drjobs Vulnerability Management / SAM Specialist

Vulnerability Management / SAM Specialist

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Pune - India

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Responsibilities:

  • Define and operate a formal Vulnerability Management Program and framework that defines the vulnerability priorities aligned with business criticality.
  • Manage and maintain vulnerability scanning tools to identify security vulnerabilities in enterprise systems networks and applications.
  • Refine scan results to identify and resolve any false positive findings and produce vulnerability reports with actionable and prioritized information for system owners
  • Perform risk-based prioritization of identified vulnerabilities. Collaborate with security analysts to conduct detailed assessments of critical vulnerabilities and develop mitigation strategy.
  • Work with IT and cross-functional teams to develop and implement prioritized vulnerability remediation plans and timelines. Ensure timely patching or mitigation.
  • Ensure that Metros systems and applications are regularly updated with security patches to mitigate vulnerabilities and maintain a secure environment.
  • Provide risk-based mitigation and remediation recommendations and guidance. Manage tracking and reporting on remediation progress to stakeholders and leadership.
  • Stay updated on emerging threats and vulnerabilities through threat intelligence sources. Integrate threat intelligence into the vulnerability management process to address high-risk areas proactively.
  • Develop baseline asset inventories and maintain owners for systems in the inventory.
  • Define metrics and reporting to track program effectiveness and improvement. Develop and track key performance indicators (KPIs) for the vulnerability management program.
  • Lead a team of security engineers providing mentorship and performance management in improving and automating processes wherever possible.
  • Ensure compliance with security frameworks (e.g. ISO 27001 SOX). Prepare for and support internal and external audits related to vulnerability management.

Technical & Soft Skills:

  • Experience scaling an enterprise vulnerability program across multiple environments driving owner accountability and prioritization
  • Hands-on experience and knowledge of vulnerability management technologies and orchestration via SOAR or other platforms to automate vulnerability management program.
  • In-depth knowledge across core domains OS and Application Vulnerability Management Container Scanning and Patch Management.
  • Well-versed in penetration testing vulnerability scanning and red teaming methodologies and frameworks such as OWASP Top 10 and CWE 25.
  • Advanced understanding of technical information security concepts related to threat landscapes.
  • Strong understanding of network protocols operating systems and security technologies.
  • Experience in improving vulnerability prioritization models.
  • Ability to conduct independent research and analysis identifying issues formulating options and making conclusions and recommendations.
  • Demonstrable conceptual analytical and innovative problem-solving and evaluative skills.
  • Very high attention to detail with strong skills in managing/presenting data and information.
  • Excellent communication collaboration and interpersonal skills
  • Strong skills in documentation including policies standards processes and procedures

Qualifications :

  • Bachelors degree in Computer Science Information Technology Cybersecurity or a related field. A Masters degree or relevant certifications (e.g. CISSP CISM SANS/GIAC) may be preferred.
  • 7-11 years of relevant professional experience in a large multi-national organization or in a known MSSP.


Remote Work :

No


Employment Type :

Full-time

Employment Type

Full-time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.