Sr. Analyst, Vulnerability Management

최근 채용 공고

고용 유형: Full time
지점: Pune, Maharashtra IN
직위 분류: Information Systems
직위 번호: WD30218954

What you will do:

The Johnson Controls Global Cyber Security (GCS) team is undergoing transformation and expansion as Johnson Controls increases its cybersecurity resources and capabilities to address the ever-changing cybersecurity threat landscape. 

The Sr. Vulnerability Analyst for Vulnerability Management will ensure the continuous identification and monitoring of vulnerabilities in the JCI Corporate infrastructure and websites and will support the IT department of Johnson Controls. The role will also identify and recommend methods and techniques to improve security posture and help establish a security culture across the various IT departments. Creates documentation and technical working instructions to support high-quality security operations, monitoring, and compliance in corporate environments. Supports achieving the vulnerability program objectives in the infrastructure, web application and compliance area. The candidate will also coordinate the improvement of current automation related to the vulnerability management area.  The successful candidate will need to be highly knowledgeable of the concepts of security vulnerability management and IT compliance hardening and have the technical skills and communication abilities to converse with IT engineers about security vulnerabilities and support remediation. The candidate will be able to articulate thoughts clearly, run operations, plan initiatives, and execute with appropriate urgency. The candidate will demonstrate drive, intelligence, maturity, and energy and will be a proven change agent..

How you will do it:

  • Coordinate and/or perform regular Infrastructural and Web Application vulnerability assessments;
  • Identify, and maintain the vulnerability management corporate platform in order to prompt identify weakness in the internal and external perimeter, including Cloud infrastructure;
  • Monitor the identified security vulnerabilities or misconfiguration and support the IT stakeholders for remediation;
  • Enforce VM processes and procedures to ensure also the right coverage and security of the Corporate Business Infrastructure and Web Applications;
  • Collaborate with GIS teams to develop or optimize automations used for vulnerability tracking and reporting;
  • Support to adopt Security best practices and security standards applied by the organization.

What we look for:

Required

  • Minimum 8 years working in Information Security and Security Operations area.
  • Knowledge of industry best practices in Vulnerability Management and Compliance areas; (e.g. NIST and “CVSS – Common Vulnerability Scoring System” frameworks)
  • Experience in management and configuration of vulnerability assessment platform (e.g Rapid7 Insight VM and AppSec, Nessus, Qualys VM and WAS, Burp Suite, ZAP)
  • Experience with administration of ITSM solutions used for vulnerability tracking and reporting (Service Now SecOps VM Module/Jira)
  • Experience with OWASP Top 10 assessment and methodology and CIS hardening standard;
  • Experience with various cloud providers (Azure, Google, Amazon) and knowledge on methodology how to secure them;
  • Experience on enforcement of VM operational Security process and procedures;
  • Experience with penetration test assessment, red/blue team activities and security monitoring;
  • Effective communication skills to interface with both internal and external stakeholders;
  • Self-starter mentality that defaults to action and thinks creatively on how to overcome challenges;
  • Good communicator, both verbally and in writing;
  • Highly motivated, adaptable and willing to learn new technologies.

Preferred

  • Bachelor’s degree in computer engineering, computer security or computer science discipline;
  • Previous technical background in IT or Software development roles;
  • Experience with Splunk SIEM Platform;
  • Experience with management of Service NOW SecOps Vulnerability Response module.

Desired Security certifications:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • Offensive Security Certified Professional (OSCP)
  • CompTIA Security+
  • Qualys Certified Specialist
  • Burp Suite Certified Practitioner

채용정보 공유

최신 디지털 관련 채용 공고구인 공고

소프트웨어 엔지니어, 데이터 과학자, 아키텍트, 개발자, 기술 리더(외 다수)로 구성된 우리 디지털 팀으로 우리는 보다 스마트하게 일할 수 있습니다. 이러한 전문가들이 Johnson Controls에서 전사적 IT 전략을 이끌고 있든, AI 기반 솔루션을 위해 고객과 협력하고 있든, 우리의 재능 있는 직원들은 디지털 혁신을 이끌어 감에 있어 선두에 있습니다. 구축된 환경을 혁신하고 미래 대비형 기능을 탑재함으로써 스마트하고, 건강하며, 지속 가능한 공간으로 탈바꿈해 나가는 용기 있는 혁신가들의 팀에 합류하세요. 몇 번의 클릭으로, 커다란 기회를 잡을 수도 있습니다!

아래에서 채용 중인 자리를 검색해 보십시오

Zero Trust and IAM Eng II
Information Systems
Pune, Maharashtra
Zero Trust and IAM Eng II
Information Systems
Pune, Maharashtra
Operations Analyst - Automation
Information Systems
Pune, Maharashtra
Solution Architect
Information Systems
Pune, Maharashtra
동영상 열기: A Day in the Life at Johnson Controls동영상 열기: A Day in the Life at Johnson Controls

인류의 진보를 위한 노력을 이들이 지원하고 있다는 것을 항상 믿어왔습니다.

동영상 열기: A Day in the Life at Johnson Controls | Plant Operations Roles동영상 열기: A Day in the Life at Johnson Controls | Plant Operations Roles

경력 경로를 창조하고 개발할 기회를 잡은 것은 물론, 성공적인 지원, 교육 및 훈련을 받았습니다

Karen | 공장 관리자 | 미국

동영상 열기: A Day in the Life at Johnson Controls | Sales Roles동영상 열기: A Day in the Life at Johnson Controls | Sales Roles

전 세계에서 온 팀과 함께 일하는 것에서 가장 좋은 부분은 서로 간에 배울 수 있어 개인적으로나 직업적으로나 성장할 수 있다는 것입니다

Ignacio | 비즈니스 개발 리더 | 스페인

동영상 열기: A Day in the Life at Johnson Controls | Engineering Roles 동영상 열기: A Day in the Life at Johnson Controls | Engineering Roles

하나의 팀 환경인 JCI에서 우리는 훨씬 더 큰 잠재력을 일깨우고 발현할 수 있습니다

Tanya | 글로벌 하드웨어 플랫포밍 이사 | 미국

동영상 열기: A Day in the Life at Johnson Controls | Digital Roles동영상 열기: A Day in the Life at Johnson Controls | Digital Roles

전 사람들의 삶을 개선하는 혁신을 전달하는 일에서 기쁨을 느낍니다. 우리는 스스로 정한 한계 외에는 한계가 없죠

Gyandendra | 엔지니어링 이사보 | 인도