Cyber Security Vulnerability Analyst 2
Garmin Ltd
Olathe, KS, United States
8 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.jofdav.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source
Tech stack
JavaScript (Programming Language)
Microsoft Windows
C Sharp (Programming Language)
Cloud Computing
Cyber Security
Information Systems
Databases
Perl (Programming Language)
Information Security Management
Python (Programming Language)
Windows PowerShell
Security Information and Event Management
+6 more
Software Vulnerability Management
Scripting
Garmin
Information Technology
Data Analytics
Vulnerability Analysis
Job description
- Review/configure automated tools, analyze threat feeds, and monitor disclosure programs to identify/prioritize vulnerabilities
- Work with stakeholders to help determine/implement remediation timelines/plans and is tasked to execute/align remediation plans based on experience and available data on Garmin risks
- Operate independently to configure and perform vulnerability scanning and assessments to support the identification, analysis, and remediation of risk to networks, operating systems, applications, and other information system components
- Responsible for reviewing/configuring automated tools, analyzing threat feeds, and monitoring disclosure programs to identify and prioritize vulnerabilities
- Work with stakeholders to help determine and implement remediation timelines/plans
- Independently analyze results from internal/external vulnerability scans and charged with using experience and skills to prioritize risk-based remediation plans
- Coordinate/establish proper scan timelines to avoid service interruption, ensuring complete and accurate results are achieved
- Establish strong relationships with business stakeholders to facilitate prioritization and timely remediation
- Develop metrics/timelines in support of the monitoring of vulnerability management program health
- Work with Cyber Security, System Administration, and System Owners to establish vulnerability mitigations and plans of action
- Independently build performance metrics that provide advanced and detailed views of remediation performance
- Ensure that external vulnerability disclosures are assigned to the proper teams and facilitates communications with vulnerability reporters and finders
- Analyze compliance requirements and develop scanning plans and procedures to test and report on results
- Coordinate efforts with compliance teams to develop vulnerability and scanning processes in support of governance/compliance requirements
- Perform system administration activities on vulnerability management systems and applications
- Communicate in written and verbal form effectively in a large team or departmental setting
- Authorized to formulate remediation plans and timelines following vulnerability scans using input from system owners
- Establish/create vulnerability documentation mitigations and remediations
- Develop, create, and provide reports of vulnerability scan results that are in a consumable/consistent format
- Help establish/track compliance with vulnerability management policies, standards, and procedures
- Demonstrate proficient use and knowledge of standards and procedures
- Understand vulnerability tool configurations and be able to provide guidance or remediation
Requirements
- Bachelor’s Degree in Computer Science, Information Technology, Management Information Systems, Business, or related field AND a minimum of 1 year relevant experience OR equivalent combination of education and relevant experience
- Possess analytical skills and strong ability to maintain composure and remain diplomatic under highly stressful situations
- Familiarity with Common Vulnerability Scoring System CVSS framework, National Vulnerability Database (NVD)
- Strong multitasking skills to be able to effectively manage multiple activities, including cross-team dependent activities simultaneously
- Consistently demonstrates quality/effectiveness in work documentation and organization
- Demonstrated ability/effectiveness to exercise strong and effective verbal, written, and interpersonal communication skills in a small team setting
- Must be team-oriented, possess a positive attitude and work well with others
- Familiarity with defensive security techniques and implementation of mitigating security controls, * Working experience with automated vulnerability scanning tools, to include implementation, configuration, maintenance
- Information security related experience, in areas such as: security operations, incident analysis, incident handling, system patching, and end point protection
- Experience with vulnerability scanning in cloud-based environments, to include security posture management
- Ability to work in a fast paced, dynamic environment
- Experience with NIST 800-53 and/or NIST Cyber Security Framework (CSF)
- Familiarity information and event management (SIEM) Platforms
- Experience with BI tools for data analytic reporting and KPIs
- System administration experience: Windows and Linux/Unix Scripting OR development experience (Python, JavaScript, PowerShell, C#, Perl)
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.jofdav.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
EM
Eli McGarvie
Highest Paying Tech Companies for Developers
over 3 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
EM
Eli McGarvie
Data Analyst Salary in the UK
about 3 years ago