Vulnerability Management Analyst

1 Month ago • 5 Years + • Cyber Security

Job Summary

Job Description

The Vulnerability Management Analyst role within ION’s central services division supports the Group Security strategy by identifying, mitigating, and remediating information security vulnerabilities, misconfigurations, and risks. This global role reports to the Vulnerability Management Manager. The analyst will build and lead a team of Security professionals specializing in Vulnerability Management, manage partner and vendor deliverables, and develop a world-class Vulnerability Management program. Key activities include discovery scanning, risk/exposure assessments, mitigation support, continuous validation, and process improvement. The ideal candidate is diligent, dedicated, creative, motivated, possesses excellent communication skills, and has at least 5 years of cybersecurity experience with a focus on Vulnerability Management.
Must have:
  • Minimum 5 years of experience in Vulnerability Management
  • Excellent communication skills (written and verbal)
  • Strong technical expertise in vulnerability prioritization
  • Knowledge of Vulnerability Management frameworks (NIST/SANS)
  • Ability to work independently and manage time effectively
  • Exceptional attention to detail and quality
  • Problem-solving and trouble analysis skills
Good to have:
  • Security+ , CCSP, CEH, GCIH, GMON, CASP, or CISSP certifications
  • Experience building a global Vulnerability Management program
  • Experience with risk management frameworks
  • Experience in designing and publishing Security Standards & Policies
  • Experience running global Bug Bounty/VDP programs
  • Experience in Pen Testing
  • Knowledge of Vulnerability Management tools (Tenable/Rapid7/Qualys)
  • Knowledge of Cloud Security compliance (IaaS, PaaS, SaaS)
  • Knowledge of general IT networking and security concepts
  • Forensic investigation techniques experience
  • Experience with security technologies (AV/EPP/EDR, SIEM, DLP, etc.)
  • Knowledge of compliance and regulatory practices

Job Details

The Role:

The Vulnerability Management Analyst is a global role within ION’s central services division and will support the Group Security strategy and operational excellence through the identification, mitigation and remediation of information security vulnerabilities, misconfigurations and risks to the business. This role reports to the Vulnerability Management Manager who reports to the Global Head of IT Security.

As a member of the ION Security team, you will build and lead a team of Security professionals specialising in Vulnerability Management along with managing the partners and technology vendor deliverables and of course building and owning the strategy to deliver a world class Vulnerability Management program. The candidate must understand their role in the broader vulnerability management program and your team will regularly perform discovery scanning, risk/exposure assessments, mitigation support activities, continuous validation assessments, and lessons learned workshops and improvement projects to continuously improve our process across Group Security and all other Verticals.

We are looking for a diligent, dedicated, creative and motivated individual. Excellent communication skills are a must, and the role holder will be expected to cultivate working relationships with other teams and colleagues of varying technical ability. The role would suit a technically strong candidate with an extensive cybersecurity background, at least 5+ years working in a security role, with focus on Vulnerability Management.

Responsibilities:
  • This role may require work-out of hours in support of 24x7 globally coordinated operation
  • The primary responsibilities of this role are to:

  • Personnel Management
  • Align deliverables and objectives to OKRs
  • Be the escalation point for security Tooling issues and critical security breaches

  • Protect and defend:
  • Manage Vulnerability Management tooling to ensure coverage/availability/efficacy
  • Drive improvements and feature enhancement to ensure ROI

  • Operate and maintain:
  • Configure, tune, maintain & operate key vulnerability management controls
  • Management reporting – real-time metrics and scheduled reports
  • Drive process/procedure changes accordingly
  • Ensure quality of ticketing & runbook maintenance
  • Cultivate and maintain strong vendor relationships
  • Have an attitude of continuous improvement
  • Participate in CAB, Tool review or Architecture Review Boards (ARBs)

  • As a member of the ION IT Security Team, it is expected that the person in this role will:
  • Execute ongoing, operational business-as-usual (BAU) tasks to meet management-defined KPIs and SLAs, and deliver security projects in line with management-defined priorities and deadlines
  • Stay current with the latest security news, threats, intelligence, tactics, techniques, and vulnerabilities. Research and analyze new threats and vulnerabilities to determine exposure.
  • Assist and/or lead efforts to isolate, contain, respond to, and recover from security incidents
  • Identify, review, prioritize, plan, coordinate, and follow-up on the remediation of vulnerabilities
  • Define, document, and follow approved processes for all the responsibilities included in this job description. Create and maintain documentation for systems, including design and operation
  • Review vulnerability management systems, configurations, and processes to ensure and report on compliance with ION policy, client requirements, audit controls, regulations, and industry best practices. Provide best practice security recommendations to IT and other teams within ION, based on review results

