Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via emailNot Disclosed
Salary Not Disclosed
1 Vacancy
Overview
A minimum of 5 years of experience is required for the position as well as each of the technical skillsets.
This candidate serves as the Security Vulnerability Team Lead within the Information Security Office of Pennsylvanias Infrastructure and Economic Development IT Delivery Center (IED DC) which includes the Department of Transportation (PennDOT) PA Emergency Management Agency (PEMA) and the Department of Community and Economic Development (DCED).
Job Responsibilities
Primary role is as the subject matter expert (SME) for the management and administration of the delivery centers vulnerability management program.
Conduct regular vulnerability assessments and tests to identify security weaknesses in systems and applications.
Collaborate with compliance teams to ensure adherence to regulatory requirements and industry standards related to security vulnerabilities.
Coordinate with IT and development teams to prioritize vulnerabilities and ensure timely remediation actions are taken.
Stay informed about the latest security trends threats and best practices to continuously improve the vulnerability management process.
Prepare and present vulnerability management reports to senior management highlighting key findings and recommendations.
Provide training and awareness programs for staff on security vulnerabilities and best practices for risk mitigation.
Facilitate incident response activities related to vulnerabilities and coordinate with external partners as necessary.
Demonstrates good judgement and problemsolving skills. Reacts and adapts to changing circumstances rapidly.
Leverages Commonwealth incident tracking and ticketing systems to receive tasks from other units delegate tasks to other units prioritize daily tasks document actions taken and the final resolution for tasks completed.
Provides on call and/or emergency support including afterhours as needed.
Adheres to established service management processes and procedures.
Performs all other related duties as assigned.
Requirements
Extensive experience with Tenable Security Center a must. Certifications are a plus.
Familiarity with DAST tools such as Rapid 7 AppSpider.
Technically proficient and experienced with Windows and Linux operating systems and system hardening.
Knowledge of regulatory compliance standards relevant to cybersecurity
Experience with risk assessment methodologies and frameworks (e.g. NIST FAIR)
Professional oral and written communication skills.
Strong understanding of network protocols and technologies (e.g. OSI Model TCP/IP firewalls intrusion detection systems)
Excellent soft skills such as listening presenting and negotiating.
Must pass required Pennsylvania State Police background check.
Cannot have any felony offenses.
Ability to work remotely/and locally when required.
Full-Time