Manager Vulnerability Management

JetBlue Airways CorporationWashington, District of ColumbiaOn-siteFull-timeStaff, 8–12 yearsListed 4 hours ago

Apply now

About this role

Position Summary

At JetBlue, cyber security is driven by the concepts of Risk Management and Threat-Informed Defense, the study of current threats, actors and techniques to prioritize risks and adapt defenses, controls and resources to those constantly-changing dynamics. The Crewmember in this role is responsible for overseeing, directing and prioritizing activity across a range of risk-reduction efforts with regard to the identification, prioritization, and remediation of vulnerabilities. Beyond traditional infrastructure vulnerabilities, the Manager will be responsible for activities to detect and mitigate cloud and application layer vulnerabilities. This role reports to the Director – Cyber Security who is responsible for Threat Intel, Security Monitoring, Detection & Incident Response, and will work in close concert with those other teams.

Essential Responsibilities

- Continued development, evolution and maintenance of JetBlue’s Vulnerability Management Program, including managing traditional scanning and cloud security tools and overseeing the scanning and discovery process, exposure management and external attack surface posture

- Manage the team, policies and procedures to support successful compliance with Payment Card (PCI), Sarbanes-Oxley, TSA and other required oversight bodies/frameworks

- Collaborate with cross-functional teams in IT, networking and other departments to drive remediation of identified vulnerabilities and misconfigurations across a hybrid environment, and to enumerate, monitor and manage exposure across our external attack surface

- Partner with architecture, engineering and application development teams to establish and maintain comprehensive visibility into potential risks in a large-scale cloud environment

- Oversee analysts, partners and service providers to ensure regular, rigorous and effective vulnerability discovery and tracking processes, including regular metrics and reporting

- Clearly articulate and correctly prioritize risk for stakeholder and leadership teams

- Coordination with our Penetration Testing program to reduce risk throughout JetBlue’s software development, deployment and testing lifecycle to minimize the introduction of vulnerabilities as the environment continues to evolve

- Coordinate with the Threat Intel and Pen Test teams to ensure immediate assessment of risk for actively-exploited vulnerabilities and live or time-sensitive threat-actor campaigns and activity

- Understand business requirements, network topology and other factors to make informed decisions around inherent and residual risk, prioritization and resource allocation

- Develop the integration and automation strategy and manage analysts to optimize workflows between Vulnerability Management and the asset and application teams who address findings

- Drive continuous evolution and improvement in processes, controls, and the Risk Exception and Risk Acceptance processes as they relate to Vulnerability response

- Take a significant role in the development of direct reports and other Crewmembers to support their engagement, growth, and goal achievement

- Other duties as assigned

Minimum Experience and Qualifications

- Bachelor's Degree in Computer Science, Cyber Security, Data Analysis, or other relevant discipline; OR demonstrated capability to perform job responsibilities and a High School Diploma/GED and at least four (4) years of previous related work experience

- Five (5) years of relevant work experience in Vulnerability Management, Patch Management, IT Platform Engineering or other related fields

- Demonstrated knowledge of scanning tools such as Tenable or Rapid7, cloud security platforms such as Wiz or Orca and Attack Surface Management tools and concepts

- Experience with penetration testing methodologies and tools

- Familiarity with industry standards and frameworks, such as Payment Card Industry (PCI) Security Standards, ISO 27001 and/or National Institute of Standards and Technology (NIST) Cybersecurity Framework

- Experience with application security concepts and scanning methodologies such as static code analysis and dynamic application security testing

- Understanding of application container architecture

- Leadership and management experience, including leading a team

- Risk Management knowledge and experience

- Excellent communication and presentation skills

- Available for occasional overnight travel (10%)

- Must pass a ten (10) year background check and pre-employment drug test

- Legally eligible to work in the country in which the position is located

- Authorization to work in the US is required. This position is not eligible for visa sponsorship

Preferred Experience and Qualifications

- Six (6) years of relevant work experience

- Experience with security testing, Attack Surface Management or red-teaming

- Strong understanding of the differences in Vulnerability Management across Data Center, Cloud, Containers, Applications etc. is highly desirable

- Creative problem solver and innovative thinker

- Past work performing or overseeing additional adjacent disciplines such as Patch Management, Secure Software Development Life Cycle (SSDLC), Pen Testing or Red/Purple Teaming

- Experience working with AWS, Azure and/or GCP

- Experience building out Management Metrics and Key Performance Indicators (KPIs)

Crewmember Expectations:

- Regular attendance and on time punctuality

- Potential need to work flexible hours and be available to respond on short-notice

- Able to maintain a professional appearance

- When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of aircraft

- Organizational fit for the JetBlue culture, that is, exhibit the JetBlue values of Safety, Caring, Integrity, Fun and Passion

- Promote JetBlue’s #1 value of safety as a Safety Ambassador, supporting JetBlue’s Safety Management System (SMS) components, Safety Policy and behavioral standards

- Identify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue’s confidential reporting systems (Aviation Safety Action Program (ASAP) and Safety Action Report (SAR))

- Responsible for adhering to all applicable laws, regulations (FAA, OSHA, DOT, etc.) and Company policies, procedures and risk controls

- Uphold JetBlue’s safety performance metric goals and understand how they relate to their duties and responsibilities

- The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.

Equipment:

- Computer and other office equipment

Work Environment:

- Traditional office environment

Physical Effort:

- Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary)

#LI-AC1

#LI-Hybrid