Experience, Skills and Qualifications:
  • Degree/diploma/certifications in a technology-related field and/or relevant working experience; highly desired certifications include:
  • Security+, CCSP, CEH, GCIH, GMON, CASP, or CISSP
  • Minimum of 5 years’ experience in Vulnerability Management within large organizations
  • Excellent track record of building a Vulnerability Management program on a global scale with knowledge on vulnerability assessments, remediation and mitigation activities
  • Technical Security/Engineering/Compliance background with a previous track record of building risk management framework and applying to an existing vulnerability management program
  • Strong technical expertise in implementing a Prioritization formula to vulnerabilities and misconfigurations and translating these into risks
  • Excellent knowledge of Vulnerability Management frameworks such as NIST/SANS

  • The following general characteristics are required:
  • A team player with the ability to work independently and unsupervised
  • Ability to own delegated tasks and see them through to completion
  • Ability to manage time and prioritize work to maximize productivity
  • Excellent reporting and presentation skills are essential for this role
  • Excellent communication skills (both written and verbal)
  • Exceptional attention to detail and quality
  • Excellent problem-solving techniques and trouble analysis skills
  • Experience in design and publishing Security Standards & Policies
  • Experienced in running global Bug Bounty/VDP programs
  • Experienced in Pen Testing, from scope, schedule, findings, remediation and risk registration

  • The candidate should have a good knowledge of:
  • Vulnerability Management concepts, controls, and best practices for all Operating systems & asset types, (e.g. workstations, endpoints, mobile, servers either Windows/Linux, cloud instances, etc.)
  • Vulnerability Management tools (Tenable/Rapid7/Qualys)
  • Cloud Security compliance (IaaS, PaaS, SaaS) and misconfigurations
  • Multi-platform endpoints, infrastructure and XaaS vulnerability management deployments
  • General IT networking concepts, protocols, standards and network security concepts, controls, and best practices
  • Forensic investigation techniques
  • Prior experience deploying, configuring, managing, and/or operating security technologies is preferred, such as endpoint security (e.g. AV/EPP/EDR), SIEM, DLP, SWG, CASB, UEBA, IDS, IPS, firewalls, IAM/PIM/PAM, Vulnerability Management, MDM, etc.
  • Proven knowledge of compliance, regulatory practices and experience managing audits

About us:

We’re a diverse group of visionary innovators who provide trading and workflow automation software, high-value analytics, and strategic consulting to corporations, central banks, financial institutions, and governments. Founded in 1999, we’ve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world.

• Over 2,000 of the world’s leading corporations, including 50% of the Fortune 500 and 30% of the world’s central banks, trust ION solutions to manage their cash, in-house banking, commodity supply chain, trading and risk.

• Over 800 of the world’s leading banks and broker-dealers use our electronic trading platforms to operate the world’s financial market infrastructure.

ION is a rapidly expanding and dynamic group with 13,000 employees and offices in more than 40 cities around the globe. Our ever-expanding global footprint, cutting edge products, and over 40,000 customers worldwide provide an unparalleled career experience for those who share our vision.

ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities, abilities, cultures, and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business.
ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.

Similar Jobs

Fortra - Website Marketing Manager

Fortra

Canada (On-Site)
1 Day ago
Ambient.ai - Senior Product Manager

Ambient.ai

Redwood City, California, United States (Hybrid)
6 Months ago
Harvey - Software Engineer, Backend

Harvey

San Francisco, California, United States (On-Site)
4 Days ago
Sprinkler - Lead Sales Operations Analyst

Sprinkler

Bengaluru, Karnataka, India (On-Site)
1 Year ago
Telnyx - Developer Support Specialist

Telnyx

Amsterdam, North Holland, Netherlands (On-Site)
2 Months ago
Plaid  - Software Engineer - Security Engineering

Plaid

New York, United States (On-Site)
4 Days ago
Wolters Kluwer - Sr. IT Security Analyst (IAM Operations + Cyberark)

Wolters Kluwer

Pune, Maharashtra, India (On-Site)
1 Month ago
Tide - Staff Backend Engineer - DevEx, Security and Technology Foundations

Tide

Sofia, Sofia City Province, Bulgaria (Hybrid)
2 Months ago
endava - Senior Information Security Engineer

endava

Córdoba, Córdoba Province, Argentina (Remote)
2 Months ago
Capgemini - SWSS Security Engineer

Capgemini

Gurugram, Haryana, India (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Publicis Groupe - Account Manager III (Strategic)

Publicis Groupe

Boston, Massachusetts, United States (Remote)
3 Days ago
Zenoti - Director - Contract Renewals (Customer Success)

