Vulnerability Management Lead
1 month ago
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better. Join us and build an exceptional experience for yourself, and a better working world for all. The exceptional EY experience. It's yours to build. EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities. The opportunity From strategy to execution, the Government & Public Sector (GPS) practice of Ernst & Young LLP provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes. We deliver real change and measurable results through our diverse, high-performing teams, quality work at the highest professional standards, operational know-how from across our global organization, and creative and bold ideas that drive innovation. We enable our government clients to achieve their mission of protecting the nation and serving the people; increasing public safety; improving healthcare for our military, veterans and citizens; delivering essential public services; and helping those in need. EY is ready to help our government build a better working world. Our GPS Technology Organization is a structure within the US GPS practice that implements and maintains a new operate and technology model designed specifically to support U.S. defense and Government engagements. As the Vulnerability Management Lead you will assist the CISO and Cyber Defense Lead design and drive strategy and tactical plans toward holistic vulnerability management across multiple technology teams in a complex organization. You will play a lead role in the development and maturity of our threat intelligence program. Your key responsibilities Collaborate with the Cybersecurity Operations Team ensuring proper Security Operations Center (SOC) performance, threat strategy, management and reporting across the organization. Provide vulnerability data feeds which the SOC can use to alert on. Produce and regularly evaluate all Vulnerability Management program and process related documentation. Perform and provide vulnerability assessment results and recommendations to the Cyber Defense Leader, Information Security Governance Lead and Cloud Operations Leads on a weekly basis and especially when needed due to identified threats. Provide vulnerability risk assessment guidance to peers and stakeholders throughout the organization. Provide regular reporting on patch management operations compliance. Communicate potential risks and business impacts with technical and non-technical internal partners. Provide threat analysis and current status summations to leadership along with proposed actions to minimize identified threats. Ensure effective and complete scanning of production and non-production environments, and capable of providing evidence of the scans. Ensure the accurate and timely release of vulnerability metrics. Research and investigate new and emerging vulnerabilities, to include Zero Day events, assess against risk to the corporate and production environments, and participate in EY Global communities to share intelligence. Manage the work direction and resource needs for the VM platform within the GPS IT environment. Maintain an ongoing development of current threat intelligence and vulnerability analysis with an in-depth knowledge of identification, mitigation, and recovery strategies. Skills and attributes for success Knowledge of security frameworks and standards (e.g., NIST, DoD SRG). Ability to analyze vulnerability scans and reports to identify security risks. Skill in interpreting the results of penetration tests. Competence in assessing the severity of vulnerabilities and potential impact. Meticulousness in reviewing technical details and understanding the implications. Precision in documenting vulnerabilities and the steps needed for remediation. Creativity in developing solutions to mitigate or remediate vulnerabilities. Ability to prioritize issues based on risk and business impact. Proficiency in communicating technical information to non-technical stakeholders. Skill in writing clear and concise reports and remediation plans. Ability to advocate for security within the organization. Capability to manage multiple tasks and projects simultaneously. Efficiency in tracking and monitoring vulnerability management processes. Teamwork skills to work with IT, security, and other departments. Ability to build relationships with vendors and security researchers. Commitment to staying current with the latest security trends and threats. Willingness to pursue relevant certifications (e.g., CISSP, CEH, OSCP). Understanding of risk assessment methodologies and risk management principles. Ability to communicate risk to stakeholders and influence decision-making. Skills in planning, executing, and overseeing vulnerability management projects. Strong ethical standards to handle sensitive information responsibly. Ability to adapt to changing threat landscapes and technologies. Ability to align vulnerability management activities with the organization's strategic goals. Basic programming or scripting skills to automate tasks and analyze data. To qualify for the role you must have Minimum bachelor’s degree in information systems or related field or an equivalent combination of education and experience. 