Responsibilities:
Vulnerability Assessment and Management:
Serve as the Subject Matter Expert on vulnerability management in infrastructure & application security domain.
Identify and prioritize active critical vulnerabilities for remediation based on risk-based approach and/or business risk appetite.
Coordinate with local Entity Security team, and IT team for identified vulnerabilities, detected through vulnerability management process.
Analyzing structured and unstructured datasets from various sources to analyses vulnerabilities and produce remediation recommendations.
Provide technical advisory to IT Production and/or Application Teams to effectively remediate vulnerabilities.
Recommend compensatory measures when remediation is not possible and ensure that the risk acceptance process is followed accordingly.
Track, follow up and document the status of all vulnerabilities and updates in the registry.
Ensure timely follow up for remediation of vulnerabilities and assess the risk impact according to internal risk methodologies and framework.
Assist in investigation of security issues by reviewing results from relevant alerts and other vulnerability identification method (vulnerability scanning, web apps security testing, etc.)