Sr. Security Analyst
Why This Role Stands Out
This hybrid role at Javen Technologies, Inc. offers significant growth potential by allowing you to deepen your expertise in cyber risk management and vulnerability remediation across various areas. You will thrive here if you are a skilled security professional eager to contribute to a resilient security environment and collaborate with a supportive team. Apply today to leverage your risk assessment and advisory skills in a dynamic setting.
Quick Overview
Job Description
ROLE OBJECTIVE (Manager Perspective):
- Add capacity to existing security analysts and assist with operational tasks
- Perform security risk assessments, quantify risk, facilitate risk decisions, and provide advisory services to business and technology stakeholders.
- Support existing team of security analysts with different types of vulnerability remediation and vulnerability functional process improvements: (Infrastructure, Container, SAST, DAST)
- Support miscellaneous project work supporting Cyber Risk Management, Security Awareness, and Vulnerability Management Programs
Job Description Summary - We are seeking a skilled and motivated Sr. Security Analyst to join our team! The ideal candidate will be responsible for adding depth to the Cyber Risk Management Program, supporting the Bank's Vulnerability Management Program, Security Awareness Program, and provide hands-on support for day-to-day security operations to ensure a resilient and secure environment. The addition of this role will help establish a more mature cybersecurity risk management capability by enabling proactive security risk assessments, risk quantification, and consultation activities that complement our existing vulnerability management and operational security functions.
Requirements:
- 4 year college degree in information technology, cyber security or equivalent experience OR Security and technology certifications are preferred (Security+, Microsoft Azure, AWS, etc).
- Security risk assessment experience.
- Understanding of NIST CSF, NIST 800-53, ISO 27001, CIS Controls, or similar frameworks.
- Experience evaluating technical and administrative controls.
- Risk scoring and risk quantification experience.
- Strong documentation and report-writing skills.
- Ability to communicate risk to non-technical audiences.
- 5 years of vulnerability management experience.
- Experience with vulnerability scanning tools such as Nexpose, Qualys or Nessus is a plus
- Experience with Servicenow Vulnerability Response Module is a plus
- Experience with Infrastructure, Container, SAST, DAST vulnerability remediation is a plus
- Excellent analytical and problem solving skills.
- Demonstrated experience evaluating security statistics to identify patterns and produce metrics that can be used for strategic decision making.
- Be a clear and confident public speaker, able to tailor messaging around technical concepts to diverse audiences.
- Ability to quickly learn new processes and tools
- Naturally curious and driven to understand how technologies, applications, and business processes operate.
Key Responsibilities:
- Add depth to the Cyber Risk Management Function of the Team.
- Assist with efforts to quantify and analyze areas of risk in the environment.
- Design and operationalize a robust, actively maintained Security Risk Register that informs security priorities, drives riskbased decisionmaking, and directly supports the Bank s overall security strategy through improved process, governance, and reporting.
- Demonstrates intellectual curiosity and a desire to continuously learn, investigate security concerns, challenge assumptions, and identify emerging risks, threats, and opportunities for security improvement.
- Work with existing staff to identify and create process improvements to the existing vulnerability management and security awareness programs
- Work with remediation teams to create and track plans to address discovered vulnerabilities.
- Identify and evaluate vulnerability metrics to determine areas of concern and improvement.
- Creating and adhering to procedure documents.
- Perform Vendor Security and Software Risk Assessments.
- Contribute to Security Awareness efforts on an as needed basis.
- Support Misc. operational tasks
We are looking for additional support in the below operational support areas:
- Manage and resolve incoming service requests and incidents through a ticketing system.
- Evaluate new technologies and solutions to ensure alignment with organizational security policies, standards, and risk tolerance before adoption.
- Review and assess SOC2 reports as part of vendor security evaluations.
- Review and respond to phishing emails reported by users, and escalate if necessary.
Enhancing Qualifications:
- Familiarity of Infrastructure, Container, SAST, DAST vulnerability remediation concepts from a vulnerability management remediation perspective is a plus. This role will work with existing application security resources to enhance the existing vulnerability management program.
- Experience conducting risk assessments is a plus
- Self-starter who can work independently as well as in a team setting
- Experience with Data Visualization Tools
- Ability to think critically, ask thoughtful questions, and challenge assumptions in a constructive manner.
Similar jobs
Cyber Operations Plans Analyst with Security Clearance
Department of the Army · Fort Meade, United States
22 minutes agoSoftware Development Manager, Amazon Security Data Engineering
Amazon.com Services LLC · San Luis Obispo, United States
23 minutes ago$184.2k/yrSr. Security Risk Analyst
VC5 Consulting · Houston, United States
41 minutes agoApplication Security Engineer - DAST Engineering
Cloud Destinations LLC · Charlotte, United States
44 minutes agoSenior Security Engineer
Solution Partners, Inc. · Schaumburg, United States
44 minutes agoSenior Information Security Engineer - DOWIN Ops with Security Clearance
ASRC Federal · Alexandria, United States
44 minutes ago