The Vulnerability Management Analyst is responsible for analyzing, categorizing, and prioritizing identified security vulnerabilities across the firm's technology infrastructure. Acting as a trusted partner to technology teams, the role will drive vulnerability remediation efforts, provide risk-based guidance, and track remediation progress to help reduce the firm's overall cyber risk exposure
Main responsibilities:
To operate and serve as a subject matter expert in the firm’s vulnerability management program. Perform regular vulnerability scans and across applications and infrastructure. Validate and prioritise remediation of vulnerabilities from the firm’s security tooling. Monitor security advisories, threat intelligence services and vendor notifications for vulnerability remediation.
Skills and experience:
• Expert experience of working with enterprise vulnerability management platforms.
• Working experience with threat intelligence, attack surface mgmt. and exposure mgmt. platforms.
• Expert understanding of vulnerability scoring, including CWE,
CVSS and MITRE ATT&CK.;
• Foundational knowledge of windows, Linux and networking.
• Ability to assess security risks and prioritise remediation works at enterprise scale.
• Experience in the creation and development of Vulnerability dashboards, reports and executive level metrics.
• Ability to validate the presence of identified vulnerabilities with accuracy and reduce false positive detections.
• Experience of managing vulnerability exceptions, risk acceptance in a large, structured enterprise environment.
• Highly desired experience of working within an enterprise SOC.
• Ongoing commitment to understanding of the threat landscape and common adversary motivations/practices. Ability to quickly adapt practices to evolving circumstances.
• Ability to perform autonomous vulnerability threat research and analysis
• Strong written and oral communication skills. Ability to convey complex concep