About this role
Supports the full cycle of vulnerability management from discovery/asset identification through risk assessment, remediation, verification, and reporting. Works with Information Security, Information Technology, engineering, and other technical and product/operational stakeholders to ensure understanding of and commitment to relevant vulnerability standards and practices. Proactively monitors system, network, and other changes to ensure their inclusion in vulnerability assessment/remediation activity.
Required Qualifications
- Diploma or equivalent work experience required.
- Minimum of 5-7 years of relevant experience or equivalent combination of education and experience in Vulnerability Management.
- Good business English skills (Written and spoken).
- Excellent business English and communication skills (Written and spoken).
- Ability to influence behavior and outcomes via tactful, yet assertive, communication with colleagues.
- Administrative and/or integration knowledge of scanning and ticketing systems such as Tenable and ServiceNow.
- Working competence with Office, especially Outlook and Excel, including formulas.
Preferred Qualifications
- Good knowledge of Threat Intelligence collection, dissemination, analysis and delivery.
- Good knowledge of multiple security and privacy concepts such as: OSINT, HUMINT, SOCMINT, NIST, PCI, GDPR.
- GCIA, GHIH, CEH, or CISSP Certification.
- Good knowledge of ISO 9001 Quality management system.
- Good knowledge of ISO 20000 information technology service management (ITSM) system.
- Good knowledge of other security frameworks such as COBIT, PCI DSS, NIST and SSAE16 is advantage.
- Good knowledge of Security Regulations (SOX, PCI, GLBA) is an advantage.
- Good knowledge of ISO 31000:2009 Risk Management.
- Knowledge of Windows OS, Linux OS and/or general application patching, configuration, or upgrade.
- DOD ACAS, HBSS training