The Vulnerability Management Analyst is a global role within IONs central services division and will support the Group Security strategy and operational excellence through the identification mitigation and remediation of information security vulnerabilities misconfigurations and risks to the business. This role reports to the Vulnerability Management Manager who reports to the Global Head of IT Security.
As a member of the ION Security team you will build and lead a team of Security professionals specialising in Vulnerability Management along with managing the partners and technology vendor deliverables and of course building and owning the strategy to deliver a world class Vulnerability Management program. The candidate must understand their role in the broader vulnerability management program and your team will regularly perform discovery scanning risk/exposure assessments mitigation support activities continuous validation assessments and lessons learned workshops and improvement projects to continuously improve our process across Group Security and all other Verticals.
We are looking for a diligent dedicated creative and motivated individual. Excellent communication skills are a must and the role holder will be expected to cultivate working relationships with other teams and colleagues of varying technical ability. The role would suit a technically strong candidate with an extensive cybersecurity background at least 5 years working in a security role with focus on Vulnerability Management.
Responsibilities:
This role may require work-out of hours in support of 24x7 globally coordinated operation
The primary responsibilities of this role are to:
Personnel Management
Align deliverables and objectives to OKRs
Be the escalation point for security Tooling issues and critical security breaches
Protect and defend:
Manage Vulnerability Management tooling to ensure coverage/availability/efficacy
Drive improvements and feature enhancement to ensure ROI
Management reporting real-time metrics and scheduled reports
Drive process/procedure changes accordingly
Ensure quality of ticketing & runbook maintenance
Cultivate and maintain strong vendor relationships
Have an attitude of continuous improvement
Participate in CAB Tool review or Architecture Review Boards (ARBs)
As a member of the ION IT Security Team it is expected that the person in this role will:
Execute ongoing operational business-as-usual (BAU) tasks to meet management-defined KPIs and SLAs and deliver security projects in line with management-defined priorities and deadlines
Stay current with the latest security news threats intelligence tactics techniques and vulnerabilities. Research and analyze new threats and vulnerabilities to determine exposure.
Assist and/or lead efforts to isolate contain respond to and recover from security incidents
Identify review prioritize plan coordinate and follow-up on the remediation of vulnerabilities
Define document and follow approved processes for all the responsibilities included in this job description. Create and maintain documentation for systems including design and operation
Review vulnerability management systems configurations and processes to ensure and report on compliance with ION policy client requirements audit controls regulations and industry best practices. Provide best practice security recommendations to IT and other teams within ION based on review results
Experience Skills and Qualifications:
Degree/diploma/certifications in a technology-related field and/or relevant working experience; highly desired certifications include:
Security CCSP CEH GCIH GMON CASP or CISSP
Minimum of 5 years experience in Vulnerability Management within large organizations
Excellent track record of building a Vulnerability Management program on a global scale with knowledge on vulnerability assessments remediation and mitigation activities
Technical Security/Engineering/Compliance background witha previous track record of building risk management framework and applying to an existing vulnerability management program
Strong technical expertise in implementing a Prioritizationformula to vulnerabilities and misconfigurations and translating these into risks
Excellent knowledge of Vulnerability Management frameworks such as NIST/SANS
The following general characteristics are required:
A team player with the ability to work independently and unsupervised
Ability to own delegated tasks and see them through to completion
Ability to manage time and prioritize work to maximize productivity
Excellent reporting and presentation skills are essential for this role
Excellent communication skills (both written and verbal)
Exceptional attention to detail and quality
Excellent problem-solving techniques and trouble analysis skills
Experience in design and publishing Security Standards & Policies
Experienced in running global Bug Bounty/VDP programs
Experiencedin Pen Testing from scope schedule findings remediation and risk registration
The candidate should have a good knowledge of:
Vulnerability Management concepts controls and best practices for all Operating systems & asset types (e.g. workstations endpoints mobile servers either Windows/Linux cloud instances etc.)
Cloud Security compliance (IaaS PaaS SaaS) and misconfigurations
Multi-platform endpoints infrastructure and XaaS vulnerability management deployments
General IT networking concepts protocols standards and network security concepts controls and best practices
Forensic investigation techniques
Prior experience deploying configuring managing and/or operating security technologies is preferred such as endpoint security (e.g. AV/EPP/EDR) SIEM DLP SWG CASB UEBA IDS IPS firewalls IAM/PIM/PAM Vulnerability Management MDM etc.
Proven knowledge of compliance regulatory practices and experience managing audits
About us:
Were a diverse group of visionary innovators who provide trading and workflow automation software high-value analytics and strategic consulting to corporations central banks financial institutions and governments. Founded in 1999 weve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world.
Over 2000 of the worlds leading corporations including 50% of the Fortune 500 and 30% of the worlds central banks trust ION solutions to manage their cash in-house banking commodity supply chain trading and risk.
Over 800 of the worlds leading banks and broker-dealers use our electronic trading platforms to operate the worlds financial market infrastructure.
ION is a rapidly expanding and dynamic group with 13000 employees and offices in more than 40 cities around the globe. Our ever-expanding global footprint cutting edge products and over 40000 customers worldwide provide an unparalleled career experience for those who share our vision.
ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities abilities cultures and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business.
ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.