Jobs · Information Technology · Kansas

Cyber Security Vulnerability Analyst 2

Garmin · Olathe, KS · 2 wk ago
On-siteInformation TechnologyFull-time

About the role

We are seeking a full-time Cyber Security Vulnerability Analyst 2 at Garmin's U.S. headquarters in the Greater Kansas City area. In this role, you will operate independently to configure and perform vulnerability scanning and assessments to support the identification, analysis, and remediation of risk to networks, operating systems, applications, and other information system components.

Responsibilities

  • Review, configure, and operate automated tools, analyze threat feeds, and monitor disclosure programs to identify and prioritize vulnerabilities
  • Work with stakeholders to determine and implement remediation timelines and plans, executing and aligning remediation based on Garmin risks and available data
  • Independently analyze results from internal and external vulnerability scans, prioritizing risk-based remediation plans using experience and skills
  • Coordinate and establish proper scan timelines to avoid service interruption, ensuring complete and accurate results
  • Establish strong relationships with business stakeholders to facilitate prioritization and timely remediation
  • Develop metrics and timelines to monitor the health of the vulnerability management program
  • Work with Cyber Security, System Administration, and System Owners to establish vulnerability mitigations and plans of action
  • Build performance metrics that provide advanced and detailed views of remediation performance
  • Ensure external vulnerability disclosures are assigned to the proper teams and facilitate communications with vulnerability reporters and finders
  • Analyze compliance requirements and develop scanning plans and procedures to test and report on results
  • Coordinate efforts with compliance teams to develop vulnerability and scanning processes in support of governance and compliance requirements
  • Perform system administration activities on vulnerability management systems and applications
  • Communicate effectively in written and verbal form in a large team or departmental setting
  • Authorize, formulate, and communicate remediation plans and timelines following vulnerability scans using input from system owners
  • Establish and create vulnerability documentation, mitigations, and remediations
  • Develop, create, and provide reports of vulnerability scan results in a consumable and consistent format
  • Help establish and track compliance with vulnerability management policies, standards, and procedures
  • Demonstrate proficient use and knowledge of standards and procedures
  • Understand vulnerability tool configurations and provide guidance or remediation

Requirements

  • Bachelor’s Degree in Computer Science, Information Technology, Management Information Systems, Business, or related field AND a minimum of 1 year relevant experience OR equivalent combination of education and relevant experience
  • Analytical skills and strong ability to maintain composure and remain diplomatic under highly stressful situations
  • Familiarity with Common Vulnerability Scoring System (CVSS) framework and National Vulnerability Database (NVD)
  • Strong multitasking skills to effectively manage multiple activities, including cross-team dependent activities simultaneously
  • Consistently demonstrate quality and effectiveness in work documentation and organization
  • Demonstrated ability to exercise strong and effective verbal, written, and interpersonal communication skills in a small team setting
  • Team-oriented, with a positive attitude and ability to work well with others
  • Familiarity with defensive security techniques and implementation of mitigating security controls

Qualifications

  • Working experience with automated vulnerability scanning tools, including implementation, configuration, and maintenance
  • Information security-related experience in areas such as security operations, incident analysis, incident handling, system patching, and endpoint protection
  • Experience with vulnerability scanning in cloud-based environments, including security posture management
  • Ability to work in a fast-paced, dynamic environment
  • Experience with NIST 800-53 and/or NIST Cyber Security Framework (CSF)
  • Familiarity with information and event management (SIEM) platforms
  • Experience with BI tools for data analytic reporting and KPIs
  • System administration experience with Windows and Linux/Unix
  • Scripting or development experience (Python, JavaScript, PowerShell, C#, Perl)

Benefits

This position is eligible for Garmin's benefit program. Details can be found here: Garmin Benefits.

Similar jobs

Cyber Defense Analyst 2

The Swift Group, LLCAnnapolis Junction, MD· 1 mo ago
Information Technology$50k–$290k/yrapply on jobs.gem.com

Cyber Security Analyst II

Memorial Sloan Kettering Cancer CenterNew York, NY· 1 mo ago
Information Technology$124k–$205k/yrapply on msk.wd108.myworkdayjobs.com

Cyber Security Analyst II

Abacus Technology CorporationSumter, SC· 2 wk ago
Information Technologyapply on careers-abacustech.icims.com