Senior Vulnerability Analyst - Cyber Security (FTC 12 months)
Role details
Job location
Tech stack
Job description
A Senior Technical Vulnerability Analyst is responsible for identifying, evaluating, and assisting in fixing security vulnerabilities and misconfigurations in a system or network. You will have a strong understanding of vulnerability management processes and tools for performing assessments and remediation activities. You will also work closely with business and technology stakeholders and product owners in other IT and security teams to ensure that systems are secure and compliant with relevant regulations and standards. What you'll do Work with internal and external resources to coordinate the remediation of identified vulnerabilities and misconfigurations across various platforms and environments. Develop and implement effective remediation strategies and solutions. Work as part of a vulnerability scanning team to identify, prioritise and address high-risk vulnerabilities and misconfigurations Collaborate extensively with IT operations, development teams, and security architects to ensure effective vulnerability and misconfiguration mitigation. Collaborate with different business units, security leads, and Business Information Security Officers (BISOs) to align remediation efforts with broader business objectives and security policies. Develop and maintain documentation, including remediation guides and playbooks. Manage and track remediation efforts, ensuring timely closure and compliance with security policies and standards. Communicate effectively with senior stakeholders regarding the status of remediation efforts - including the development, maintenance and continuous improvement of regular, accurate and clear metrics. Support incident response activities related to vulnerabilities when required. Stay updated on emerging threats and adapt remediation strategies accordingly. What you'll bring: Experience in vulnerability remediation and mitigation in complex IT environments. Experience of secure configuration scanning and mitigation/remediation in line with industry standard hardening benchmarks (e.g. CIS) Experience in broader Application & Infrastructure Security domains. Strong understanding of various operating systems, applications, and network infrastructures. Solid understanding on Vulnerability scanning tools (preferably Tenable) as well as opensource discovery tooling e.g. Nmap. Experience in scripting and automation to streamline remediation processes. Experience of consistently producing accurate and clear remediation compliance metrics for senior stakeholders.
Requirements
Excellent collaboration and communication skills, with the ability to work across various teams and organizational levels. Evidence of Cyber Security relevant qualifications, training or accreditations (e.g. CISSP, CISM, CompTIA Security+) and/or experience with common Cyber Security benchmarks and frameworks (e.g. ISO 27001, NIST 800-53, Center for Information Security [CIS] Benchmarks) Team overview