AVP, Vulnerability Management Analyst
Job Description
Role Summary/Purpose:
The AVP, Vulnerability Management Analyst will execute the work of the Synchrony (SYF) Vulnerability Management Team. This individual will enhance processes and drive efforts to identify, assess, and prioritize vulnerabilities for remediation. The AVP, Vulnerability Management Analyst will contribute towards process improvements including assessment of vulnerability risk, enhancement of metrics, development of documentation, and identifying opportunities for streamlining and automation. This position will also be responsible for executing the strategic direction set by the VP of Vulnerability Management.
We're proud to offer you choice and flexibility. You have the option to be remote, and work from home, or come into one of our offices. You may be occasionally requested to commute to our nearest office for in person engagement activities such as team meetings, training and culture events.
Essential Responsibilities:
The Vulnerability Management Team coordinates across all elements of the IT organization at all levels, including senior executives. This role requires experience in applied data analytics for information security, risk management, and VM. Responsibilities include:
- Coordinate the scanning and identification of vulnerabilities associated with hosts connected to the Synchrony network.
- Assist in the maintenance of all tools that are used in the scanning and identification of vulnerabilities, as well as the tools used to rationalize, consolidate, and apply additional contextual information.
- Support identification and assessment activities for specific emergency or priority vulnerabilities, guided by input from other elements of the firm such as cyber intelligence, and track remediation approaches.
- Maintain cooperative relationship with infrastructure, application, database, network, and desktop/laptop teams to drive remediation.
- Analyze vulnerability data and assist with the prioritization and remediation of the identified vulnerabilities commensurate to risk and the SYF vulnerability management standard.
- Understand vulnerabilities, their impacts, mitigation techniques, and document and articulate this understanding to various stakeholders.
- Update and develop security standards, procedures, and dataflow ETL pipeline documentation as required to meet new regulatory/audit/etc. requirements.
- Contribute to the improvement of the efficacy and efficiency of data driven SYF VM practices, including vulnerability identification/assessment/prioritization/remediation.
- Execute tasks in accordance with existing VM frameworks/policies/standards to ensure SYF VM maintains a minimum of industry best practices commiserate with organization's risk profile while also ensuring compliance with industry standards (e.g., PCI DSS).
- Assist in the collection of data and documentation in support of examinations/audits.
- Work with existing solution vendors (e.g., Qualys) as necessary; identify potential solutions.
- Perform other duties and/or special projects as assigned
Qualifications/Requirements:
- Master's degree and a minimum of 1 year of work in IT OR a Bachelor's degree and a minimum 2 years of work experience in IT OR in lieu of a degree, a High School Diploma/GED and minimum 3 years of work experience.
- Minimum of 2 years of experience in applied data analytics and engineering leveraging enterprise business intelligence and data analysis tools such as Tableau, PowerBI, and Excel.
- Minimum of 1 year of experience in vulnerability management and supporting tools such as Qualys, Tenable, or Nexpose.
Desired Characteristics:
- Data automation scripting and query languages such as Python, R, PowerQuery, VBA, and SQL are a plus.
- Deep knowledge of and experience in designing and maintaining ETL pipelines, development of business metrics, and identification of actionable data insights.
- Proficient knowledge of and experience in vulnerability management, risk management, information security, and use of Qualys Security platform tools.
- Excellent written and oral communication skills, to include ability to present detailed technical solutions to a non-technical audience.
- Self-starter with ability to work with only limited guidance/direction.
- Awareness of the latest cybersecurity trends and developments.
Eligibility Requirements:
- You must be 18 years or older
- You must have a high school diploma or equivalent
- You must be willing to take a drug test, submit to a background investigation and submit fingerprints as part of the onboarding process
- You must be able to satisfy the requirements of Section 19 of the Federal Deposit Insurance Act.
- New hires (Level 4-7) must have 9 months of continuous service with the company before they are eligible to post on other roles. Once this new hire time in position requirement is met, the associate will have a minimum 6 months' time in position before they can post for future non-exempt roles. Employees, level 8 or greater, must have at least 24 months' time in position before they can post. All internal employees must consistently meet performance expectations and have approval from your manager to post (or the approval of your manager and HR if you don't meet the time in position or performance expectations).
Legal authorization to work in the U.S. is required. We will not sponsor individuals for employment visas, now or in the future, for this job opening. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
Our Commitment:
When you join us, you'll be part of a diverse, inclusive culture where your skills, experience, and voice are not only heard-but valued. We celebrate the differences in all of us and believe that our individual, unique perspectives is what makes Synchrony truly a great place to work. Together, we're building a future where we can all belong, connect and turn ideals into action. Through the power of our 8 Diversity Networks+ , with more than 60% of our workforce engaged, you'll find community to connect with an opportunity to go beyond your passions.
This starts when you choose to apply for a role at Synchrony. We ensure all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
Reasonable Accommodation Notice:
- Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.
- If you need special accommodations, please call our Career Support Line so that we can discuss your specific situation. We can be reached at 1-866-301-5627. Representatives are available from 8am - 5pm Monday to Friday, Central Standard Time
Job Family Group:
Information Technology
Date Posted
12/21/2022
Views
8
Similar Jobs
IT Security Analyst, Sr - Southern Company
Views in the last 30 days - 6
The text describes a senior IT security analyst position at Southern Company a major US energy firm The role involves designing creative solutions and...
View DetailsBusiness Intelligence Analyst (Hybrid - Irvine, CA) - Safe-Guard Products International
Views in the last 30 days - 7
The job posting is for a Business Intelligence Analyst position at SafeGuard Products International The role involves business analysis project manage...
View DetailsInformation Security Analyst - NCR Corporation
Views in the last 30 days - 6
The job description is for a Cyber Defense Analyst at NCR Corporation responsible for investigating information security events developing and impleme...
View DetailsSr. Data Analyst/Engineer - Remote - Sharecare
Views in the last 30 days - 11
Sharecare is a digital health company that helps people manage their health They are seeking a Sr Data AnalystEngineer to contribute to a new platform...
View DetailsOral & Maxillofacial Surgeon - Atlanta Oral & Maxillofacial Surgery
Views in the last 30 days - 0
View Details