Vulnerability Management SME

Greeley Square, NY 10001

Category: Security Engineer Job Number: 21703

Job Description

1 day hybrid NYC

We are seeking a highly motivated and experienced Vulnerability Management Subject Matter Expert (SME) to join our growing security team. In this role, you will be responsible for leading our vulnerability management program, identifying, prioritizing, and remediating security vulnerabilities across our IT infrastructure.

Responsibilities:

  • Design, implement, and manage a comprehensive vulnerability management program aligned with industry best practices (e.g., NIST CSF).
  • Customize scan profiles, schedules, and policies to optimize vulnerability scanning across diverse IT environments.
  • Serve as the primary point of contact for technical inquiries and escalations related to the Qualys platform.
  • Serve as the primary point of contact for technical inquiries and escalations related to the Qualys platform.
  • Identify opportunities for automation and integration to streamline vulnerability management processes.
  • Provide advanced troubleshooting and resolution of issues to ensure the stability and reliability of vulnerability scanning operations.
  • Provide advanced troubleshooting and resolution of issues to ensure the stability and reliability of vulnerability scanning operations.
  • Conduct regular vulnerability assessments and penetration testing using industry-recognized tools and methodologies.
  • Prioritize vulnerabilities based on severity, exploitability, and business impact.
  • Develop and implement remediation plans for identified vulnerabilities, working cross-functionally with IT and development teams.
  • Track and report on vulnerability management program metrics and KPIs.
  • Collaborate with security analysts and engineers to investigate and respond to security incidents.
  • Provide security awareness training on vulnerability management best practices to internal stakeholders.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Effective communication and interpersonal skills, with the ability to interact with stakeholders at all levels.
  • Collaborate with cross-functional teams to integrate Qualys Vulnerability Management with other security tools and systems.
  • Work closely with IT operations, security operations, and compliance teams to ensure alignment and coordination on vulnerability management initiatives.
  • Develop and maintain comprehensive reports and dashboards to track key performance indicators and metrics related to vulnerability management.
  • Provide regular updates and insights to senior management and key stakeholders on the organization's vulnerability posture.
  • Stay abreast of emerging trends and advancements in vulnerability management technologies and methodologies.
  • Drive continuous improvement initiatives to enhance the effectiveness and efficiency of vulnerability scanning processes.

Qualifications:

  • 8-12 years of experience in vulnerability management and security operations.
  • Proven experience in designing, implementing, and managing vulnerability management programs.
  • Strong understanding of vulnerability assessment tools and methodologies on Qualys, knowledge with other tools like Rapid7 InsightVM /Nexpose, Nessus, Tenable.io is a plus.
  • Experience with vulnerability prioritization frameworks (e.g., CVSS).
  • Excellent understanding of network security concepts, firewalls, intrusion detection/prevention systems (IDS/IPS).
  • Experience working in a cross-functional environment and collaborating with IT and development teams.
  • Strong communication, analytical, and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work independently and manage multiple priorities.

Preferred Skills:

  • Experience with Security Information and Event Management (SIEM) systems.
  • Experience with scripting languages (e.g., Python, Bash).
  • Experience with penetration testing methodologies (e.g., OWASP Top 10).
  • Certifications in vulnerability management (e.g., GSEC, CISSP) a plus.
  • Ability to work independently and manage multiple priorities in a fast-paced environment.
  • Strong project management skills with the ability to lead and execute technical initiatives from inception to completion.

 

This is a hybrid role. This role is to be filled outside the states of California and Colorado.

 

**We are an equal opportunity employer and value diversity at our company. We do not discriminate based on race, religion, color, ethnic origin, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.**

#LI-CW1

 

Job Requirements

Vulnerability management, NIST CSF, Qualys platform, Automation and integration, Vulnerability assessments, Penetration testing, Vulnerability prioritization, Remediation plans, Security incident response, Security awareness training, Analytical skills, Problem-solving skills, Network security concepts, Firewalls, Intrusion detection/prevention systems (IDS/IPS), Cross-functional collaboration, CVSS, Qualys, Rapid7 InsightVM/Nexpose, Nessus, Tenable.io, SIEM systems, Scripting languages (e.g., Python, Bash), OWASP Top 10, GSEC, CISSP certifications, Project management

Meet the Recruiter

Send an email reminder to:

Share This Job:

Related Jobs:

Login to save this search and get notified of similar positions.

About Greeley Square, NY

Start your career in the vibrant heart of New York City at Greeley Square! Explore our job opportunities in this bustling area, located near iconic landmarks such as the Empire State Building and the lively Garment District. With a blend of commerce, culture, and endless growth possibilities, Greeley Square offers job seekers a unique chance to thrive in a dynamic environment. Enjoy delectable cuisine from nearby Koreatown, catch a show at the renowned New Victory Theater, or discover local art at the ICP Museum. Join us in this exciting region, where opportunities abound and the city's irresistible charm awaits. Begin your journey today!