Vulnerability Management Admin I

Branch/Office
OP CENTER
Department
SECURITY OPERATIONS CENTER
City
OGDEN
Address
1344 West 4675 South
Position Status
40 HR
Schedule
Mon- Fri

Overview

Oversees and coordinates the vulnerability management process.  Performs vulnerability scans on all systems that connect to the Credit Union’s network.  Works closely with the necessary business, system, and IT owners responsible for protecting the assets of the Credit Union to resolve vulnerabilities in a timely manner.  Provides real-time reports on the status of patching of all systems connected to the Credit Union’s network.  Escalates unresolved vulnerabilities to the appropriate level of management based on risk and responsiveness.  Helps identify false positives and remove them from regular scans.  Sets up authenticated scanning wherever possible on systems.  Evaluates requested exceptions based on risk and makes recommendations for appropriate exclusion from scanning.  Oversees the review of exceptions on a periodic basis.

Responsibilities


1. Vulnerability Scanning
a. Assists System Owners, Server Admins, and IT Managers in identifying vulnerabilities on their systems primarily through the use of vulnerability management software.
b. Ensures that the Vulnerability Management software is scanning all available hosts on AFCU’s network.
c. Ensures that all scans are completed as scheduled following a risk-based approach for type and frequency of scans.
d. Sets up authenticated scans as often as possible.
e. Works with the Asset Tracking Admin to ensure each host on the network with a vulnerability has an owner.
f. Follows up on any incomplete scans.
g. Assists in the troubleshooting and fixing of problems related to vulnerability scans.
h. Assists System Owners and Server Admins with the verification of false positives and adjusts the vulnerability management software scans to omit those.
i. Updates the vulnerability management standards as needed to align with industry best practices.

 

2. Monitoring
a. Runs regular reports to determine AFCU’s status in their patching efforts and communicates those findings to the appropriate personnel. For example…
I. Uses outstanding patch trending reports to monitor for anomalies in the vulnerability management effort.
II. Follows up with the appropriate personnel when anomalies are detected; documents the reason for the anomalies and facilitates their resolution.
III. Reports outstanding patch trending reports to SOC Manager, System Owners, Server Admins, and IT Managers on a regular basis to keep them informed on patching status.
IV. Escalates vulnerabilities that are not resolved in a timely manner as per AFCU’s vulnerability management standard.

 

3. Managing Exceptions
a. Carefully reviews and documents requests for exceptions to the vulnerability management software scans and obtain the necessary approvals for exceptions as per the vulnerability management standard.
b. Updates the vulnerability management software to omit approved exceptions for the regular scans.
c. Periodically reviews exceptions as per the vulnerability management standard.

 

4. Responsible for related duties as required or assigned.
a. Creates other means for measuring, monitoring, and controlling vulnerabilities and the patching of those vulnerabilities, such as identifies Key Performance (KPI) & Key Risk Indicators (KRIs).
b. Completes special projects as assigned.
c. Assists with security assessments of credit union systems.
d. Assists with the security assessment of various software purchases, external vendors and technology service providers.
e. Supports other IT Department and SOC Department staff as needed.
f. Performs ad-hoc scans as needed.

Qualifications

Training/Education/Certification:

  • Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, or related field.
  • Two of the following preferred: CEH, CISSP, GPEN, GXPN, OSCP, Security +, and/or PenTest +.

 

Required Knowledge:

  • Knowledge of Microsoft platform (e.g.; Server, Workstation), multiple Linux distros, virtual machines, Java, Adobe, Web Applications, WebSphere, networking concepts (Firewalls, Switches, Load Balancers), and Databases (e.g.; Oracle, SQL Server, DB2, etc.).
  • Knowledge of IT security/hardening best practices; including but not limited to operating systems (e.g., Windows, Linux), virtual machines, web applications, network devices, and databases.
  • Knowledge of industry standard security best practices and vulnerability management processes.
  • Familiar with scripting languages (python, perl, etc.) and/or programming languages (java, .net, etc.) preferred.
  • Familiar with security standards such as NIST, FFIEC, CIS, PCI, and other control frameworks.

 

 Experience Required:

  • Three years using vulnerability scanning tools (Qualys preferred).
  • Three years in information security.
  • Three years in information technology.

 

Skills/Abilities:

  • Champion for vulnerability management and information security, including broadening awareness and education of security best practices.
  • Strong analytical and problem-solving skills.
  • Strong curiosity, initiative, willingness to experiment, and persistence in providing solutions to tough technical challenges.
  • Well organized with good verbal and written communications skills.
  • Ability to prioritize and plan projects effectively.
  • Ability to assist others and share knowledge with other team members.
  • Ability to work effectively with cross-functional teams.
  • Able to use PC, terminal keyboards, and various computer hardware.
  • Self-directed and works with minimal guidance.

 

Apply

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed