Company

PAYCOMSee more

addressAddressOklahoma City, OK
type Form of workFull-Time
CategoryInformation Technology

Job description

Job Details
Level
Experienced
Job Location
Oklahoma City Office - Oklahoma City, OK
Position Type
Full Time
Education Level
Bachelor's Degree
Job Category
Information Technology
Description
The IT Vulnerability Risk Management Analyst II will be responsible for applying Patch and Vulnerability management principles and best practices to proactively protect and maintain the confidentiality, integrity, and availability, of the company's data, computing systems, and networks (Security Critical Control of continuous vulnerability assessment and remediation). The analyst will be involved in all the steps of the Patch and Vulnerability Management process and will utilize a vulnerability scanner. They will be responsible for documenting procedures, provide direction and recommendations for patching, set up scans and assist in coordinating patching efforts. Analyst will enhance scan results by providing feedback on risks given the host/system criticality and compensating controls.
The IT Vulnerability Risk Management Team is responsible for assessing and mitigating risk through internal risk assessments and risk assessments for 3rd party vendors. This includes reviewing security questionnaire responses, utilizing web app scanning technology and open-source software scanning technology, reviewing security compliance reports such as ISO27001, SOC 2, CSA, SIG, and more. Ultimately the team is responsible for providing security requirements and approval decisions from a security perspective for given technology initiatives.
Other responsibilities include: ongoing security hardenings of technology assets and monitoring compliance, security recommendations for business and technology initiatives, social engineering/phishing awareness and training simulations, and staying apprised of current security threats and vulnerabilities such as zero-day vulnerabilities.
RESPONSIBILITIES
  • Endpoint vulnerability scanning, identification, risk ranking, and reporting
  • Tracking of remediation and actions taken and escalation requests through ticketing system
  • Facilitate discussions with stakeholders to come up with mutually agreed upon plans for patching
  • Communicate risks in a meaningful way to business units unfamiliar with security
  • Perform risk assessments for business and technology initiatives such as new vendors and supporting software
  • Become a SME and leader for some of the ongoing processes involving vulnerability scanning, reporting, and risk assessment
  • Issue phishing awareness training and simulations enterprise-wide and report metrics
  • Reporting of program key performance indicators and metrics
  • Manage/Create asset groups in vulnerability scanner
  • Facilitate Risk Acceptance process for asset owners
  • 3rd party risk assessments, including OSS, SaaS, on-prem, and hardware
  • Staying up-to-date and current on any trending vulnerabilities (including Zero-Day)
  • Support the Patch Tuesday Process for Microsoft Patching
  • Recommend and monitor security hardening settings for technology assets
  • Build relationships with other business units and technology groups and champion vulnerability management
  • Auditing of critical controls: Security Agents, Data protection, and malware defenses

Qualifications
Education/Certification:
  • Bachelor's degree in Computer Science, Management of Information Systems, Engineering or related field

Experience:
  • 3+ years of vulnerability management, security Risk Management, and/or security administration

Additional Requirement(s):
  • Due to the nature of this position and the need for employees in this position to either work an on-call schedule or be on site within a short period of time, the successful applicant must live within 45-miles of the posted office location.

PREFERRED QUALIFICATIONS
Education/Certification:
  • Industry Certification (Sec+, CASP, CISA, GSEC, CISSP)

Skills/Abilities:
  • Strong knowledge of threats and vulnerabilities associated with cloud and on-premise technology
  • Experienced utilizing Vulnerability Management scanning tools and ticketing systems
  • Familiarity with GRC tools, particularly as it relates to vendor Risk Management
  • Facilitate proactive remediation of new vulnerabilities by collecting information from threat and vulnerability feeds, analyzing the impact/applicability to our environment and communicating applicable vulnerabilities and recommended remediation actions to the impacted teams
  • Perform security risk assessments for technology or business initiatives such as new software or services
  • Provide security recommendations to system and technology owners
  • Phishing and social engineering principles
  • Open-source software assessment and scanning
  • Containerization technology and security principles
  • Assist with routine compliance and audit functions to ensure regulatory scanning requirements are satisfied
  • Stay current on security industry trends, attack techniques, mitigation techniques, security technologies and new and evolving threats to the organization by attending conferences, networking with peers and other education opportunities
  • Ability to deliver reporting on and providing fixes to identified vulnerabilities
  • Strong analytical and problem-solving skills
  • Highly responsive with an ability to handle escalations quickly and professionally
  • Strong verbal and written communication skills
  • Strong research skills and willingness to seek information
  • Maintain effective working relationships with supervisor and coworkers
  • Overcome hurdles that arise around applying security mitigations, controls and patching through collaboration and communication

Paycom is an equal opportunity employer and prohibits discrimination and harassment of any kind. Paycom makes employment decisions on the basis of business needs, job requirements, individual qualifications and merit. Paycom wants to have the best available people in every job. Therefore, Paycom does not permit its employees to harass, discriminate or retaliate against other employees or applicants because of race, color, religion, sex, sexual orientation, gender identity, pregnancy, national origin, military and veteran status, age, physical or mental disability, genetic characteristic, reproductive health decisions, family or parental status or any other consideration made unlawful by applicable laws. Equal employment opportunity will be extended to all persons in all aspects of the employer-employee relationship. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, training, promotion, discipline, compensation benefits, and separation of employment. The Human Resources Department has overall responsibility for this policy and maintains reporting and monitoring procedures. Any questions or concerns should be referred to the Human Resources Department. ****To learn more about Paycom's affirmative action policy, equal employment opportunity, or to request an accommodation - Click on the link to find more information: paycom.com/careers/eeoc
Refer code: 7763464. PAYCOM - The previous day - 2024-01-07 22:57

PAYCOM

Oklahoma City, OK
Popular It Vulnerability jobs in top cities
Jobs feed

Sr. Associate, Product Management - REVEAL

Capital One

Richmond, VA

Sr. Manager, Contract Management

Capital One

Richmond, VA

Manager, Quality Assurance Process Management

Capital One

Richmond, VA

Manager, Cyber Technical (DLP Engineering)

Capital One

Richmond, VA

Starbucks Barista - Capital One - West Creek Business Dining

Aramark

Henrico, VA

$29.4K - $37.2K a year

Manager, Product Management, AI Foundations

Capital One

Richmond, VA

Manager - Accounting (Auto)

Capital One

Richmond, VA

Senior Associate, Finance Risk Management

Capital One

Richmond, VA

Dairy Queen - General Manager

Fourteen Foods - Dairy Queen

Iowa, United States

$48.2K - $61K a year

Share jobs with friends