Deliver - efficiently
? Triage publicly disclosed vulnerabilities of vendor software/hardware products
? Identify prioritize and draft mitigation guidance for vulnerabilities impacting FIL.
? Develop remediation plan along for identified vulnerabilities with platform and application teams
? Monitor and report the progress on agreed remediation plans.
? Continuously expand and rationalize the vulnerability scan coverage.
? Conduct open source research to identify and analyze known and unknown vulnerabilities
? Analyze known issues with vendor fixes and contact vendor for solution
? Represent team in different forums.
? Engage - productively
? With stakeholders for information gathering, sharing and increasing awareness about VM best practices
? Work with platform / application teams at regular basis to increase sensitivity for addressing vulnerabilities
? Work proactively with IT Infrastructure partners with for strategic and tactical plans for remediating vulnerabilities
? Communicate with Subject Matter Experts to determine expected impact and likelihood of loss events
? Publish easy to understand reports and dashboards.
Experience Required
? 3+ years of diverse experience in cyber security vulnerability assessments, or equivalent combination of education and work experience.
? Experience with applying knowledge of Common Weakness Enumeration (CWE), Common Vulnerability Scoring System (CVSS), Common Vulnerabilities and Exposures (CVE) while analysing vulnerabilities and applying contextual risks to the organization under consideration.
? Understanding of lifecycle of cyberspace threats, attack vectors, and exploitation methods.
? Knowledge of IT Security best practices and standards (such as CIS, PCI DSS, etc.).