Sr Security Vulnerability Engineer
Sovrn
·
Posted:
August 2, 2023
·
Onsite
About the position
As a Senior Security Vulnerability Engineer, you will be responsible for conducting vulnerability assessments and managing remediation efforts to protect our company's digital assets. You will work closely with other security professionals and Sovrn team members to identify, prioritize, and mitigate security risks across the organization. This is a full-time position that may require occasional evening and weekend work. The Senior Security Vulnerability Engineer will work primarily in an office environment but may be required to work remotely on occasion.
Responsibilities
- Conduct vulnerability assessments and drive penetration testing on company systems, applications, and networks.
- Develop and maintain vulnerability management processes to ensure timely identification and resolution of vulnerabilities.
- Work closely with developers and system administrators to ensure timely and effective remediation of identified vulnerabilities.
- Provide security guidance and recommendations to development teams and stakeholders to ensure secure coding practices.
- Develop and maintain security metrics to measure the effectiveness of vulnerability management processes.
- Monitor and analyze security alerts and events to identify potential security incidents.
- Participate in incident response efforts and provide technical guidance during security incidents.
- Stay up-to-date with emerging security threats and vulnerabilities and make recommendations for mitigating them.
- Participate in the development of security policies, standards, and procedures.
- Drive automations to maximize team efficiency.
Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field
- 5+ years of experience in security vulnerability management or related field
- In-depth knowledge of vulnerability assessment tools and methodologies
- Experience with network and application security testing
- Familiarity with security standards such as PCI-DSS, HIPAA, or ISO 27001
- Experience with NIST
- Experience with incident response and forensic analysis
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
- Ability to work independently and as part of a team
- Relevant certifications such as CISSP, CISM, CEH, or OSCP are a plus
- Experience working in an agile environment
Benefits
- Competitive salaries
- Stock options
- Medical, dental, and vision coverage
- Short and long term disability
- Life insurance
- 11 paid holidays
- Flexible vacation
- Commuter benefits
- 401(k) plan and match
- Paid parental leave program