Security Vuln Metrics
hace 8 horas
Company Description
**About us, but we'll be brief**
Experian is the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society.
We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for.
In addition, for the last five years we've been name in the 100 "World's Most Innovative Companies" by Forbes Magazine.
**Job Description**:
**What you'll be doing**
**Responsibilities**
- This is an independent role, responsible for driving the development of vulnerability management metrics, gathering feedback from senior leaders in the organization, and being able to articulate metrics to senior leaders
- Evaluate and define functional requirements for vulnerabilities, flaws, and misconfigurations metrics
- Understand the end-to-end Cloud and Attack Surface Management metrics process including metrics collection, tracking, and reporting.
- Develop, maintain, and run advanced reporting, dashboards, scorecards and analytical results
- Communicate metrics to system owners and business partners on outstanding vulnerabilities, issues, and concerns.
- Develop and automate vulnerability metrics with specific procedures for data collection, analysis, and charting, partnering with necessary teams as appropriate.
- Determines requirements for technical solutions and tools to effectively implement Vulnerability Metrics
- Maps metrics back to strategic objectives for providing insight into the effectiveness and efficiency of Cloud and Attack Surface Management
- Develops vulnerability KPIs/metrics to demonstrate coverage and remediation effectiveness
- Develops program efficacy metrics to support platform stability and improvements
- Review business and internal requests for new or vulnerability management reporting, design the solution, and develop metrics
- Work with stakeholders to identify risk-based vulnerability management metrics that align with the security program and security risk management.
- Develop procedures to structure the metrics and reporting framework as part of a long-term strategy
- Produce timely scoping documents outlining the requirements for business requests
- Provide actionable recommendations to critical stakeholders based on data analysis and findings related to vulnerability management processes requiring reporting
- Aggregating vulnerability data across technologies such as endpoints, servers, network equipment, and cloud and interpreting and presenting risk.
**Qualifications**:
**What your background looks like**
- Four-year college diploma or university degree in computer science or computer engineering, and/or 5 years equivalent work experience.
- 5+ related experience in Cyber Security/Information Security and Vulnerability Management reporting
- Experienced in tools like SQL, Tableau, MS Excel, etc.
- Experienced with collaboration tools such as JIRA, ServiceNow, Confluence, etc.
- Understanding of end-to-end security metrics process including metrics collection, tracking, and reporting, including ownership and responsibilities for each activity.
- Understanding of Common Vulnerability Scoring System (CVSS), including calculations and implications of base, temporal, and environmental scoring factors
- Experience with collecting, analyzing, and interpreting qualitative and quantitative data from various sources for the purposes of detailing results and analyzing findings to provide sophisticated threat intelligence.
- Familiarity with architecture, engineering, and operations of one or more vulnerability management tools, such as Wiz, Qualys, Rapid7, and ServiceNow.
- Ability to provide creative solutions to complex problems
- Ability to clearly communicate the risk of vulnerabilities to all levels within an organization.
- Knowledge of major cloud platforms (AWS, Azure, or GCP).
- Ability to manage, organize, analyze, and present substantial amounts of data
- Experience with large-scale and complex environments
- A broad and deep understanding of cybersecurity threats, vulnerabilities, controls, and remediation strategies
- Applied knowledge and experience in cybersecurity, technology infrastructure, vulnerability management, and security and controls
- An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood and actionable manner
**Personal Attributes**
- Excellent interpersonal skills and strong verbal and written communication
- Proactive attitude, seeking improvement opportunities that can positively impact the security posture and the business
- Outstanding writing and documentation skills
- Strong organizational skills with proven ability to manage multiple high visibility issues simultaneously
- Able to communicate ideas in both technical and user-friendly language
- Highly self-motivated and directed, with keen attention to detail
- Able to prioritize and execute tasks in a high
-
Vulnerability Management Metrics Specialist
hace 9 horas
Heredia, Costa Rica Experian A tiempo completoCompany Description**About us, but we'll be brief**Experian is the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society.We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for.In addition, for the last five years we've...
-
Attack Surface Management Metrics Specialist
hace 9 horas
Heredia, Costa Rica Experian A tiempo completoCompany Description**About us, but we'll be brief**Experian is the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society.We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for.In addition, for the last five years we've...
-
Security Reporting Specialist
hace 7 días
Heredia, Costa Rica Experian A tiempo completoCompany Description Experian is the world’s leading global information services company. During life’s big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence. We help individuals to take financial control...
-
Security Lead Engineer
hace 9 horas
Heredia, Costa Rica Auxis A tiempo completoJob Summary:Security Lead Engineer is responsible for the provisioning, deployment, configuration, and administration of many different pieces of network and security-related hardware and software.Security Lead Engineer is also responsible to mitigate any potential threats that become evident, but also to strategize and prepare before any security threat is...
