Security Vulnerability Metrics
hace 5 meses
**Job Title**:
**Security Vulnerability Metrics & Data Analyst**
**Job Category**:
Professional
**Department/Group**:
**Attack Surface Management**
**Position Type**:
Full time
**Location**:
Remote, Costa Rica
**Reports to**:
Director Attack Surface Management
Security Vulnerability Metrics & Data Analyst
Description
This role will establish and maintain regional and global reports in support of the Cloud and Application Attack Surface Management scope, embrace and integrate a threat-informed approach, and perform regular analytical reviews for the purpose of enhancing Experian’s Cloud and Application Attack Surface Management with intelligent, prioritized, and actionable transparency.
Functions
- This is an independent role, responsible for driving the development of vulnerability
management metrics, gathering feedback from senior leaders in the organization, and being
able to articulate metrics to senior leaders
- Evaluate and define functional requirements for vulnerabilities, flaws and misconfigurations
metrics
- Understand the end-to-end Cloud and Attack Surface Management metrics process
including metrics collection, tracking and reporting.
- Develop, maintain, and run advance reporting, dashboards, scorecard and analytical results
- Communicate metrics to system owners and business partners on outstanding
vulnerabilities, issues, and concerns.
- Develop and automate vulnerability metrics with specific procedures for data collection,
analysis and charting, partnering with necessary teams as appropriate.
- Determines requirements for technical solutions and tools to effectively implement
Vulnerability Metrics
- Maps metrics back to strategic objectives for providing insight into the effectiveness and
efficiency of Cloud and Attack Surface Management
- Develops vulnerability KPIs/metrics to demonstrate coverage and remediation effectiveness
- Develops program efficacy metrics to support platform stability and improvements.
- Review business and internal requests for new or vulnerability management reporting,
design the solution and develop metrics.
- Work with stakeholders to identify risk-based vulnerability management metrics that align with the security program and security risk management.
- Develop procedures to structure the metrics and reporting framework as part of a long-term strategy.
- Produce timely scoping documents outlining the requirements for business requests.
- Provide actionable recommendations to critical stakeholders based on data analysis and findings related to vulnerability management processes requiring reporting.
- Aggregating vulnerability data across technologies such as endpoints, servers, network equipment, and cloud and interpreting and presenting risk.
Position Requirements
Formal Education & Certification
- Four-year college diploma or university degree in computer science or computer
engineering, and/or 5 years equivalent work experience.
Knowledge & Experience
- 5+ related experience in Cyber Security/Information Security and Vulnerability
Management reporting.
- Experienced in tools like SQL, Tableau, MS Excel etc.
- Experienced with collaboration tools such as JIRA, ServiceNow, Confluence etc.
- Understanding of end-to-end security metrics process including metrics collection,
tracking and reporting, including ownership and responsibilities for each activity.
- Understanding of Common Vulnerability Scoring System (CVSS), including calculations.
and implications of base, temporal, and environmental scoring factors.
- Experience with collecting, analyzing, and interpreting qualitative and quantitative data
from various sources for the purposes of detailing results and analyzing findings to
provide sophisticated threat intelligence.
- Familiarity with architecture, engineering, and operations of one or more vulnerability
management tools, such as Wiz, Qualys, Rapid7 and ServiceNow.
- Ability to provide creative solutions to complex problems.
- Ability to clearly communicate risk of vulnerabilities to all levels within an organization.
- Knowledge of major cloud platforms (AWS, Azure, or GCP).
- Ability to manage, organize, analyze, and present substantial amounts of data
- Experience with large scale and complex environments.
- A broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies.
- Applied knowledge and experience in cybersecurity, technology infrastructure, vulnerability management and security and controls.
- An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood and actionable manner.
Personal Attributes
- Excellent interpersonal skills and strong verbal and written communication.
- Proactive attitude, seeking for improvement opportunities which can positively impact the security posture and the business.
- Outstanding writing and documentation skills.
- Strong organizational skills with proven ability to manage mu
-
Vulnerability Management Metrics Specialist
hace 4 meses
Heredia, Costa Rica Experian A tiempo completoCompany Description **About us, but we’ll be brief** Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years...
-
Security Vuln Metrics
hace 5 meses
Heredia, Costa Rica Experian A tiempo completoCompany Description **About us, but we’ll be brief** Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years...
-
Attack Surface Management Metrics Specialist
hace 4 meses
Heredia, Costa Rica Experian A tiempo completoCompany Description **About us, but we’ll be brief** Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years...
-
Associate Vulnerability Management Engineer
hace 5 meses
Heredia, Costa Rica AlignTech A tiempo completo**Join a team that is changing millions of lives.** - Transforming smiles, changing lives_ At Align Technology, we believe a great smile can transform a person’s life, so we create technology that gives people the confidence to take on whatever’s next. We revolutionized the orthodontic industry with the introduction of the Invisalign system, and we have...
