Vulnerability Analyst

hace 1 semana


Monterrey, Nuevo León, México Nearshore Cyber A tiempo completo

Location:
Anywhere in Mexico (WFH/Remote)
:
Applications from persons not living in Mexico will NOT be accepted.


The successful Vulnerability Analyst takes an active lead to inform, advise, and partner with technology leadership and business units to secure the company.


The analyst will regularly report on the state of vulnerabilities including criticality, exploit probability, business impact and remediation to security and IT leadership.

This includes all company digital assets that may have weaknesses to allow internal or external threat actors to potentially exploit, which may lead to a breach.

The ability to collaborate with multiple teams and take a pragmatic approach, while at the same time possessing a sense of urgency when needed, is essential.

The Vulnerability Analyst will support strategic initiatives driven from information security and IT leadership for short

Essential Job Duties
- services, cloud services, and third-party assets.

  • Work closely with technical and nontechnical system owners to advise and support remediation efforts to close vulnerability exposure to new threats in the wild and verify the organization's security posture against them.
  • Provide vulnerability education and guidance to stakeholder to prevent new offerings from being at risk of misconfiguration, compromise, or information leakage.
  • Supervise testing and validation vulnerability remediation and controls.
  • Conduct continuous discovery, vulnerability assessment and remediation status of enterprisewide assets.
  • Prioritize vulnerability remediation based on criticality, exploit probability, rating, and business
- risk exposure.

  • Document, prioritize, recommend, validate, and report on the state of vulnerabilities.
  • Automate asset inventory and vulnerability discovery and reporting.
  • Communicate vulnerability results in a manner understood by technical and nontechnical staff based on risk tolerance and threat to the business.
  • Procure and maintain tools and scripts used in asset discovery and vulnerability status.
  • Leverage vulnerability database sources to understand each weakness, its probability, and remediation options, including vendorsupplied fixes and workarounds.
  • Collaborate with IT & security groups to form a holistic team dedicated to reducing attack
- surface.
- outcomes.

  • Liaise with the security operations team to improve monitoring and response workflow.
  • Assist with change management operations to ensure vulnerabilities are not introduced.
  • Define key performance indicators and metrics to illustrate efficacy with vulnerability
- management.

  • Understand breach and attack simulation solutions for known vulnerabilities and work with the team to validate controls effectiveness.
  • Remain current with emerging threats and share knowledge with colleagues to improve security posture.
  • Work as a team to consistently learn and share advanced skills and foster team excellence.
  • Maintain documentation related to vulnerability policies and procedures.
  • Serve as a point of contact for new and existing vulnerabilityrelated issues.

Skills and Experience

  • 57+ years information security administration, vulnerability management, security operations, or IT project/program management.
  • Proficient with commercial and open source vulnerability management solutions.
  • Understanding of networking protocols and devices.
  • Preferably some experience with vulnerability management across cloud environments such as Microsoft Azure, Amazon Web Services, or Google Cloud Platform.
  • Experience conducting organizationwide vulnerability scanning and remediation processes.
  • Ability to influence technical and nontechnical teams and collaborate to reduce attack surface.
  • Capable of scripting in Python, Bash, Perl, or PowerShell preferred.
  • Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the software development lifecycle.
  • Capacity to comprehend complex technical infrastructure, managed services, and thirdparty dependencies.
  • Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively.
  • Experience with one or more of the following frameworks a plus: NIST, ISO 27001, PCI DSS,
  • HIPAA, HITECH, SOX, GDPR, CCPA, CIS, or SOC
  • Selfstarter requiring mínimal supervision.
  • Analytical and problemsolving mindset.
  • Highly organized and efficient.
  • Demonstrated strategic and tactical thinking, along with decisionmaking skills and business acumen.

Education Requirements

  • Preferably higher education with a technical focus such as information security, IT, management information systems, or equivalent industry experience.

Certification Requirement

  • CISSP, CRISC, GCED, GCCC, GPEN, GCIH, GCIA, GEVA, CND, ECIH, CSA, CEH, CySA+, or PMP preferred.

  • Cyber Security Analyst

    hace 2 semanas


    Monterrey, Nuevo León, México Charger Logistics Inc A tiempo completo

    Charger Logistics is a world class asset-based carrier. We specialize in delivering your assets, on time and on budget. With the diverse fleet of equipment, we can handle a range of freight, including dedicated loads, specialized hauls, temperature-controlled goods and HAZMAT cargo. We are currently looking for an experienced IT Security Analyst to join our...

