Senior Information Security Specialist - Vulnerability Management
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+22 more
Job description
We use cookies to offer you the best possible website experience. Your cookie preferences will be stored in your browserās local storage. This includes cookies necessary for the websiteās operation. Additionally, you can freely decide and change any time whether you accept cookies or choose to opt out of cookies to improve websiteās performance, as well as cookies used to display content tailored to your interests. Your experience of the site and the services we are able to offer may be impacted if you do not accept all cookies. Modify Cookie Preferences Reject All Cookies Accept All Cookies Search Jobs, The role serves as the primary liaison between Global stakeholders and the Vulnerability Management team. Managing security assessments, penetration testing, remediation tracking, reporting, and security governance activities to reduce cyber risk and strengthen the organizationās security posture. Providing vulnerability assessments to the Amway businesses globally through a comprehensive testing process. Someone that is comfortable in identifying, assessing, prioritizing, and driving the remediation of security vulnerabilities. Looking for a candidate that is team player, collaborative, analytical, persistent and comfortable challenging the status quo. What Youāll Do: As a senior-level contributor, the individual is expected to evaluate emerging security technologies, mentor others, influence stakeholders, and champion continuous improvement initiatives. Stay informed on evolving threats and leverage AI-assisted security capabilities, automation, and advanced analytics to improve vulnerability management, penetration testing, and security operations outcomes. Additionally, they help assess and govern risks associated with internally developed and externally sourced solutions, ensuring secure adoption and alignment with enterprise security standards.
Requirements
- BA/BS Degree in Computer Science, Computer Science Engineering, Information Security, or related field
- Good working knowledge of large and mid-range operating systems and related security software in a large, complex, multi-server, multi-protocol environment.
- Strong knowledge of application security concepts including OWASP Top 10, SAST, DAST, SCA, secret scanning, API Security, secure code review practices, and Secure Software Development Lifecycle (SSDLC).
- Attention to detail
- Good customer service orientation
- Good written and oral communication and interpersonal skills
Skills to be successful in the role:
- Strong understanding of vulnerability management, risk assessment, remediation lifecycle management, and vulnerability prioritization frameworks.
- Experience coordinating vulnerability assessments, penetration testing, red team exercises, and security reviews across application, infrastructure, cloud, API, endpoint, and container environments.
- Working knowledge of Java, .NET, Python, JavaScript/TypeScript, cloud-native architectures, DevSecOps, CI/CD pipelines, source code repositories, build automation, containers, Infrastructure-as-Code (IaC), and deployment platforms.
- Knowledge of infrastructure, cloud, network, endpoint, and container security principles.
- Experience administering, automating, and optimizing vulnerability management and application security tools, including Tenable, Invicti, GHAS, Prisma Cloud, SonarQube, Veracode, Checkmarx, or equivalent platforms.
- Strong analytical, problem-solving, stakeholder management, communication, and collaboration skills, with experience validating findings, assessing risk, driving remediation against SLAs, influencing cross-functional teams, and recommending effective mitigation strategies.
- Experience preparing security metrics, dashboards, executive reporting, and risk summaries; supporting audit, regulatory, compliance, and cyber insurance requirements; and evaluating emerging security technologies.
- Knowledge of AI-assisted security assessment capabilities, AI security risks, governance, and secure AI lifecycle practices, including the use of automation and AI to improve security operations and mitigate risks associated with internal and third-party AI solutions.
- Familiarity with Agile methodologies and continuous improvement practices.
Benefits & conditions
Actual compensation packages are based on a wide array of factors unique to each candidate, including but not limited to skill set, years & depth of experience, certifications and specific office location. This may differ in other locations due to cost of labor considerations., + $118,248-130,696 per year
About the company
Information at a Glance Helping People Live Better Lives Amway is based in Ada, Michigan, U.S.A., with global headquarters still located on the same property where the company was founded. Family-owned and guided by enduring values, we continue to be shaped by our Founders Fundamentals. Since 1959, our heart has remained the same: helping people realize their potential. Today, that mission spans six continents and more than 100 countries and territories. Amway complies with the General Data Protection Regulation (GDPR) - the protection of personal data and digital privacy. Each of our affiliate locations have their own visa work permit and hiring and immigration policies, which may impact the ability to consider applicants who need authorization to work in a particular country. Ć Cookie Consent Manager When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. Because we respect your right to privacy, you can choose not to allow some types of cookies. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer. Required Cookies These cookies are required to use this website and canāt be turned off. Required Cookies Show More Details Required Cookies Provider Description Enabled SAP as service provider We use the following session cookies, which are all required to enable the website to function:
- ārouteā is used for session stickiness
- ācareerSiteCompanyIdā is used to send the request to the correct data center
- āJSESSIONIDā is placed on the visitorās device during the session so the server can identify the visitor
- āLoad balancer cookieā (actual cookie name may vary) prevents a visitor from bouncing from one instance to another
Cookies from provider SAPasserviceprovider are required and cannot be turned off Functional Cookies These cookies provide a better customer experience on this site, such as by remembering your login details, optimizing video performance, or providing us with information about how our site is used. You may freely choose to accept or decline these cookies at any time. Note that certain functionalities that these third-parties make available may be impacted if you do not accept these cookies. Consent to all Functional Cookies Show More Details Functional Cookies Provider Description Enabled YouTube YouTube is a video-sharing service where users can create their own profile, upload videos, watch, like, and comment on videos. Opting out of YouTube cookies will disable your ability to watch or interact with YouTube videos. Consent to cookies from provider YouTube Vimeo Vimeo is a video hosting, sharing, and services platform focused on the delivery of video. Opting out of Vimeo cookies will disable your ability to watch or interact with Vimeo videos.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role ā technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Walking Into The Era of Supply Chain Risks
9 Ways to Make Money Hacking
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Why Upskilling And Reskilling is Important For Developers