Job description: Experience with both Vulnerability Management and Risk Management
This role is not with Information Security side of the organization this is with IT side. This role is to manage the day to day vulnerability remediation activities performing by IT after getting the vulnerability reports from Information Security side.
- The following activities will be performed by this position once GIT receives the Vulnerability reports from different vulnerability scanning sources on weekly basis
- Initial triaging (comparison of the vulnerabilities with previous week for updating remediation status Risk Acceptance Status Fall outs etc. update the Target Remediation Dates etc.) of the vulnerabilities received from Information Security side on Weekly basis
- Coordinate with ITs different technology teams day to day basis for target remediation dates justification for slippage of the dates etc.
- Proactively get the real-time status from different remediation teams and escalate the in case needed
- Reporting the status (through PowerPoint / PDF presentations )to the different Committees and should be able to answer the questions from C Level executives in those committees
- Prefer to have knowledge and experience with Operational and Cybersecurity Risk mitigation process
- Coordinate with IT teams to get the Risk Acceptance and Remediation Template documents whichever applicable on time Good to have the knowledge and experience to do sanity check of those documents
- Update the Knowledge base documents including SoPs as needed
- Strong knowledge and experience in Jira and Excel are desirable including the knowledge to update the backend workflows of Jira if needed
- Strong knowledge and experience in adhering the existing process and suggest the improvement required to bring the efficiency
Strong communication skills along with the skill of converting complex technology jargons into simple phrases understandable by any C Level executives
If you are interested or have any references please share resume at