Vulnerability Analyst

  • Charlotte, NC
  • Posted 1 day ago | Updated 1 day ago

Overview

On Site
Depends on Experience
Accepts corp to corp applications
Contract - W2
Contract - Independent
Contract - 12 Month(s)

Skills

Accountability
Bash
Cloud Computing
Computer Networking
Continuous Improvement
Cyber Security
Database
Documentation
Facilitation
Information Security
Leadership
Linux Administration
Management
Microsoft Excel
Microsoft Power BI
Microsoft Windows
Nessus
Network
Nexpose
Operating Systems
Presentations
Python
Qualys
Regular Expression
Regulatory Compliance
Reporting
Scripting
ServiceNow
Symantec
System Administration
Unix
Virtual Machines
Virtualization
Vulnerability Management
Windows PowerShell
Writing

Job Details

Vulnerability Analyst

Charlotte - NC

Contract

$ 55/hr on C2C

Skills:

Vulnerability Assessment

Unix

Vulnerability Management

MS Windows

Python

Job Description:

The Vulnerability Analyst will support the configuration compliance program by developing configuration compliance policies, validating them with technology partners, implementing them via tooling, and ensuring consistently accurate scans and reports are generated. Will work on multiple technology products at one time and enable remediation of vulnerability and compliance findings.

The ideal candidate for this role will have a strong technical foundation in system administration (Unix or Windows), familiarity with networking and cyber security, and hands-on experience with infrastructure scanning tools such as Symantec, Qualys, Tanium, Tenable, etc. Cloud, container, and/or familiarity with python, bash, powershell and/or regex experience is a plus as well as the ability to develop scripts and run code. The candidate must be equally comfortable speaking with developers as well as infrastructure teams about vulnerabilities and configuration compliance.

The Vulnerability Analyst will be accountable for the identification, reporting and remediation of vulnerability and compliance findings within their area of responsibility.

Principal Expectations:

Assist in facilitating vulnerability and compliance scanning and reporting activities, as directed by senior team members, ensuring accurate & timely identification, reporting, and escalation.

Leverage vulnerability management reports and metrics, to drive remediation of vulnerabilities for specified areas of the environment

Communicate with Ally technology staff on vulnerability management and remediation of key vulnerabilities. Assist teams with understanding the vulnerability, possible remediations, and assist with false positives or mitigation solutions.

Identify enhancements to tools, standards, and processes to enable continuous process improvement and automation of existing processes.

Maintain awareness of the latest critical information security vulnerabilities, threats, and exploits

In zero-day events, iterate through VM lifecycle creatively assist with time-sensitive escalations, developing new types of reports, and perform special investigations.

Required Skillsets:

Bachelor s degree in a related field (Computer Science, Engineering, Information Systems, etc.) or the equivalent combination of training and experience

3+ years of experience in technology or cyber security

Mid-level knowledge of Windows or Linux system administration and related security configurations, networking, and cyber security

Intermediate Python development experience preferred

Virtualization, cloud, and container experience preferred

Working knowledge of security risk oversight, CVSS (Common Vulnerability Scoring System), CVE (Common Vulnerabilities and Exposures), and technical security vulnerability remediation/mitigation

Experience with enterprise vulnerability management platforms such as Rapid7 Nexpose, Tenable Nessus, or Qualys

Experience with ServiceNow preferred

Skilled at analyzing IT/VM data sets using tools such as Excel or Power BI and presenting in a meaningful, digestible format for stakeholders and leadership teams

Excellent communications skills (verbal and written) are required. Adept at communicating concepts to diverse audiences with varying skill sets

A self-motivated, detail-orientated individual with the ability to work independently as well as function as an integral part of a team and take initiative and ownership in a fast-paced environment.

Mandatory Skills:

  • Solid working experience and knowledge of Unix operating systems or Windows OS.
  • Understanding of databases, web technologies, and network devices
  • Experience with vulnerability scanners
  • Strong verbal and written communications skills Intermediate competency with spreadsheets Intermediate competency writing scripts using python
  • Able to write documentation
  • Ability to identify and solve problems
  • Able to organize meetings, and translate discussed decisions into actions
  • Self-directing with sense of ownership

Desired Skills:

  • Ability to design and document processes
  • Ability to teach others their area or responsibility

Years of Experience: 8.00 Years of Experience

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

About Digitive LLC