8 дней назад
Senior Vulnerability & Security Engineer (Cybersecurity)
150 000 - 195 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Vulnerability & Security Engineer (Cybersecurity): Advancing enterprise vulnerability management and security configuration programs with an accent on risk-based vulnerability analysis, secure configuration baselines, and automated compliance assessment. Focus on evaluating exploitability and business impact, engineering remediation workflows, and translating complex security findings into actionable recommendations.
Location: Jersey City, New Jersey, United States
Salary: $150,000–$195,000 annual base salary for New Jersey, plus annual target bonus.
Company
is a global financial services firm providing investor services, capital partnerships, specialist expertise, and technology solutions.
What you will do
- Analyze vulnerabilities from enterprise scanning, EDR, application security testing, penetration testing, and threat intelligence sources.
- Assess CVEs, vendor advisories, attack vectors, exploitability, business impact, mitigation options, and residual risk.
- Partner with infrastructure, cloud, application, platform, and engineering teams to develop and evaluate remediation strategies.
- Design and improve vulnerability and security configuration management capabilities, including secure configuration baselines and automated compliance monitoring.
- Integrate configuration findings with vulnerability management workflows to improve cyber-risk visibility and prioritization.
- Act as a technical escalation point, provide subject-matter expertise, and mentor cybersecurity team members.
Requirements
- 7+ years of cybersecurity experience, preferably in financial services or another highly regulated industry.
- Strong knowledge of enterprise infrastructure, operating systems, networking, databases, applications, and cloud platforms.
- Experience operating vulnerability management and security configuration management programs.
- Experience with vulnerability exceptions, compensating controls, risk acceptance, remediation governance, and compliance evaluation.
- Knowledge of NIST, ISO 27001, OWASP, NYDFS Part 500, DORA, CIS, and STIG frameworks and regulations.
- Strong analytical, problem-solving, stakeholder management, communication, and influencing skills.
Nice to have
- CISSP or equivalent certification.
- Automation and scripting experience with PowerShell, Python, or similar tools.
- Advanced PowerPoint and Excel skills for executive risk reporting, dashboards, metrics, and presentations.
Culture & Benefits
- Long-term employment within a private partnership with a 200-year history.
- Collaborative environment focused on collective problem-solving, knowledge sharing, and mentoring.
- Benefits include long-term savings, healthcare, income protection, professional development, and paid time off.
- Compensation includes base salary, discretionary bonuses, and profit-sharing.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
8 дней назад
Security Engineer (AI)
95 000 - 110 000$
13 дней назад
Security Automation and Orchestration Engineer (Cybersecurity)
70 000 - 140 000$
12 дней назад
Security Engineer - Federal (FieldOps)
134 000 - 167 000$
14 дней назад
Security Engineer - Cloud Security Controls
91 000 - 185 900$
14 дней назад
Business Information Security Officer (Cybersecurity)
180 000 - 200 000$
13 дней назад
Security Engineer - Vice President - IAM - Jersey City (PKI)
130 000 - 250 000$