Vulnerability Management Analyst at WTW CO
Taguig, Metro Manila, Philippines -
Full Time


Start Date

Immediate

Expiry Date

15 Sep, 26

Salary

0.0

Posted On

17 Jun, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Vulnerability Scanning, Remediation Tracking, Network Architecture, Cloud Security, CI/CD Pipeline Security, PowerBi, Excel, Stakeholder Engagement, Risk Management, Scripting, OSI Layers, SDLC, Cyber Operations, Regulatory Compliance, Technical Communication, Problem Solving

Industry

Financial Services

Description
As a Vulnerability Management Analyst at WTW, you will work as part of the Vulnerability Management team, supporting WTW's Vulnerability Management lifecycle to ensure that vulnerability related risks are managed effectively and in a timely manner. The Vulnerability Management Analyst will collaborate closely with both the Cyber Offensive and Defensive teams to ensure that WTW’s attack surface risk is addressed. Your work will involve close coordination with other areas of Offensive and Defensive security, acting as a Vulnerability Management SME supporting these teams as well as engaging with the wider business.  As well as supporting regular BAU activities, such as ensuring the smooth operation of scanning, reporting, prioritization, remediation tracking as well as communicating with the business, the VM Analyst will have opportunities to work on various projects to constantly improve the VM function, as well as building expertise in different areas to support the team. Regular training, staying on top of industry trends and understanding their implications will be critical in keeping WTW resilient against evolving threats.  The Role Responsible for supporting the Vulnerability Management and ICS teams to help reduce vulnerability related attack surface risk within WTW. * Expertise in Scanning/CMDB Tools: Develop/enhance expertise in WTW scanning tools (and supporting tools) and support scanning, reporting and data verification activities, to ensure high quality and accurate data for the business and stakeholders * Tracking Vulnerability Remediation: Attending or leading remediation calls with different areas of the business in order to track and drive vulnerability remediation efforts, escalating where necessary * Supporting internal projects: Support existing and upcoming internal projects, to enhance WTW’s ability to identify, prioritize and respond to vulnerabilities of varying risk within different areas of the business * Collaboration with Business/Teams/Stakeholders: Work alongside senior members of both offensive (Red Team, Security Testing Team) and defensive teams. Help ensure that findings from vulnerability scans are communicated clearly to the business and any identified gaps are tracked and addressed * Explore Emerging Technologies: Stay informed on the latest vulnerabilities and attack techniques in order to bolster WTW’s vulnerability remediation efforts * Support BAU Processes: Work as an integral part of the team in order to support the WTW vulnerability management lifecycle, built into the company’s corporate controls. * Report Findings and Metrics: Assist in ensuring vulnerability remediation reports are accurate and fit for purpose, as well as working to ensure that monthly metrics that are provided to stakeholders are accurate, effective and timely  * Continuous Learning: Take advantage of training opportunities available within WTW, as well as self-learning to remain abreast of emerging vulnerability related threats as well as vulnerability related technical details * Assist with Audits – Assist with both internal and external audits where required

How To Apply:

Incase you would like to apply to this job directly from the source, please click here

Responsibilities
Support the vulnerability management lifecycle by coordinating scanning, reporting, and remediation efforts across offensive and defensive security teams. Act as a subject matter expert to reduce attack surface risk and ensure accurate reporting of metrics to stakeholders.
Loading...