OVERVIEW AND REPORTING RELATIONSHIP
This analyst will be a member of the Exposure Management team and will report to the Cybersecurity Manager. This position will be responsible for various technical cybersecurity analyst functions, including vulnerability management, attack surface management, cloud security, as well as providing network and endpoint security support.
REPORTING STRUCTURE & WORK SETTING
Global Business Center - Manila position, within the IS Threat Management Team, under the Cybersecurity Manager, within the Tenet Corporate Cybersecurity organization.
RESPONSIBILITIES
Vulnerability Management
- Perform scheduled security vulnerability assessments across global applications and infrastructure.
- Manage, coordinate, and track vulnerabilities from discovery, triage, remediation, and validation.
- Document, prioritize and formally report asset and vulnerability state, along with remediation recommendations and validation.
- Coordinate, schedule, and manage the engagement process (with internal stakeholders and third-party vendors) for vulnerability remediation activities.
- Formally document and establish well-defined processes, procedures, remediation and mitigation strategies, and lessons learned.
- Manage vulnerability related tickets to ensure issues are remediated within designated timelines.
- Provide vulnerability mitigation strategies and meaningful vulnerability metrics.
- Support the maintenance and operations of vulnerability assessment infrastructure through refresh initiatives and annual planning.
- Report on findings and respond to requests and known vulnerabilities as well as delivering ad-hoc vulnerability scans on request.
- Coordinate emergency vulnerability patching, including remediation efforts.
- Conduct research and provide feedback to leadership and Cybersecurity team members of the recommended actions for vulnerability scan findings.
- Leverage vulnerability database sources to understand each weakness, its probability and remediation options, including vendor-supplied fixes and workarounds.
- Provide support of maintenance and operations to the vulnerability assessment toolsets.
- Provide support to internal processes to ensure compliance with the Payment Card Industry (PCI) standard.
- Support internal and external auditors in their duties that focus on compliance and risk reduction.
- Collaborate with security groups such as red teams, threat intelligence and risk management to form a holistic team dedicated to thwarting attackers and reducing attack surface.
- Work closely with infrastructure teams to advise and support remediation efforts to close vulnerability exposure to new threats in the wild and verify the organization’s security posture against them.
- Regularly research and learn new TTPs in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary.
- Maintain an active database comprising third-party assets, their vulnerability state, remediation recommendations, overall security posture and potential threat to the business.
- Define key performance indicators (KPIs) and metrics across business units to illustrate effectiveness with vulnerability management.
- Understand breach and attack simulation solutions for known vulnerabilities and work with the team to validate controls effectiveness.
- Liaise with the security engineering team to improve tool usage and workflow, as well as with the advanced threats and assessment team to mature monitoring and response capabilities.
REQUIRED KNOWLEDGE AND EXPERIENCE: Please describe the minimum education, technical training and/or experience required to perform this job (formal education, relevant work experience, ability to perform specific tasks, certification, skills, etc.).
QUALIFICATIONS
- Information Systems (IS) security professional with a broad range of knowledge in vulnerability and endpoint security systems/processes.
- Intermediate or advanced understanding in information security administration, vulnerability assessment and management, or security operations.
- Intermediate or advanced understanding of advanced threat detection in an enterprise environment.
- Intermediate or advanced understanding of malware families, their types, and threats they pose.
- Strong technical background in vulnerability assessment tools, as well as network and endpoint security best practices.
- Demonstrated ability in identification of vulnerabilities/threats to data, systems and networks.
- Comprehension of end-to-end vulnerability management workflow to include industry standards such as CVE, CPE, MITRE Attack Framework, and CVSS.
- Preferred experience with vulnerability management in both on-premise and cloud provider platforms.
- Experience in conducting organization-wide vulnerability scanning and remediation processes.
- Knowledge of compliance standards such as Payment Card Industry (PCI), National Institute of Standards (NIST), and/or International Standards Organization (ISO).
- Fluency in speaking and communicating in English.
EDUCATION AND WORK EXPERIENCE
- Minimum three years of experience
- BS in Computer Science or equivalent field.
- Preferred education and/or experience: Relevant industry recognized certifications (CISSP, CompTIA Security+,
- CEH, GIAC, Security+, etc.)
SPECIALIZED KNOWLEDGE, SKILLS & ABILITIES:
- Effectively communicate security goals effectively with other departments.
- Ability to work within an environment of frequently changing priorities.
- Knowledge of industry trending threats, security tools, and best practices.
- Proven ability in the performance of information security risk assessments.
- Experience in performing risk and compliance assessments of new and existing solutions.
- Ability to provide guidance and recommended remediation or alternative solutions for both internal and external supported environments.
- Ability to provide guidance in the identification, documentation and rating of threats/vulnerabilities, and remediation steps recommended to reduce risks to data, systems and networks.