Vulnerability Analyst
Date: Nov 9, 2024
Location: Columbia, MD, US, 21044
Company: W. R. Grace & Co.
Annual Wage Range: $104,000.00 - $143,000.00
Other Compensation: Eligibility for the Short-Term Incentive program and other applicable bonuses
Benefits: U.S. Employee Benefits Summary (grace.com)
Final salary and compensation will be based on several factors including candidate qualifications and experience, geographical location, market, and business considerations.
Job Description
The Cybersecurity team at Grace is seeking to hire a versatile and highly motivated vulnerability analyst to join our global team. Reporting to the Grace Deputy CISO, the Vulnerability Analyst will play an important role for our cybersecurity program by supporting a full suite of security assurance services including vulnerability management, configuration management, and application security and will serve as the Grace technical subject matter expert (SME) for associated tools and technologies. This entails managing and maintaining vulnerability management tooling and infrastructure, coordinating authenticated and unauthenticated scans against infrastructure and web applications, assisting with measuring and maintaining secure configuration baseline of infrastructure, maintaining asset ownership, and managing the end-to-end remediation process including coordination with all relevant IT stakeholders.
Responsibilities
- Support Vulnerability Management, Configuration Management, and Application Security services
- Provide input on vulnerability and risk prioritization based on Grace’s environment
- Maintain awareness of emerging threats and vulnerabilities
- Serve as the technical subject matter expert for all things Vulnerability, Configuration Management, and Application Security
Requirements
- At least 3-5 years of experience within cybersecurity, with a focus on vulnerability management
- Hands-on operational experience with enterprise vulnerability management and scanning solutions, such as Tenable or Qualys, and ability to both deploy and manage
- Experience with Cloud-Native Application Protection Platform (CNAPP) solutions, such as Wiz or Rapid7
- Experience with SAST/DAST scanning technologies, such as Qualys and Checkmarx
- Understanding of vulnerability scoring systems and methodologies (i.e.: CVSS, EPSS, CWE, OWASP, etc.)
- Familiarity with cloud environments, such as Google Cloud and Microsoft Azure
- Practical experience with scripting, use of APIs, and developing automation capabilities
- Experience with IT Service Management solutions for ticket assignment
- Ability to communicate to both technical and non-technical audiences, including leadership teams
- Experience with generating regular metric reports for stakeholders and leadership teams
- Ability to work alongside with and support other security-related functions as needed
- Prior experience within a service delivery or consultancy role a plus
- Passionate about cybersecurity and technology
Benefits
- Medical, Dental, Vision Insurance
- Life Insurance and Disability
- Grace Wellness Program
- Flexible Workplace
- Retirement Plans
- 401(k) Company Match – Dollar to dollar up to the first 6%
- Paid Vacation and Holidays
- Parental Leave
- Tuition Reimbursement
- Company Donation Match Program
Grace is not accepting unsolicited assistance from search firms for this employment opportunity. Please, no phone calls or emails. All resumes submitted by search firms to any employee at Grace via email, the Internet or in any form and/or method without a valid written search agreement in place for this position will be deemed the sole property of Grace. No fee will be paid in the event the candidate is hired by Grace as a result of the referral or through other means.
Nearest Major Market: Baltimore