Job Summary
This position leads Information Security staff in the evaluation of risks and threats, development, implementation, communication, operation, monitoring and maintenance of the IT security policies and procedures to promote secure and uninterrupted operation of all IT systems, application and infrastructure. In this role, you will be responsible for proactively identifying, prioritizing, and tracking security vulnerabilities across the client’s network and systems. You will also be responsible for conducting security assessments, running penetration tests, review Cyber threat intelligence and provide relevant data to parties to action upon. This role will perform red team exercises mimicking adversary practices while leveraging similar tools and techniques. To be successful in this role you must have a broad understanding of information security and experience in vulnerability management, and cyber exploitation techniques. You must also possess excellent problem-solving and communication skills.
Job Responsibilities
- Cyber Assessment & Vulnerability Management lead is responsible for the overall lifecycle of the Cyber Assessment & Vulnerability Management program.
- Inform, advise, and partner with IT, Security, and other business units to help better secure their operations. Identify gaps in current processes, workflows, and design and recommend changes or enhancements as needed.
- Participate in Change Management Process, from early Assessment of proposed changes/enhancements, through Vulnerability scanning and recommended remediation before go-live.
- Participate in incident response activities as needed. Ensure cross-company processes around threat & vulnerability management are adhered to. This includes tracking SLAs, discovery, and handling of any finding. Maintain situational awareness, identification, tracking, and ensuring action on industry news related to software vulnerabilities, including zero-day vulnerabilities and emergency patching.
- Implement and operationalize advanced Vulnerability Management reporting tools. Design, develop and operationalize Vulnerability Management metrics. Design and Implement advanced Vulnerability dashboards.
- Evaluate performance, perform career development, coaching and counseling and manage compensation for Cyber assessment staff.
- Responsible for conducting security assessments & penetration tests. Review Cyber threat intelligence and ensures and provide relevant data to parties within the Cyber Assessment & Vulnerability management teams to action upon. Oversee regular red team exercises to proactively emulate attackers TTP and report back findings so security engineering and operations can improve their defenses.
- Create, perform tabletop exercises exercising mimicking adversary practices testing the company’s ability to respond to cyber incidents.
Required
Job Specific Qualifications:
- Bachelor's degree and 8 years of relevant cyber security experience
- In lieu of a degree 12 years of cyber experience
- Experience within vulnerability/compliance management, penetration testing, and/or threat hunting
- Strong leadership and influence skills
- Ability to present to all levels of management and executive leadership
- Excellent teamwork, facilitation, relationship building, and negotiation skills
- Able to maintain positive working relationships both leading and as part of a team
- Effective time management skills and able to multitask effectively
- Able to communicate effectively with both technical and non-technical individuals
Desired
Certified Information Systems Security Professional (CISSP), or equivalent