Senior IT Security & Vulnerability Analyst

  • Posted 4 hours ago | Updated 4 hours ago

Overview

On Site
Full Time

Skills

AIM
Information Security
IT Infrastructure
Security Engineering
Incident Management
Strategic Management
Bloomberg
Partnership
Cloud Computing
Workflow
Reporting
IT Operations
Systems Management
Vulnerability Scanning
Information Engineering
Internet Explorer
Qualys
Nessus
Nmap
Enterprise Networks
System Administration
IT Security
Operating Systems
Microsoft Windows
Unix
Linux
Web Applications
Network
Software Development Methodology
Vulnerability Management
Security Management
Management
Risk Management
Scrum
PMP
Hardening
TLS
Secure Shell
Web Servers
Database
Apache HTTP Server
Continuous Integration
Continuous Delivery
Relational Databases
MySQL
PostgreSQL
Computer Science

Job Details

Our Team:
The Threat and Vulnerability Management Team (TVM) is dedicated to making our systems and technologies as secure as possible. We protect Bloomberg. We partner with internal technical departments to ensure the confidentiality, integrity, and availability of Bloomberg systems and the data we process. We aim to ensure that our clients see us as a trusted partner.

We report to the Chief Information Security Office (CISO) who owns the technical aspects of this mission by ensuring Bloomberg products, systems, networks and commercial applications are built and maintained with security in mind.

We work on purpose. Come find yours.

What's The Role?
We are seeking an IT Security Analyst to help ensure that our IT infrastructure and security processes are resilient against the latest threats. You will be responsible for analyzing and assessing vulnerabilities across a wide range of technologies. You'll engage with various technology partners to validate and manage identified vulnerabilities through remediation. You will work directly with other cross-department security engineering and incident response teams to set strategic direction for our enterprise Threat and Vulnerability Management program.

This is a team that drives company-wide initiatives to improve the effectiveness of Bloomberg's security posture. Analysts in this role must show exemplary judgment in making technical decisions to achieve business goals. You're expected to always demonstrate resilience and navigate difficult situations with composure and tact.

We'll Trust You To:
- Perform IT Security assessments and partner with other security or IT professionals to assess potential impact from vulnerabilities and determine appropriate mitigating controls
- Build strong partnerships with technical teams to promote best practices for managing vulnerabilities across traditional infrastructure and in cloud environments
- Understand business requirements and work with business partners to define appropriate solutions; meeting both security mandates and business needs
- Help standardize workflows, processes, procedures and reporting
- Produce metrics and key performance indicators that demonstrate the effectiveness of the team's remediation efforts across the enterprise
- Improve the design and usefulness of our IT Security management tools and solutions.
- Have excellent interpersonal and effective communications skills

You'll Need to Have:
- 7+ years IT Security experience including IT Operations & Systems Management
- Operation vulnerability scan tools (ie: Rapid7, Qualys, Nessus, Nmap)
- Hands-on expertise working with enterprise network architectures, Linux and Windows OS, system administration or as a software developer
- Knowledge of IT security and system hardening best practices; including but not limited to operating systems (Windows, Unix, Linux), web applications, network devices and SDLC processes
- Vulnerability Management of Regulated Systems
- Experience analyzing vulnerability findings from IT and Security management tools
- Understanding of industry standards such as NIST, CVE, CPE and CVSS
- Ability to interpret complex data sets to make informed risk-based decisions
- Can effectively manage complex tasks, projects, and initiatives

We'd love to see:
- Solid understanding of Risk management frameworks and security tools
- SCRUM Master Certification / PMP Certified
- Experience with hardening TLS & SSH configurations across Web Servers, Databases and APIs.
- Understanding in patching 3rd Party software and its prerequisites such as Apache HTTPD, CI/CD tools, Relational Databases (MySQL, PostGres), etc.
- Ability to learn and implement technologies quickly
- A Bachelor's degree in Computer Science, Engineering, or other related fields
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.