  • Cyber Security Analyst

    hace 1 semana


    Monterrey, Nuevo León, México Charger Logistics A tiempo completo

    We're proud to say we've been named one of "Super Empresas Expansión 2023 Top Charger Logistics is a world class asset-based carrier. We specialize in delivering your assets, on time and on budget. With the diverse fleet of equipment, we can handle a range of freight, including dedicated loads, specialized hauls, temperature-controlled goods and HAZMAT...


  • Monterrey, Nuevo León, México ZF Friedrichshafen AG A tiempo completo

    ZF Friedrichshafen AG ZF is a global technology company and supplies systems for passenger cars, commercial vehicles and industrial technology. View company page Corporate Security Analyst (CSA) is responsible for analysing, operating, and maintaining corporate security processes in Mexico. The Analyst has an advanced understanding and applies professional...

  • Cyber Security Analyst

    hace 1 semana


    Monterrey, Nuevo León, México Charger Logistics A tiempo completo

    We're proud to say we've been named one of "Super Empresas Expansión 2023 TopCharger Logistics is a world class asset-based carrier. We specialize in delivering your assets, on time and on budget. With the diverse fleet of equipment, we can handle a range of freight, including dedicated loads, specialized hauls, temperature-controlled goods and HAZMAT...


  • Monterrey, Nuevo León, México Nearshore Cyber A tiempo completo

    Location: Monterrey or Matamoros, Mexico: Applications from persons not living in Mexico will NOT be accepted.The Information Security Analyst is responsible for activities relating to monitoring and responding to security events. The analyst receives, researches, triages, and documents all security events and alerts as they are received, supporting multiple...


  • Monterrey, Nuevo León, México British American Tobacco A tiempo completo

    BAT is evolving at pace - truly like no other organisation.To achieve the ambition, we have set for ourselves, we are looking for colleagues who are ready to live our ethos every day. Come be a part of this journeyBAT MEXICO IS LOOKING FOR A CYBER DEFENCE AND CYBER SECURITY OPERATIONS-POSTURE AND ASSURANCE ANALYSTSENIORITY LEVEL:ManagerialFUNCTION:DBSSALARY...


  • Monterrey, Nuevo León, México Reclutamiento IT A tiempo completo

    Vacante para la empresa Reclutamiento IT en Monterrey, Nuevo León:Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración).Respeto,...


  • Monterrey, Nuevo León, México Training Talent A tiempo completo

    Vacante para la empresa Training Talent en Monterrey, Nuevo León:Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración)...


  • Monterrey, Nuevo León, México Reclutamiento IT A tiempo completo

    Vacante para la empresa Reclutamiento IT en Monterrey, Nuevo León:Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración). Respeto,...


  • Monterrey, Nuevo León, México Training Talent A tiempo completo

    Vacante para la empresa Training Talent en Monterrey, Nuevo León:Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración). Respeto,...


  • Monterrey, Nuevo León, México Reclutamiento IT A tiempo completo

    Vacante para la empresa Reclutamiento IT en Monterrey, Nuevo León:Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración).Respeto,...


  • Monterrey, Nuevo León, México Training Talent A tiempo completo

    Vacante para la empresa Training Talent en Monterrey, Nuevo León:Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración).Respeto,...


  • Monterrey, Nuevo León, México NORMA Group A tiempo completo

    NORMA Group NORMA Group is a global market leader in engineered joining technology in the three product categories clamp, connect and fluid with around 10,000 customers in 100 countries. View company page We are an international mid sized group with appetite for innovations, approachable management, lead by objectives / targets which give the opportunity...

  • Vulnerability Analyst

    hace 2 meses


    Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Anywhere in Mexico (WFH/Remote)**:** Applications from persons not living in Mexico will NOT be accepted.** The successful Vulnerability Analyst takes an active lead to inform, advise, and partner with technology leadership and business units to secure the company. The analyst will regularly report on the state of vulnerabilities including...

  • Vulnerability Analyst

    hace 2 días


    Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Anywhere in Mexico (WFH/Remote)**:** Applications from persons not living in Mexico will NOT be accepted.** The successful Vulnerability Analyst takes an active lead to inform, advise, and partner with technology leadership and business units to secure the company. The analyst will regularly report on the state of vulnerabilities including...


  • Monterrey, México CHUBB A tiempo completo

    The Chubb Information Security team is responsible for protecting information and information systems against unauthorized access, detecting and responding to attempts to gain access and enabling access through our identity processes. Chubb operates a global information security team supporting local business units across five regions (Asia Pacific, North...


  • Monterrey, México CHUBB A tiempo completo

    The Chubb Information Security team is responsible for protecting information and information systems against unauthorized access, detecting and responding to attempts to gain access and enabling access through our identity processes. Chubb operates a global information security team supporting local business units across five regions (Asia Pacific, North...


  • Monterrey, México CHUBB A tiempo completo

    The Chubb Information Security team is responsible for protecting information and information systems against unauthorized access, detecting and responding to attempts to gain access and enabling access through our identity processes. Chubb operates a global information security team supporting local business units across five regions (Asia Pacific, North...


  • Monterrey, México CHUBB A tiempo completo

    The Chubb Information Security team is responsible for protecting information and information systems against unauthorized access, detecting and responding to attempts to gain access and enabling access through our identity processes. Chubb operates a global information security team supporting local business units across five regions (Asia Pacific, North...

  • Cyber Security Analyst

    hace 4 días


    Monterrey, México Charger Logistics Inc A tiempo completo

    Charger Logistics is a world class asset-based carrier. We specialize in delivering your assets, on time and on budget. With the diverse fleet of equipment, we can handle a range of freight, including dedicated loads, specialized hauls, temperature-controlled goods and HAZMAT cargo. We are currently looking for an experienced IT Security Analyst to join our...

  • Cyber Security Analyst

    hace 2 meses


    Monterrey, México Charger Logistics Inc A tiempo completo

    **_We’re proud to say we’ve been named one of "Super Empresas Expansión 2023 Top_** Charger Logistics is a world class asset-based carrier. We specialize in delivering your assets, on time and on budget. With the diverse fleet of equipment, we can handle a range of freight, including dedicated loads, specialized hauls, temperature-controlled goods and...


  • Monterrey, México Atos A tiempo completo

    **Publication Date**: Nov 21, 2023 **Ref. No**: 500482 **Location**: Monterrey, Nuevo Len, MX, 66490 The future is our choice At Atos, as the global leader in secure and decarbonized digital, our purpose is to help design the future of the information space. Together we bring the diversity of our people’s skills and backgrounds to make the right...


  • Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:** Applications from persons not living in Mexico will NOT be accepted.** The Information Security Analyst is responsible for activities relating to monitoring and responding to security events. The analyst receives, researches, triages, and documents all security events and alerts as they are received,...


  • Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:** Applications from persons not living in Mexico will NOT be accepted.** The Information Security Analyst is responsible for activities relating to monitoring and responding to security events. The analyst receives, researches, triages, and documents all security events and alerts as they are received,...

  • IT Security Analyst

    hace 4 semanas


    Monterrey, México Charger Logistics Inc A tiempo completo

    **_We’re proud to say we’ve been named one of "Super Empresas Expansión 2023 Top_** Charger Logistics is a world class asset-based carrier. We specialize in delivering your assets, on time and on budget. With the diverse fleet of equipment, we can handle a range of freight, including dedicated loads, specialized hauls, temperature-controlled goods and...

  • IT Security Analyst

    hace 2 meses


    Monterrey, México Charger Logistics Inc A tiempo completo

    **_We’re proud to say we’ve been named one of "Super Empresas Expansión 2023 Top_** Charger Logistics is a world class asset-based carrier. We specialize in delivering your assets, on time and on budget. With the diverse fleet of equipment, we can handle a range of freight, including dedicated loads, specialized hauls, temperature-controlled goods and...


  • Monterrey, México iKraft Solutions A tiempo completo

    The **Sr Information Security Analyst **will be a key member Information Security team. This person will work closely with cross functional teams to ensure appropriate physical, administrative and technical controls are operating effectively to ensure the confidentiality, integrity and available information resources. Strategize on the development and...


  • Monterrey, México Training Talent A tiempo completo

    **Vacante para la empresa Training Talent en Monterrey, Nuevo León**: Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración). -...


  • Monterrey, México Training Talent A tiempo completo

    Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración). - Respeto, estabilidad, solidez financiera y crecimiento en todo sentido, la...


  • Monterrey, México Reclutamiento it A tiempo completo

    Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración). - Respeto, estabilidad, solidez financiera y crecimiento en todo sentido, la...


  • Monterrey, México Reclutamiento IT A tiempo completo

    **Vacante para la empresa Reclutamiento IT en Monterrey, Nuevo León**: Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de...


  • Monterrey, México Training Talent A tiempo completo

    **Vacante para la empresa Training Talent en Monterrey, Nuevo León**: Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración)...


  • Monterrey, México Reclutamiento IT A tiempo completo

    **Vacante para la empresa Reclutamiento IT en Monterrey, Nuevo León**: Especialistas en soluciones de ciberseguridad y consultoría, desarrollo profesional, estabilidad y capacitaciones, intégrate como consultor Ciberseguridad (Pentester Ethical Hacker) con experiência deseable en análisis de vulnerabilidades y Pentester (pruebas de penetración). -...