strong deductive reasoning multitasking critical thinking problem solving and prioritization skills.
- Familiarity with Cyber scanning tools including Qualys Snyk CrowdStrike and other tools is an advantage.
- Experience of working with data sources via SQL JSON APIs and Splunk will be highly beneficial.
- General understanding ofhow software is built what dependencies are and how vulnerable dependencies present risk to the application.
Preferred qualifications capabilities and skills
- Strong deductive reasoning multitasking critical thinking problem solving and prioritization skills.
- Familiarity with open source vulnerability databases and tools e.g. National Vulnerability Database (NVD) Snyk.
- Strong ability to work collaboratively in a team environment
Required Experience:
Senior IC