We are seeking a highly motivated and experienced Vulnerability Management Subject Matter Expert (SME) to join our growing security team. In this role you will be responsible for leading our vulnerability management program identifying prioritizing and remediating security vulnerabilities across our IT infrastructure. Responsibilities: Design implement and manage a comprehensive vulnerability management program aligned with industry best practices (e.g. NIST CSF). Conduct regular vulnerability assessments and penetration testing using industryrecognized tools and methodologies. Prioritize vulnerabilities based on severity exploitability and business impact. Develop and implement remediation plans for identified vulnerabilities working crossfunctionally with IT and development teams. Stay up to date on the latest vulnerability trends and threats recommending and implementing new tools and processes as needed. Track and report on vulnerability management program metrics and KPIs. Collaborate with security analysts and engineers to investigate and respond to security incidents. Provide security awareness training on vulnerability management best practices to internal stakeholders. Qualifications: 810 years of experience in vulnerability management and security operations. Proven experience in designing implementing and managing vulnerability management programs. Strong understanding of vulnerability assessment tools and methodologies (e.g. Rapid7 InsightVM /Nexpose Nessus Tenable.io Qualys). Experience with vulnerability prioritization frameworks (e.g. CVSS). Excellent understanding of network security concepts firewalls intrusion detection/prevention systems (IDS/IPS). Experience working in a crossfunctional environment and collaborating with IT and development teams. Strong communication analytical and problemsolving skills. Excellent written and verbal communication skills. Ability to work independently and manage multiple priorities. Preferred Skills: Experience with Security Information and Event Management (SIEM) systems. Experience with scripting languages (e.g. Python Bash). Experience with penetration testing methodologies (e.g. OWASP Top 10). Certifications in vulnerability management (e.g. GSEC CISSP) a plus.
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.