Principal Cyber Vulnerability Engineer Dallas or Detroit metro

Principal Cyber Vulnerability Engineer Dallas or Detroit metro

03 Apr 2024
Michigan, Auburnhills, 48321 Auburnhills USA

Principal Cyber Vulnerability Engineer Dallas or Detroit metro

Principal Cyber Vulnerability Engineer The Cyber Vulnerability Operations Team consists of both the Application Security (AppSec) teams and the Vulnerability Management Operations (VM Ops) teams. Together, the Vulnerability Operations team collaborates with peers across Comerica to provide visibility into vulnerabilities within applications and infrastructure and ensures they are remediated, as well as facilitates and enforces the use of secure development practices across the bank. The Principal Cyber Vulnerability Operations Engineer role is responsible for vulnerability scanning, prioritizing vulnerabilities, and driving remediations while partnering with the application and infrastructure teams. The ideal candidate for this role will have hands-on expertise working in vulnerability management and operations and will have knowledge of tools and technologies such as Qualys, PowerBI, attack surface management, Cloud, and expertise in at least one programming language. This candidate will be experienced working with cross-functional teams in vulnerability management and prioritization and will have the ability to automate while using a programming language. The ideal candidate with have technical and non-technical risk and vulnerability assessment background in network, infrastructure, and application space, as well as experience with ServiceNow VR module added plus. CISSP/SANS/Cloud Certification desired. Position Responsibilities: Vulnerability Management Operations Perform vulnerability assessments and common baseline control scans across the Comerica environment and report on Key Risks Indicators (KRIs). Lead security vulnerabilities and risk management activities across Comerica, including identifying vulnerabilities and supporting application/system owners to manage risks/remediate vulnerabilities. Establish and mature processes around vulnerability management, remediation, and reporting. Lead key projects such as vulnerability prioritization to remediate critical key vulnerabilities. Participate in vendor evaluations and selection for vulnerability management products, such as external attack surface management. Implement and support those products on a continuous basis. Stay current on vulnerability management best practices across the industry. Administration & Reporting Develop a comprehensive set of metrics to track on enterprise risks and remediation trends and keep Management informed of them through accurate, timely, and appropriate reporting. Support monthly KRI reporting through data collection, working with application and infrastructure teams to remediate vulnerabilities. Create presentations based off KRI materials and keep Management informed of them. Technical Consulting & Communication Drive technical excellence and implementation of vulnerability management best practices in collaboration with technology teams across the enterprise. Provide consultation to and work closely with other functional infrastructure areas/departments on multiple initiatives to meet common organizational/business goals and objectives. Collaborate with business units, application and infrastructure teams, and vendors to identify, review and evaluate solution requirements. Automate existing manual processes in order to create improved processes and create faster delivery. Coach and mentor more junior team members and application teams on vulnerability remediation efforts. Risk Management Identify and communicate gaps in our vulnerability management practices. Participate in Red Team exercises to identify potential vulnerabilities proactively. Partner with application and infrastructure owners to provide consulting on vulnerability remediation to allow them to appropriately remediate large highly complex vulnerabilities within the SLA (service level agreement) and reduce risk for the bank. Develop cyber vulnerability analysis for known vulnerabilities, as well as cyber-related metrics and reporting deliverables. Equal Opportunity Employer Minorities/Women/Protected Veterans/Disabled

Related jobs

  • Field Support Infrastructure Operations Analyst III The Field Support Infrastructure Operations Analyst will work under general supervision to support all Comerica locations, including Mexico and Toronto, responsible for basic technology operations tasks, with a primary focus on the management and delivery of desktop hardware technology. This role collaborates with various technology teams, vendors, and Senior Infrastructure Operations members to identify opportunities, solve problems, resolve incidents/requests, change orders associated with operations, and provide budgetary support to management regarding resources, hardware/software. This candidate should be polished in both their written and verbal communication delivery, capable of building strong colleague relationships and self-motivated. Required to be on site 5 days a week. Primary location is Auburn Hills but will be expected to work between other various MI Locations as needed. Must be flexible as this position is expected to rotate in a shared 24/7 on-call schedule with MI Field Services Team. Polite and Friendly Attitude – A positive demeanor, friendliness, and self-assuredness are essential traits. Colleagues should feel comfortable approaching the candidate for assistance. Multitasking and Time Management – This role often involves juggling multiple tasks simultaneously. Strong multitasking skills and effective time management are valuable. Computer Literacy and Tech Savviness – Proficiency in basic computer skills and a talent for technology are fundamental. This position should be comfortable navigating various devices and platforms. Position Responsibilities: System Operations Perform Level 0 and Level 1 support to associates and document steps taken in incidents and service requests. Identify potential operational issues in projects, request fulfillment and individual assignments. Monitor operational performance and troubleshoot alerts from commercial, open source and locally developed monitoring tools. Provide system failure analysis and recovery recommendations. Participate in Business continuity planning and testing. Serve as liaison with non-technical people, operations personnel, and/or field service personnel; interact directly with customers to negotiate solutions and implementation specifics. Perform system provisioning, analysis and tuning. Support Work closely with others to perform technical analysis and make recommendation on minimally complex problems and incidents. Second line support for incident management problems and issues related to select applications. Works closely with others to identify and resolve root cause behind reported problems and issues. Assist in the development and/or maintenance of operational documentation. Conduct proactive maintenance toward select systems. Participate in the design, development, testing and implementation of enhancements required to maintain business unit success. Evaluate business processes and company policies to enhance process workflows. Provide support in a 24x7 data center and/or 24x7 on-call support. Equal Opportunity Employer Minorities/Women/Protected Veterans/Disabled

  • Job Description:

Job Details

Jocancy Online Job Portal by jobSearchi.