
Security Vulnerability Engineer

Security Vulnerability Engineer
24
Applications
Montréal, Canada
Full-Time
Senior: 7 to 10 years
$ 65 - $ 70 (Per Hour)
Posted on Aug 02 2024
Not Accepting Applications
About the Job
Skills
Threat & Vulnerability Management
CISSP
Qualys
Certified Information Security Manager (CISM)
Vulnerability Management
NIST
HIPAA
OWASP
Main Responsibilities:
Responsibilities include but are not limited to:
- Understands and advises on enterprise policies and technical standards with specific regard to vulnerability management and secure configuration.
- Able to successfully partner with other security and IT infrastructure professionals to assess potential impact from vulnerabilities specific to environment and determine appropriate mitigating controls.
- Identify and recommend appropriate measures to manage and remediate vulnerabilities with the focus on reducing potential impacts on information resources to an acceptable level based upon policies and standards.
- Build strong partnerships with technical teams to promote best practices for managing vulnerabilities in an agile manner; across traditional infrastructure and in cloud environments.
- Ability to fully understand business requirements and work with business partners to define appropriate solutions; meeting both security mandates and business needs.
- Review and/or escalate exception requests submitted to the VM team
- Using a risk based approach, analyze vulnerability data against open / closed information sources to best prioritize vulnerability hygiene activities.
- Develop and improve KPIs, metrics, and trend analysis for vulnerability management functions.
- Assist the team to maintain appropriate documentation that defines the Threat & Vulnerability Management Program, policies, and procedures.
Requirements:
Training and occupational experience:
- B.S. in Computer Science or equivalent field
- CISSP, CISM or similar industry certification
- +5 years of experience in Vulnerability Management or related field.
Essential Specific Requirements:
- Expertise knowledge of the Vulnerability Management process including vulnerability identification, false negative/positives identification & elimination
- Strong knowledge of Qualys, Nexpose or Nessus including configuration and maintenance, scan execution, agent deployment and oversight
- Experience of industry standards relating to Vulnerability Management including Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS) and Open Web Application Security Project (OWASP).
- Experience Security Standards/Controls specified under various IT governance and compliance models (NIST, HIPAA, PCI, GDPR, ISO 27001&27002).
- Experience of technology and security topics including operating systems, network security, protocols, application security, infrastructure hardening and security baselines.
- Previous experience working in large-scale environments with diverse technologies is a must.
- Knowledge of scripting languages desired
About the company
Infotree Global was founded in 2002 in a small office in Canton, MI, Infotree Global had a clear mission; To bring the world’s best talent together with the greatest companies producing results through continuous improvement and innovation. From those humble beginnings, Infotree Global has explosively grown from a two-person operation to a global solutions company, functioning in over 150 countri ...Show More
Infotree Global was founded in 2002 in a small office in Canton, MI, Infotree Global had a clear mission; To bring the world’s best talent together with the greatest companies producing results through continuous improvement and innovation. From those humble beginnings, Infotree Global has explosively grown from a two-person operation to a global solutions company, functioning in over 150 countries across 5 different continents.
Infotree Global proudly serves more than 250 of the Global 1000, numerous government agencies, and some of the world’s largest nonprofit organizations. Our sustained growth is attributed to our focus and commitment to our thousands of full-time professionals. In today’s market, where high-quality dedicated individuals are in demand; Infotree Global recognizes that an emphasis on understanding, achieving, and exceeding our employee’s goals, aspirations and overall experience is paramount. This “people over profits” mindset has yielded tremendous success for our employees and clients. Our employees have a vast array of assignments available across the world to help achieve and exceed their career goals and our clients have motivated, dedicated, and hardworking professionals on their team. We are here to help the best talent work with the greatest companies to produce innovative results in a variety of industries including but not limited to IT, Engineering, Clinical, Skilled Trades, Finance and Accounting.
Our mission’s success is supported by several industry awards and accolades. If you are looking for a committed and understanding partner, your search ends here. ...Show Less
Industry
Staffing and Recruiting
Company Size
1001-5000 Employees
Headquarter
Plymouth, Michigan