5+ years of comprehensive knowledge of Vulnerability Management identification, analysis, metrics and reporting tools processes enabling proper governance, risk and compliance. Familiar with Azure.gov/GCCH environments preferred, Vulnerability Management tools. Extensive knowledge and experience with diverse IT architectures and enterprise IT data centers, large scale transaction processing environments, external hosted services and cloud computing environments. Must have Excellent communication skills, translating complex technical information across all levels of the organization. Speak in front of non-technical executives on matters related to vulnerabilities to their systems and any threats against those systems. Well organized with excellent follow up skills to meet deadlines, coordinates work of others while fostering teamwork and cooperation, and able to handle multiple concurrent tasks. Have broad scope knowledge and experience in Vulnerability management processes. Must be able to work independently in a remote work environment. Ability to obtain and maintain Top Secret Security Clearance. Ideally, you’ll also have Previous Cybersecurity engineering experience preferred. Experience with security management tools, i.e. SIEMs, EDRs, MSFT Defender for Cloud. Experience with Threat Intel feeds preferred. CISSP, CEH, SANS GIAC (i.e GIAC Enterprise Vulnerability Assessor Certification (GEVA) and/or GIAC Cyber Threat Intelligence (GCTI) or other security relevant certifications are preferred. Experience with perimeter technologies (e.g., router, firewalls, web proxies and intrusion prevention) preferred. Expert level familiarity with multiple enterprise vulnerability management tools, such as Qualys, MSFT Defender, Tanium, etc. What we offer We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $124,400 to $232,700. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $149,300 to $264,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being. + Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next. + Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way. + Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs. + Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs. If you can demonstrate that you meet the criteria above, please contact us as soon as possible. EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. EY is an equal opportunity, affirmative action employer providing equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com #J-18808-Ljbffr
-
IT Security Specialist
1 week ago
San Diego, California, United States MILLENNIUMSOFT Full timeJob Title: IT Security Specialist - Vulnerability ManagementEstimated Salary: $90,000 - $120,000 per yearThis role requires a highly motivated and dynamic individual to support the Threat & Vulnerability team within Security Operations. As an IT Security Specialist - Vulnerability Management, you will be responsible for identifying and proactively mitigating...
-
San Diego, California, United States MILLENNIUMSOFT Full timeJob OverviewMillenniumSoft is seeking a seasoned Vulnerability Management and Incident Response Professional to join our team. The successful candidate will have a strong background in IT security risk mitigation, including incident response, monitoring/detection, vulnerability management, and threat intel.The estimated salary for this role is $80,000 -...
-
Vulnerability Management Expert
1 week ago
San Diego, California, United States MILLENNIUMSOFT Full timeJob Title:Vulnerability Management Expert - San Diego, CA or NJAbout the Company:MILLENNIUMSOFT is a leading provider of innovative technology solutions. We are seeking a highly skilled Vulnerability Management Expert to join our team.Job Description:The Vulnerability Management Expert will be responsible for identifying and mitigating vulnerabilities in our...
-
Information Security Analyst
4 weeks ago
San Diego, United States MILLENNIUMSOFT Full timeJob Title - Information Security Analyst [Vulnerability Management] Location - San Diego, CA or Franklin Lakes, NJ [Remote OK] Duration 12 Months Work hours: 8am-5pm, 40 hours/week Client: Medical Device Company Employment Type: Contract on W2 (Need US Citizens Or GC Holders Only) Remote OK, would prefer NJ or San Diego Description: 3 must haves on the...
-
Information Security Analyst
7 months ago
San Diego, United States MILLENNIUMSOFT Full timeJob Title - Information Security Analyst [Vulnerability Management] Location - San Diego, CA or Franklin Lakes, NJ [Remote OK] Duration – 12+ Months Work hours: 8am-5pm, 40 hours/week Client: Medical Device Company Employment Type: Contract on W2 (Need US Citizens Or GC Holders Only) Remote OK, would prefer NJ or San Diego Description: 3 must...
-
San Francisco, California, United States DocuSign Full timeJob SummaryDocusign is seeking a highly experienced Cybersecurity Leader to head our Vulnerability Management team. As a key member of our security ecosystem, you will be responsible for leading the detection, assessment, and remediation of vulnerabilities across the enterprise.About UsDocusign brings agreements to life, serving over 1.5 million customers...
-
Cyber Vulnerability Reseacher
4 weeks ago
San Diego, United States ActioNet Full timeDescription ActioNet has an immediate opportunity for a Cyber Vulnerability Researcher requiring a Top Secret clearance located in Camp Pendleton, CA.. ActioNet is an IT service provider and solutions integrator headquartered in Vienna, VA that works with the Federal Government and Department of Defense. In this role, you will be responsible for Network...
-
Cyber Vulnerability Reseacher
1 month ago
San Diego, United States ActioNet Full timeDescription ActioNet has an immediate opportunity for a Cyber Vulnerability Researcher requiring a Top Secret clearance located in Camp Pendleton, CA.. ActioNet is an IT service provider and solutions integrator headquartered in Vienna, VA that works with the Federal Government and Department of Defense. In this role, you will be responsible for Network...