Zenoti

Seattle, Washington, United States (On-Site)
2 Months ago
Sprinkler - Sr. Helpdesk Analyst

Sprinkler

New York, New York, United States (On-Site)
1 Month ago
Glean - Cloud Infrastructure Engineer

Glean

Palo Alto, California, United States (Hybrid)
2 Months ago
GoMotive - Senior Enablement Specialist - SMB SDR Inbound

GoMotive

Lahore, Punjab, Pakistan (Remote)
2 Months ago
Axel springer - Intern:in Consulting (m/w/d) - Pricing and Sales

Axel springer

Berlin, Berlin, Germany (Hybrid)
1 Year ago
GoMotive - Account Executive, Enterprise

GoMotive

United States (Remote)
2 Months ago
EveryMatrix - Product Designer

EveryMatrix

London, England, United Kingdom (Hybrid)
2 Months ago
Interface AI - Event Marketing Manager

Interface AI

California, United States (On-Site)
1 Day ago

Get notifed when new similar jobs are uploaded

Jobs in London, England, United Kingdom

Moloco - Growth Manager (Russian Speaking)

Moloco

London, England, United Kingdom (On-Site)
3 Weeks ago
Hawkeye Innovations - Delivery Manager

Hawkeye Innovations

Basingstoke, England, United Kingdom (On-Site)
4 Months ago
Critical mass - Senior Product Engineer - 3D

Critical mass

London, England, United Kingdom (On-Site)
3 Weeks ago
ClearPoint Recruitment - Senior Recruitment Consultant

ClearPoint Recruitment

Darlington, England, United Kingdom (On-Site)
5 Years ago
4j studios - QA Tester

4j studios

Dundee, Scotland, United Kingdom (On-Site)
1 Month ago
Epic Games - Senior UI Programmer

Epic Games

London, England, United Kingdom (On-Site)
5 Months ago
Foster and partners  - Senior Structural Engineer

Foster and partners

London, England, United Kingdom (On-Site)
3 Weeks ago
Cloud Imperium Games - Senior AI Programmer

Cloud Imperium Games

Manchester, England, United Kingdom (On-Site)
5 Months ago
Playground Games - Senior Character Artist

Playground Games

Royal Leamington Spa, England, United Kingdom (Hybrid)
1 Year ago
Monzo - Disputes Expert

Monzo

United Kingdom (Remote)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Grammarly - Security Intelligence Engineer

Grammarly

San Francisco, California, United States (Hybrid)
1 Week ago
Optiv - Client Director - Cybersecurity Sales

Optiv

San Francisco, California, United States (On-Site)
1 Month ago
Morning Star - Lead Security Engineer

Morning Star

Chicago, Illinois, United States (Hybrid)
1 Year ago
Canonical - Senior Security Operations Engineer

Canonical

(Remote)
2 Months ago
Vercel - Software Engineer, CDN Security

Vercel

United States (Remote)
2 Months ago
bytedance - Senior Software Engineer - Network Security

bytedance

San Jose, California, United States (On-Site)
5 Months ago
binance - Web3 Security Senior Software Engineer

binance

Taipei City, Taiwan (Remote)
7 Months ago
Jane Street - Cybersecurity Governance and Risk Specialist

Jane Street

London, England, United Kingdom (On-Site)
2 Months ago
Lambda - Staff Security Engineer

Lambda

San Francisco, California, United States (Hybrid)
3 Weeks ago
PayPal - Manager, Cybersecurity Risk

PayPal

San Jose, California, United States (On-Site)
1 Week ago

Get notifed when new similar jobs are uploaded

About The Company

We’re visionary innovators who are delivering mission-critical trading and workflow automation software to financial institutions, corporations, central banks, and governments. By combining our passion for automation with a strategic view on the industries we serve, we design solutions that improve decision-making, simplify complex processes, and empower people. Simply put, we help our customers do more, faster and better than before. We believe our investments in research and development are shaping the future of automation and enabling our customers to transform their business. And we embrace the power of community, working with each other and with our customers to succeed through a positive culture of continuous improvement.

Budapest, Hungary (On-Site)

Jersey City, New Jersey, United States (On-Site)

New York, United States (On-Site)

Budapest, Hungary (On-Site)

New York, United States (On-Site)

Dubai, Dubai, United Arab Emirates (Hybrid)

Noida, Uttar Pradesh, India (On-Site)

Mumbai, Maharashtra, India (On-Site)

Budapest, Hungary (On-Site)

London, England, United Kingdom (Hybrid)

View All Jobs

Get notified when new jobs are added by Ion

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug