"I can succeed as a Vulnerability Management Specialist at Capital Group."
As a Vulnerability Management Specialist within the Security Operations Vulnerability Management team, you will lead the execution of the team's mission to identify, analyze, assign, prioritize, report and drive remediation of vulnerability risk within CG's technology systems.
Responsibilities:
- You will design, implement, and execute rigorous operational processes that maintain KPI and KRIs within acceptable levels
- You will implement and maintain systems and processes that manage vulnerability detection and asset data, perform analysis and produce actionable visualizations
- You will monitor vulnerability scanner scope and coverage to ensure accurate and complete vulnerability risk identification and work with operational partners to implement needed enhancements
Want more jobs like this?
Get jobs delivered to your inbox every week.
- You will ensure the consistent assessment of vulnerability risk through application of threat intelligence and asset context
- You will regularly report and drive improvement in KRIs through proactive communication with remediation partners and their leadership teams
- You will design, implement, enhance and run operational processes that identify actionable insights from vulnerability data and trends
- You will mature team processes, tooling and relevant documentation in support of continuous improvement measured through OKRs
- You will ensure past due vulnerabilities are escalated to leadership and exception processes are executed in alignment with risk acceptance frameworks and policies
- You will provide vulnerability and/or misconfiguration remediation guidance, risk-awareness, and education to engineering and development teams
- You will manage compliance to Information Security standards and proactively identify needed process changes
"I am the person Capital Group is looking for."
In addition to team leadership and direct report development, the ideal candidate will have diverse experiences in a wide variety of Information Technology systems, vulnerabilities, misconfigurations, risk management, data analysis, and influencing organizational change through strong relationship and consulting skills.
- You have 5+ years of experience in managing security risk and driving mitigation activities
- You have 3+ years of experience in engineering and visualizing complex data sets that produce actionable insights (experience with tools such as Power BI, Tableau, etc.)
- You have experience designing and implementing operational processes to ensure delivery and improvement of target vulnerability KPIs and KRIs
- You are comfortable articulating vulnerability risk and influencing change with a wide variety of audiences
- You have a strong understanding of application and infrastructure vulnerabilities, how they are exploited and mitigated
- You have a broad understanding of legacy and modern IT infrastructure and application stacks, including containers and application dependencies
- You have experience with public cloud infrastructure, common misconfigurations, and recommended architectures (AWS, Azure, GCP)
- You hold public cloud provider certifications (AWS, Azure, GCP)
- You hold security related certifications (CISSP, GIAC, CISA, CISM)
- You have a bachelor's degree in computer science, information security or related field (or equivalent work experience)
Southern California Base Salary Range: $173,211-$277,138
San Antonio Base Salary Range: $142,394-$227,830
New York Base Salary Range: $183,613-$293,781
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits here.
* Temporary positions in Canada and the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.