layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Ryder System
USA - Coral Gables FL 33134; USA - Coral Gables FL HQ; USA - Remote GA; USA - Remote FL
Source: Ryder System careers · View original posting
From Ryder System's posting. “We” and “our” refer to the employer.
Job Seekers can review the Job Applicant Privacy Policy by clicking here .
Summary
The Vulnerability Management Lead will ensure continuous vulnerability lifecycle management within the Ryder environment including monitoring, collection, reporting, and assessment of impact for vulnerability related data from vendors and internal resources. This individual will be responsible for configuring vulnerability assessment tools, performing scans, analyzing vulnerabilities, identifying relevant threats, recommending corrective actions, and summarizing results for relevant operational teams.
This individual will lead by forming strong partnerships with technical teams and provide vision, strategy, and prioritization to control vulnerabilities in the environment in a timely and effective manner.
Essential Functions
Leads the Proactive assessment and remediation of security vulnerabilities within applications and infrastructure software and/ or other Information assets.
Establishes strategies and frameworks for performing validation of scanning results. Performs asset and network discovery activities, helping ensure full coverage of vulnerability management environment.
Recommend Fixes, Security Patches and other measures required in the event of a security breach. Reviews penetration test findings with system owners in line with vulnerability and asset risk ratings.
Define key performance indicators (KPIs) and metrics across business units to illustrate effectiveness with vulnerability management.
Implement or coordinates remediation required by vulnerability scans, and audits, and documents exceptions as necessary.
Produces vulnerability, configuration, and coverage metrics and reporting to demonstrate assessment coverage and remediation effectiveness
Generates reports on assessment findings and prioritizes remediation schedules
Maintains Health and effectiveness of Application and device scanning applications and systems within the security.
Additional Responsibilities
Reviews security scans and leads/manages resolution of issues.
Ensures compliance with all applicable configuration standards
Oversees enterprise vulnerability assessment and configuration assessment tools
Periodically attend and participate in change management policy discussions and meetings.
Regularly research and learn new TTPs in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary
Leverage vulnerability database sources to understand each weakness, its probability and remediation options, including vendor-supplied fixes and workarounds.
Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business, and gain support through influential messaging.
Work closely with infrastructure teams to advise and support remediation efforts to close vulnerability exposure to new threats in the wild and verify the organization’s security posture against them.
Perform other duties as assigned.
Knowledge of one or more compliance standards, including Payment Card Industry (PCI), Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), National Institute of Standards (NIST) or International Standards Organization (ISO)advanced required
Proficient with vulnerability management solutions such as Qualys, Nexpose, Nessus, Kenna Security, Tanium and open source, intermediate required
Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the software development life cycle, intermediate required
Strong Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening, security baselines, and web server and database security, advanced required
Compensation
The compensation offered to a candidate may be influenced by a variety of factors, including the candidate’s relevant experience; education, including relevant degrees or certifications; work location; market data/ranges; internal equity; internal salary ranges; etc. The position may also be eligible to receive an annual bonus, commission, and/or long-term incentive plan based on the level and/or type. Compensation ranges for the position are below:
Salaried
Minimum Pay Range :
Maximum Pay Range :
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: