At a Glance
- Tasks: Join our team to identify and mitigate cybersecurity vulnerabilities globally.
- Company: ION is a leading provider of trading software and analytics, trusted by top corporations worldwide.
- Benefits: Enjoy a dynamic work environment with opportunities for growth and remote work options.
- Why this job: Be part of a diverse team making a real impact in cybersecurity and technology.
- Qualifications: 5+ years in Vulnerability Management; relevant certifications like Security+, CCSP, or CISSP preferred.
- Other info: Work with cutting-edge technology in a supportive and inclusive culture.
The predicted salary is between 48000 - 84000 £ per year.
The Vulnerability Management Analyst is a global role within ION’s central services division and will support the Group Security strategy and operational excellence through the identification, mitigation and remediation of information security vulnerabilities, misconfigurations and risks to the business. This role reports to the Vulnerability Management Manager who reports to the Global Head of IT Security. As a member of the ION Security team, you will build and lead a team of Security professionals specialising in Vulnerability Management along with managing the partners and technology vendor deliverables and building and owning the strategy to deliver a world class Vulnerability Management program.
The candidate must understand their role in the broader vulnerability management program and your team will regularly perform discovery scanning, risk/exposure assessments, mitigation support activities, continuous validation assessments, and lessons learned workshops and improvement projects to continuously improve our process across Group Security and all other Verticals. We are looking for a diligent, dedicated, creative and motivated individual. Excellent communication skills are a must, and the role holder will be expected to cultivate working relationships with other teams and colleagues of varying technical ability. The role would suit a technically strong candidate with an extensive cybersecurity background, at least 5+ years working in a security role, with focus on Vulnerability Management.
Responsibilities:
- This role may require work-out of hours in support of 24x7 globally coordinated operation.
- Personnel Management.
- Align deliverables and objectives to OKRs.
- Be the escalation point for security Tooling issues and critical security breaches.
- Manage Vulnerability Management tooling to ensure coverage/availability/efficacy.
- Drive improvements and feature enhancement to ensure ROI.
- Configure, tune, maintain & operate key vulnerability management controls.
- Management reporting – real-time metrics and scheduled reports.
- Drive process/procedure changes accordingly.
- Ensure quality of ticketing & runbook maintenance.
- Cultivate and maintain strong vendor relationships.
- Participate in CAB, Tool review or Architecture Review Boards (ARBs).
As a member of the ION IT Security Team, it is expected that the person in this role will:
- Execute ongoing, operational business-as-usual (BAU) tasks to meet management-defined KPIs and SLAs, and deliver security projects in line with management-defined priorities and deadlines.
- Stay current with the latest security news, threats, intelligence, tactics, techniques, and vulnerabilities.
- Research and analyze new threats and vulnerabilities to determine exposure.
- Assist and/or lead efforts to isolate, contain, respond to, and recover from security incidents.
- Identify, review, prioritize, plan, coordinate, and follow-up on the remediation of vulnerabilities.
- Create and maintain documentation for systems, including design and operation.
- Review vulnerability management systems, configurations, and processes to ensure and report on compliance with ION policy, client requirements, audit controls, regulations, and industry best practices.
- Provide best practice security recommendations to IT and other teams within ION, based on review results.
Experience, Skills and Qualifications:
- Degree/diploma/certifications in a technology-related field and/or relevant working experience; highly desired certifications include: Security+, CCSP, CEH, GCIH, GMON, CASP, or CISSP.
- Minimum of 5 years’ experience in Vulnerability Management within large organizations.
- Excellent track record of building a Vulnerability Management program on a global scale with knowledge on vulnerability assessments, remediation and mitigation activities.
- Technical Security/Engineering/Compliance background with a previous track record of building risk management framework and applying to an existing vulnerability management program.
- Strong technical expertise in implementing a Prioritization formula to vulnerabilities and misconfigurations and translating these into risks.
- Excellent knowledge of Vulnerability Management frameworks such as NIST/SANS.
The following general characteristics are required:
- A team player with the ability to work independently and unsupervised.
- Ability to own delegated tasks and see them through to completion.
- Ability to manage time and prioritize work to maximize productivity.
- Excellent reporting and presentation skills are essential for this role.
- Excellent communication skills (both written and verbal).
- Exceptional attention to detail and quality.
- Excellent problem-solving techniques and trouble analysis skills.
- Experience in design and publishing Security Standards & Policies.
- Experienced in running global Bug Bounty/VDP programs.
- Experienced in Pen Testing, from scope, schedule, findings, remediation and risk registration.
The candidate should have a good knowledge of:
- Vulnerability Management concepts, controls, and best practices for all Operating systems & asset types, (e.g. workstations, endpoints, mobile, servers either Windows/Linux, cloud instances, etc.).
- Vulnerability Management tools (Tenable/Rapid7/Qualys).
- Cloud Security compliance (IaaS, PaaS, SaaS) and misconfigurations.
- Multi-platform endpoints, infrastructure and XaaS vulnerability management deployments.
- General IT networking concepts, protocols, standards and network security concepts, controls, and best practices.
- Forensic investigation techniques.
- Prior experience deploying, configuring, managing, and/or operating security technologies is preferred, such as endpoint security (e.g. AV/EPP/EDR), SIEM, DLP, SWG, CASB, UEBA, IDS, IPS, firewalls, IAM/PIM/PAM, Vulnerability Management, MDM, etc.
- Proven knowledge of compliance, regulatory practices and experience managing audits.
About us: We’re a diverse group of visionary innovators who provide trading and workflow automation software, high-value analytics, and strategic consulting to corporations, central banks, financial institutions, and governments. Founded in 1999, we’ve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world. Over 2,000 of the world’s leading corporations, including 50% of the Fortune 500 and 30% of the world’s central banks, trust ION solutions to manage their cash, in-house banking, commodity supply chain, trading and risk. Over 800 of the world’s leading banks and broker-dealers use our electronic trading platforms to operate the world’s financial market infrastructure. ION is a rapidly expanding and dynamic group with 13,000 employees and offices in more than 40 cities around the globe. Our ever-expanding global footprint, cutting edge products, and over 40,000 customers worldwide provide an unparalleled career experience for those who share our vision. ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities, abilities, cultures, and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business. ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.
Vulnerability Management Analyst employer: ION Group
Contact Detail:
ION Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Vulnerability Management Analyst
✨Tip Number 1
Familiarise yourself with the latest trends in vulnerability management and cybersecurity. Follow industry leaders on social media, subscribe to relevant newsletters, and participate in online forums to stay updated. This knowledge will not only help you in interviews but also demonstrate your commitment to the field.
✨Tip Number 2
Network with professionals already working in vulnerability management or related fields. Attend industry conferences, webinars, or local meetups to connect with potential colleagues. Building these relationships can lead to valuable insights and even job referrals.
✨Tip Number 3
Showcase your technical skills by engaging in hands-on projects or contributing to open-source security tools. This practical experience can set you apart from other candidates and provide concrete examples to discuss during interviews.
✨Tip Number 4
Prepare for the interview by practising common vulnerability management scenarios and case studies. Be ready to discuss how you would approach specific vulnerabilities and the tools you would use. This preparation will help you articulate your thought process and problem-solving abilities effectively.
We think you need these skills to ace Vulnerability Management Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience in Vulnerability Management and cybersecurity. Focus on relevant roles, responsibilities, and achievements that align with the job description provided by ION.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for cybersecurity and your understanding of vulnerability management. Mention specific experiences that demonstrate your ability to build and lead teams, as well as your technical expertise.
Highlight Relevant Certifications: List any relevant certifications such as Security+, CEH, or CISSP prominently in your application. These credentials are highly desired and can set you apart from other candidates.
Showcase Communication Skills: Since excellent communication skills are essential for this role, provide examples in your application that demonstrate your ability to communicate complex security concepts to both technical and non-technical audiences.
How to prepare for a job interview at ION Group
✨Understand the Role Thoroughly
Before the interview, make sure you have a solid understanding of the responsibilities and expectations of a Vulnerability Management Analyst. Familiarise yourself with the key tasks mentioned in the job description, such as managing vulnerability management tooling and driving improvements.
✨Showcase Your Technical Expertise
Be prepared to discuss your technical background in cybersecurity, particularly your experience with vulnerability assessments and remediation activities. Highlight any relevant certifications you hold, such as Security+, CEH, or CISSP, and be ready to explain how they relate to the role.
✨Demonstrate Communication Skills
Since excellent communication skills are essential for this role, practice articulating complex technical concepts in a way that non-technical stakeholders can understand. Be ready to provide examples of how you've successfully collaborated with teams of varying technical abilities in the past.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills and ability to handle security incidents. Think of specific examples from your previous experience where you identified vulnerabilities, coordinated remediation efforts, or improved processes, and be ready to discuss them in detail.