Vulnerability Management Analyst

🕒 Junho 13

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Connexus Credit Union

Connexus Credit Union

501 - 1000 funcionários

Fundada em 2019

🏦 Bancário

💸 Finanças

💳 Fintech

Banking • Finance • Fintech

A Connexus Credit Union é uma instituição financeira que oferece uma ampla gama de serviços bancários aos seus membros, incluindo contas correntes e poupança, empréstimos, cartões de crédito e serviços de seguros. Fornece várias soluções bancárias pessoais e empresariais, como hipotecas, linhas de crédito com garantia imobiliária, empréstimos para automóveis e empréstimos pessoais. A Connexus está comprometida com o bem-estar financeiro dos membros e oferece serviços bancários digitais, calculadoras financeiras e recursos educacionais. A cooperativa de crédito também possui um programa chamado Connexus Cares para envolvimento comunitário e fornece recursos sobre segurança e proteção contra fraudes. Os membros têm acesso a serviços convenientes, como banco online, caixas eletrônicos e banco por telefone.

Descrição

• Conduct regular vulnerability scanning of networks, servers, endpoints, cloud environments, and applications using approved tools. • Analyze scan results to identify false positives, determine exploitability, and assess business and regulatory risk. • Prioritize vulnerabilities based on CVSS scores, threat intelligence, asset criticality, and financial institution risk impact. • Track vulnerabilities through remediation, validation, and closure using ticketing or governance platforms. • Perform re-scans to validate remediation effectiveness. • Ensure vulnerability management practices align with: FFIEC Cybersecurity Assessment Tool (CAT), NCUA or banking regulatory guidance, GLBA Safeguards Rule, Internal Information Security and Risk Management policies. • Prepare documentation, metrics, and evidence for internal audits, regulatory exams, and third-party assessments. • Support risk acceptance decisions by documenting compensating controls and residual risk. • Partner with IT infrastructure, application development, cloud, and network teams to remediate identified risks. • Translate technical vulnerabilities into clear business risk language for leadership and non-technical stakeholders. • Provide guidance on secure configuration, patching, and vulnerability mitigation strategies. • Participate in security incident response activities when vulnerabilities are exploited or pose imminent risk. • Monitor emerging threats, zero-day vulnerabilities, and industry advisories relevant to financial services. • Contribute to vulnerability management policies, standards, and procedures. • Assist with penetration testing coordination and result analysis. • Collect, organize, and maintain security control evidence and artifacts for monthly continuous monitoring deliverables and assessment/authorization activities, ensuring alignment with required frameworks. • Maintain accurate system inventory and authorization boundary documentation to ensure scanning scope aligns with approved system boundaries. • Analyze scan results for false positives, document justifications, and prepare deviation requests with supporting risk assessments. • Participate in change management processes to ensure continuous monitoring activities align with system changes and maintain compliance posture. • Support and maintain enterprise vulnerability management tools (such as Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring timely updates and patches. • Run regular and on-demand scans across operating systems, databases, web applications, and containers, then work with technical teams to create tickets for remediation. • Track and document vendor dependencies, operational requirements, and open vulnerabilities, producing clear monthly reports and updates. • Contribute to improving internal standards and processes, including maintaining documentation, training materials, and standard operating procedures. • Run the daily vulnerability management program operations, work closely with the patch management analyst in identifying and patching vulnerabilities, and actively participate in weekly vulnerability management team meetings. • Comply with all Federal Regulations as they pertain to your job duties, including BSA.

🎯 Requisitos

• Bachelor's degree in Information Security, Computer Science, Information Technology or commensurate experience is Required. • 3+ years professional work experience in vulnerability management, security operations, or IT risk within a regulated environment is Required. • The GIAC (GSEC or GEVA) certification is preferred upon hire although required to be completed within 6 months of hire. • Prior financial industry regulations and frameworks (FFIEC, NCUA, GLBA, NIST) is Required. • Hands-on experience with vulnerability scanning tools, such as: Tenable (Nessus, Tenable.io), Qualys, Rapid7 or similar platforms is Required. • Strong understanding of, network, operating system, and application vulnerabilities, patch management processes, and secure configuration standards (CIS Benchmarks) is Required. • Strong knowledge of vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS) and risk prioritization frameworks is Required. • Experience delivering monthly or periodic vulnerability status reports and tracking remediation efforts with internal and external teams is Required.

🏖️ Benefícios

• 25 days of paid time off and 10 paid holidays • 16 hours of paid Volunteer Time Off • 401K Retirement with up to 6% employer match • Excellent Health, Dental, Vision insurance, including multiple plan options • Health Savings Account with generous employer contributions • Employer paid Life insurance, Short-Term and Long-Term Disability • Tuition Reimbursement from $4,000 - $7,000 per calendar year • Robust Learning and Development program that includes an annual professional development stipend

Candidatar-se

Vagas Similares

🕒 Junho 13

DoorDash

10.000+ funcionários

🛍️ Comércio Eletrônico

🚗 Transporte

IT Software Asset Manager overseeing software lifecycle management for SaaS and AI platforms. Collaborating with IT, Procurement, and Finance teams to optimize software investments at DoorDash.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $95.200 - $140.000 / ano

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

🧐 Analista de Negócios

🦅 Patrocina Visto H1B

info

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 13

Gainwell Technologies

10.000+ funcionários

⚕️ Seguro de Saúde

Business Analyst at Gainwell utilizing technology to enhance health services for vulnerable communities. Collaborating with clients to innovate solutions for healthcare challenges.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $55.900 - $79.400 / ano

💰 Grant em 2023-06

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

🧐 Analista de Negócios

🦅 Patrocina Visto H1B

info

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 12

StarCompliance

201 - 500

📋 Conformidade

💸 Finanças

☁️ SaaS

Business Analyst responsible for executing implementation projects for StarCompliance solutions, ensuring client satisfaction and successful software adoption.

🇺🇸 Estados Unidos – Remoto (EUA)

💰 Venture Round em 2020-12

⏰ Tempo Integral

🟠 Sênior

🧐 Analista de Negócios

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 12

CLEAResult

1001 - 5000

⚡ Energia

📚 Educação

Business Analyst specializing in Workday Financials to provide primary finance support. Role includes configuration, reporting, and ticket management within Workday platform.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $93.100 - $139.700 / ano

💰 Private Equity Round em 2013-06

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

🧐 Analista de Negócios

🦅 Patrocina Visto H1B

info

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 12

Live Nation Entertainment

10.000+ funcionários

📱 Mídia

Business Analyst enhancing Fan-Based Marketing capabilities by analyzing fan data and campaign performance. Collaborate across Live Nation and Ticketmaster to improve fan experiences.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $88.000 - $110.000 / ano

💰 Post-IPO Debt em 2023-01

⏰ Tempo Integral

🟢 Júnior

🟡 Pleno

🧐 Analista de Negócios

🗣️🇺🇸🇬🇧 Inglês obrigatório