Role: Vulnerability Management Lead / SME (Backfill)
Location- Chicago(onsite day 1)
JD:
As a Vulnerability Lead/ SME, you will be responsible for leading and managing VMS team. VMS lead will plan managing vulnerabilities of mission critical and geographically distributed operations. Candidate will be responsible for managing client expectations from vulnerability management, leading and scheduling assessments, identifying potential risks and implement solutions to mitigate them. The ideal candidate will have experience in managing end to end vulnerability remediation activities in an enterprise.
Job Description:
· This will be leading role and a part of Vulnerability Management Services, MUST have in depth knowledge and practical delivering experience of complete Lifecyle management of Vulnerability services in different business domains i.e IT Infrastructure, Healthcare, Oil &Gas etc.
· Focal point of contact for Vulnerability Management and related topics- a go-to person for consultation regarding the vulnerabilities identified and guide & assist Infrastructure and Application teams to remediate the vulnerabilities identified under their application/infrastructure scope.
· Responsible preparing the Vulnerability Management Plan and the executes plan through all the phases of Vulnerability Management Lifecycle. Ensures that the Vulnerability scans are scheduled, configured in tool and are executed as per the schedule. Experienced in configuring and managing adhoc scans for critical assets
· Responsible for maintaining accurate Asset inventory, conducts periodical discovery of IT Assets and ensures that identified assets onboards the new asset in Vulnerability Management tool.
· Develop and maintain a risk-based approach to assess the identified vulnerabilities and study & understand the risk profile, impact as per business priorities. Understand the false positives reported and the technical limitations of the environment and facilitate the process of Risk Acceptance.
· Maintain the KPI Based Vulnerability Dashboard for the scope and submits reports both of technical teams and Management Reporting.
· Adherence to Service Level Agreement (SLA) parameters and deliver the Incident management in accordance with the defined Standard Operating Procedure (SOP).
· Collaborate with stakeholders, build and maintain positive working relationships with them.
Skills:
· Hands on experience with Vulnerability Scanning & Management tools (Qualys, Rapid 7 and Balbix, etc)
· In-depth knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management etc.
· Good knowledge of regulatory requirements and industry standards such as CIS, HIPAA, NIST, ISO 27001.
· Bachelor’s degree in Computer Science, Management Information Systems, Information Systems, or a related field/experience is required.
· Added advantage for security certifications like CISM, CISA and specific certifications for vulnerability management tools
· Good proficiency in English with good communication skills.
· Proficient in preparation of reports, and documentation.
· Good Analytical skills, Problem solving and Interpersonal skills.
· Working knowledge and experience with MS office with proficiency in Excel.