-
Security Data Engineer Ii
hace 9 horas
Heredia, Costa Rica Experian A tiempo completo**Company Description**Experian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence.We help individuals to take financial control and...
-
Lead Security Partner
hace 9 horas
Heredia, Costa Rica Experian A tiempo completoFull-timeEmployee Status: RegularRole Type: HomeDepartment: Legal & ComplianceSchedule: Full Time**Company Description**:Experian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and...
-
Security Data Engineer Ii
hace 9 horas
Heredia, Costa Rica Experian A tiempo completoFull-timeEmployee Status: RegularRole Type: HomeDepartment: AnalyticsSchedule: Full TimeShift: Day Shift**Company Description**:Experian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower...
-
Security and Risk Governance Analyst
hace 3 días
Heredia, Costa Rica IBM A tiempo completo**Introduction** At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's...
-
Cyber Security Assurance Analyst
hace 9 horas
Heredia, Costa Rica Stryker A tiempo completo**Why join Stryker?**:Our total rewards package offering includes bonuses, healthcare, insurance benefits, retirement programs, wellness programs, as well as service and performance awards - not to mention various social and recreational activities, all of which are location specific.**Know someone at Stryker?**:As a Cyber Security Assurance Analyst at...
-
Security & Access Analyst
hace 9 horas
Heredia, Costa Rica Bcd Travel Corporate A tiempo completo**SUMMARY**:The Security Baseline Technical Account Manager (TAM) is responsible for ensuring BCD CyberSecurity services and solutions provide an unrivaled experience producing exceptional satisfaction for BCD's partners, and will lead the implementation of new solutions as they become available.The TAM must have the ability to work across multiple internal...
-
PMO - Physical Security Analyst
hace 6 días
Heredia, Costa Rica Stryker A tiempo completo**Why join Stryker?**: Our total rewards package offering includes bonuses, healthcare, insurance benefits, retirement programs, wellness programs, as well as service and performance awards - not to mention various social and recreational activities, all of which are location specific. **Know someone at Stryker?**: **Who we Want**: - ** Analytical problem...
-
Network Security Engineer
hace 3 días
Heredia, Costa Rica Moody's A tiempo completoThe Cybersecurity team is globally responsible for helping the organization balance risk by aligning policies and procedures with Moody’s business and regulatory requirements. The team is responsible for the development, enforcement and monitoring of security controls, policies and procedures, disaster recovery programs, GRC (Governance, Risk and...
-
Cyber Security Data Engineer
hace 5 días
Heredia, Costa Rica Stryker A tiempo completo**Why join Stryker?**: Our total rewards package offering includes bonuses, healthcare, insurance benefits, retirement programs, wellness programs, as well as service and performance awards - not to mention various social and recreational activities, all of which are location specific. **Know someone at Stryker?**: **Who we Want**: - ** Dedicated...
-
Physical Security Senior Coordinator
hace 9 horas
Heredia, Costa Rica Stryker A tiempo completo**Why join Stryker?**:Our total rewards package offering includes bonuses, healthcare, insurance benefits, retirement programs, wellness programs, as well as service and performance awards - not to mention various social and recreational activities, all of which are location specific.**Know someone at Stryker?**:A Physical Security Senior Coordinator will be...
-
Sr Security Partner
hace 8 horas
Heredia, Costa Rica Experian A tiempo completoFull-timeEmployee Status: RegularRole Type: HomeDepartment: Legal & ComplianceSchedule: Full Time**Company Description**:Experian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and...
-
Sr Security Partner
hace 8 horas
Heredia, Costa Rica Experian A tiempo completo**Company Description**Experian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence.We help individuals to take financial control and...
-
Security Assurance Partner
hace 9 horas
Heredia, Costa Rica Experian A tiempo completoCompany DescriptionExperian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence.We help individuals to take financial control and...
-
Security Services Account Manager
hace 5 días
Heredia, Costa Rica IBM A tiempo completo**Introduction** The Security Services Manager (SSM) serves as a point of contact between the client and IBM Managed Security Services (MSS) for operational governance of MSS security services activities and deliverables. The SSM will work with the client to provide governance, oversight, and leadership for MSS operational security activities including, but...
-
Security Services Account Manager
hace 4 días
Heredia, Costa Rica IBM A tiempo completo**Introduction** The Security Services Manager (SSM) serves as a point of contact between the client and IBM Managed Security Services (MSS) for operational governance of MSS security services activities and deliverables. The SSM will work with the client to provide governance, oversight, and leadership for MSS operational security activities including, but...
-
Third Party Info Security Specialist
hace 3 días
Heredia, Costa Rica Citi A tiempo completoThis is a Third Party IS Assessment (TPISA) Analyst role where the individual will work closely with the TPISA Program management team and other stakeholders to address questions and requests related to the Third Party Information Security Assessment process. **Responsibilities**: - Individually contribute, lead or participate as a team member on projects,...