-
Security Analyst
hace 5 meses
Heredia, Costa Rica GFT Technologies SE A tiempo completoJob Description: About the role: Responsible for ensuring that vulnerability disclosure program requirements are followed and adhered to on client applications and system topologies. You will collaborate with security, application, infrastructure and DevSecOps teams to ensure vulnerabilities are identified and...
-
Senior Vulnerability Management Program Lead
hace 1 mes
Heredia, Costa Rica 1170 Kyndryl Costa Rica, Sociedad de Responsabilidad Limitada A tiempo completoWho We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The...
-
Hacker - Vulnerability Management Consultant
hace 5 meses
Heredia, Costa Rica IBM A tiempo completoIntroduction At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most...
-
Hacker - Sr Vulnerability Management Consultant
hace 5 meses
Heredia, Costa Rica IBM A tiempo completoIntroduction At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most...
-
Security Analyst
hace 5 meses
Heredia, Costa Rica GFT Technologies SE A tiempo completo**About the role**: **A day in this role**: - Prioritize newly identified vulnerabilities based upon severity, potential operational impact, exploitation, and other factors to assess risk to. - Support delivery of policy metrics for the vulnerability disclosure program. - Utilize tracking tools/capabilities in a vulnerability management system to report...
-
Principal Engineer Security Services
hace 5 meses
Heredia, Costa Rica 360training A tiempo completo**Principal Engineer Security Services** The Principal Engineer Security Services will play a crucial role in ensuring the ongoing security and protection of our company's information assets. They will be responsible for designing, developing, and overseeing the implementation of cybersecurity solutions to safeguard our systems, networks, and data. The...
-
Endpoint Security Techlead
hace 5 meses
Heredia, Costa Rica Experian A tiempo completoFull-time Employee Status: Regular Role Type: Home Department: Information Technology & Systems Schedule: Full Time Shift: Day Shift **Company Description**: Experian is the world’s leading global information services company. During life’s big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting...
-
Systems Engineer
hace 5 meses
Heredia, Costa Rica Moody's A tiempo completoMoody's is a global integrated risk assessment firm that empowers organizations to make better decisions. - Join the Workplace Services Desktop Engineering Team and you’ll provide expert advice and counsel to users, management, and IT project teams for the most complex systems, spanning multiple functions and locations. - Stay abreast of new technical...
-
Security Reporting System Specialist
hace 5 meses
Heredia, Costa Rica Experian A tiempo completoFull-time Employee Status: Regular Role Type: Home Department: Legal & Compliance Schedule: Full Time Shift: Day Shift **Company Description**: Experian is the world’s leading global information services company. During life’s big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new...
-
Security Reporting System Specialist
hace 5 meses
Heredia, Costa Rica Experian A tiempo completo**Company Description** Experian is the world’s leading global information services company. During life’s big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence. We help individuals to take financial...
-
Cyber Security Engineer
hace 5 meses
Heredia, Costa Rica In All Media A tiempo completo**We are hiring! (COSTA RICA ONLY)** **ONLY NIGHT SHIFTS AVAILABLES** **Responsabilities**: - Respond to security incidents by identifying, containing, analyzing, and mitigating the incident's impact. - Develop and maintain incident response procedures and playbooks, ensuring they are up-to-date and effective. - Conduct post-incident reviews and provide...
-
Attack Surface Management Engineer
hace 5 meses
Heredia, Costa Rica BMA Group A tiempo completo**Job Title**: Attack Surface Management Engineer **Job Category**: Professional **Department/Group**: Attack Surface Management **Position Type**: Full time **Location**: Remote, Costa Rica **Reports to**: Director Attack Surface Management - Attack Surface Management EngineerDescription The Attack Surface Management Engineer is responsible for...
-
Analyst - Cyber Security and Audit Specialist
hace 5 meses
Heredia, Costa Rica FusionHit A tiempo completo**Job Duties**: - Implement and maintain GRC frameworks like PCI DSS, SOC 2, and SOC 1, ensuring compliance with current standards. - Manage cybersecurity policies, conduct risk and vulnerability assessments to safeguard information assets. - Lead and coordinate internal and external audit processes, including collaboration with stakeholders. - Develop and...
-
Prisma Cloud Security Engineer
hace 7 meses
Heredia, Costa Rica IBM A tiempo completoIntroduction In this role, you'll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers), where we deliver deep technical and industry expertise to a wide range of public and private sector clients around the world. Our delivery centers offer our clients locally based skills and technical expertise to drive innovation and adoption of...
-
Security Reporting System Specialist Ii
hace 5 meses
Heredia, Costa Rica Experian A tiempo completoFull-time Employee Status: Regular Role Type: Home Department: Legal & Compliance Schedule: Full Time Shift: Day Shift **Company Description**: Experian is the world’s leading global information services company. During life’s big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new...
-
Application Security Engineer
hace 5 meses
Heredia, Costa Rica Global Services Business A tiempo completoAn important Company in Costa Rica is looking for an Application Security Engineer **Responsibilities**: Application security reviews (SAST, DAST, Pen testing) Secure architecture design Threat modeling Security outreach to internal development teams Security guidance documentation Security metrics delivery and improvements Build deep relationships with...