Senior Security Vulnerability Analyst
Personnel Qualifications
- At least five years of experience performing the functions associated with this labor category.
- Experience with security technologies including vulnerability scanners and SIEM solutions.
- Familiarity with relevant industry standards and regulations.
- Experience in identifying and developing mitigation strategies.
- Experience analyzing data and identifying vulnerabilities.
- Experience building consensus around vulnerability management policies and procedures.
- Experience conducting security gap analyses to identify potential vulnerabilities in Board systems and networks.
- Experience collaborating with key stakeholders to assess prioritize and develop actionable plans to address the discovered gaps
Capabilities
- Provide support for the Boards vulnerability management program that includes but is not limited to the following tasks:
- Create configure and execute daily and weekly credentialed and noncredentialed vulnerability scans of Board workstations servers and network devices.
- Evaluate the risk of all identified vulnerabilities and prepare remediation instructions for system administrators.
- Generate reports to measure the Boards progress in meeting vulnerability remediation targets.
- Monitor the Boards compliance to include tracking Board vulnerabilities against CISAs catalog of known exploited vulnerabilities.
- Manage and administer the Boards vulnerability management systems.
- Conduct cybersecurity gap analyses to identify potential vulnerabilities in Board systems and networks.
- Collaborate with key stakeholders to assess prioritize and develop actionable plans to address the discovered gaps.
Certification
- Certified Information Systems Security Professional (CISSP)
- GIAC Enterprise Vulnerability Assessor (GEVA)
- Equivalent