-
Vulnerability Response Manager
3 days ago
San Bruno, California, United States YouTube Full timeJob DescriptionWe are seeking an experienced security professional to join our team as a Security Strategist. In this role, you will be responsible for leading the security strategy for YouTube and consulting on security incidents across our products. You will review and develop secure operational practices, provide security guidance to engineers and support...
-
San Francisco, California, United States Yoh Full timeAbout the JobYoh, a Day & Zimmermann company, is seeking an experienced Senior Vulnerability Management Security Specialist to join our team in McKinney, TX. As a key member of our cybersecurity team, you will be responsible for identifying, assessing, and mitigating security vulnerabilities across our enterprise infrastructure and...
-
Vulnerability Management Security Engineer
1 week ago
San Mateo, California, United States Roblox Full timeJob Title: Vulnerability Management Security EngineerAbout Roblox:Roblox is the ultimate virtual universe where users can create, share experiences and be anything they imagine. It attracts millions of people who explore, create, play, learn and connect with friends in 3D immersive digital experiences created by a global community.We are building tools and...
-
Vulnerability Research and Development Manager
2 weeks ago
San Antonio, Texas, United States Northrop Grumman Full timeJob DescriptionAs a Sr. Principal Software Engineer: Vulnerability Research - Reverse Engineering, you will lead the development of solutions to national security threats with products that may involve kernel development, reverse engineering or vulnerability research of network and communication systems.You will design, develop, document, test and debug low...
-
Vulnerability Management Engineer
3 weeks ago
San Francisco, United States Tbwa ChiatDay Inc Full timeDiscord is used by over 200 million people every month for many different reasons, but there’s one thing that nearly everyone does on our platform: play video games. Over 90% of our users play games, spending a combined 1.5 billion hours playing thousands of unique titles on Discord each month. Discord plays a uniquely important role in the future of...
-
Marine Machinist Lead
4 weeks ago
San Diego, California, United States LEAD Staffing Full timeWe are seeking an experienced Marine Machinist to join our team at Lead Staffing. This is a full-time position with a competitive salary of $27.00 per hour.Job Responsibilities:Lead Marine has immediate openings for Marine/Navy Mechanics in the San Diego Naval Shipyard Industry.Must have navy repair/marine mechanic or prior military experience, and be DBIDs...
-
Vulnerability Management Engineer
3 weeks ago
San Francisco, United States Discord Full timeDiscord is used by over 200 million people every month for many different reasons, but there’s one thing that nearly everyone does on our platform: play video games. Over 90% of our users play games, spending a combined 1.5 billion hours playing thousands of unique titles on Discord each month. Discord plays a uniquely important role in the future of...
-
Lead Marine Sheetmetal Installer
2 weeks ago
San Diego, California, United States LEAD Staffing Full timeAbout the JobThis exciting opportunity is for a Lead Marine Sheetmetal Installer to join our team at LEAD Staffing. As a key member of our team, you will be responsible for installing and repairing sheet metal components on naval bases and shipyards.Key ResponsibilitiesLead teams of apprentices and helpers in the installation and repair of sheet metal...
-
Site Management Lead
2 weeks ago
San Diego, California, United States JRM Construction Management Full time**Job Summary**We are seeking a highly experienced Site Management Lead to oversee the successful delivery of our construction projects. As a key member of our team, you will be responsible for ensuring that all projects are completed on time, within budget, and to the highest quality standards.The ideal candidate will have a proven track record of managing...
-
Cybersecurity Vulnerability Research Specialist
4 weeks ago
San Francisco, California, United States Palo Alto Networks Full timeEmbark on a challenging role with Palo Alto Networks, where you will contribute to the development of industry-leading vulnerability management solutions. As a Cybersecurity Vulnerability Research Specialist, you will be responsible for conducting research and testing, enhancing automation processes, and ensuring a smooth workflow for identifying,...
-
Care Manager for Vulnerable Populations
1 week ago
San Francisco, California, United States Social Service Staffing & Recruiting, Inc. Full timeCare Manager Job DescriptionWe are a staffing and recruiting agency specializing in social services, and we have an exciting opportunity for a skilled Care Manager to join our team in San Francisco. As a Care Manager, you will work closely with our clients to provide intensive case management services, ensuring their well-being and...
-
Electrical Operations Manager
4 days ago
San Diego, California, United States LEAD Staffing Full time**Job Overview:** Electrical Operations ManagerSalary: $33.00 - $35.00 per hourWe are seeking an experienced Electrical Operations Manager to join our team at LEAD Staffing. In this role, you will oversee the installation of electrical systems on naval ships, troubleshoot and repair electrical issues, and supervise a team of electricians.Key...