Job Description
We are looking for an IT Risk & Vulnerability Analyst to support one of our strategic CIB clients in keeping their software secure and up to date. The ideal candidate has experience reviewing software versions, checking vulnerability data, and working closely with IT teams to fix issues.
In this role, you will help track which software needs to be updated, understand where risks come from, and make sure the right teams take action. You will also help keep our internal tools and reports accurate so we can make good decisions and stay compliant.
_ Role and responsibilities_
- Track application and software versions across the organization and identify end-of-life, outdated, or vulnerable software.
- Analyze software vulnerability and obsolescence data using tools such as Qualys and Splunk, with a focus on applications and packages, not infrastructure.
- Maintain and improve the application / software inventory, ensuring version data is accurate and up to date.
- Work closely with application owners, developers, and IT teams to define target software versions and remediation plans.
- Coordinate and follow up on software upgrades, patches, and version alignments until completion.
- Track remediation actions in tools like ServiceNow or Jira and ensure timelines are respected.
- Prepare clear reports and KPIs related to software risk, obsolescence, and upgrade progress.
- Support audits by providing documentation related to software versions, lifecycle, and remediation actions.
- Contribute to improving processes, controls, and tooling related to software risk and application lifecycle management.
#LI-ASD