Description:
Title: Security Analyst, Vulnerability & Risk Management
Location: Indianapolis, IN
Responsibilities:
•Establish relationships with internal and external customers and partner with them to monitor and maintain security controls across corporate and business applications and devices.
•Interact with customers or other stakeholders to aid in the resolution of vulnerabilities that have been identified.
•Assist in defining and continually improving vulnerability risk management requirements for global IT support organizations.
•Develop processes and/or Improve processes related to vulnerability risk management. This includes working with various platform or application teams to ensure their portfolio includes VRM deliverables.
•Collaborate with our team to conduct vulnerability assessment and monitoring services across applications and devices that are in scope of the services, including leading continuous improvement efforts over time in response to customer feedback and internal reviews.
•Collaborate with business units to identify and implement VRM operational needs and assist with remediation coordination efforts.
•Resolve technical issues escalated from the SOC as they relate to various components of the VRM services.
•Technical SME for the VRM tools used to perform scans on global devices and applications.
•Triage newly identified critical vulnerabilities and Zero-Day vulnerabilities, assess threat and impact information, manage escalation process for remediation based on risk.
•Continuously improve the processes and procedures to include reporting exceptions for further review including escalation to the appropriate risk owners.
•Coordinate with the threat intelligence team and SOC to drive key vulnerability initiatives.
•Interact with stakeholders to develop and fine-tune the process of how metrics are calculated and communicated.
•Provide written and oral communication as appropriate to the information security manager related to VRM quantitative metrics, reporting and analysis.
•Follow departmental change management process to ensure appropriate implementation of metrics and reporting capabilities.
•Lead services to integrate static and dynamic application security testing into the SDLC to ensure new applications or applications undergoing a major change are assessed for vulnerabilities prior to production implementation.
•Lead services to integrate Policy compliance scanning and vulnerability scanning solutions into device implementation processes
•Integrate internal business intelligence of high value assets into VRM tools.
Qualifications:
•IBM Appscan
•HP fortify
•Burpsuite
•Acunetix
•Checkmarx
•Comprehensive knowledge of application vulnerability management identification, analysis, metrics and reporting tools as well as processes enabling proper governance, risk and compliance.
•Working knowledge of ITIL and experience working with IT services.
•Strong written and communication skills.
•Data analysis and problem resolution. Must be able to integrate and correlate large amounts of data to identify complex patterns and trends.
•Applying good risk-based judgment to complex problems.
•Evaluation of threats and risk to business operations resulting in security solutions that appropriately balance cost and risk mitigation.
•IT Infrastructure solutions such as an Networking & Telecommunications, System Administration (Windows, Linux, UNIX, Mac OS X, iOS), Database ( Oracle, SQL Server, MySQL), Web Servers (Apache, MS IIS), Web application (.Net, JAVA, Cold Fusion, PHP, Node.js, Rube on rails) and authentication / access control technologies ( MS Active Directory, LDAP)
•Experience in assessing the risk of a proposed solution, escalating appropriately and driving to closure
•Ability to think analytically and to understand and communicate quantitative information
•Computer Science Degree