Vulnerability Management Engineer

placeRemote calendar_month 

Overview:

We are CONNECTING HEALTH AND WEALTH. Come be part of remarkable.

How you can make a difference

Lead area of responsibilities coordinating with broader Security Technology and Tools team within Risk and Security. Drive initiatives forward influencing and leading Team Members both within their immediate business unit and across the organization.
Set strategic direction and communicate security standards to Team Members to ensure that HealthEquity security risks, threats, and issues are documented, addressed, and mitigated. Able to build relationships among various technology and business leaders within business goals and objectives balancing business opportunity with security risk.

Highly proficient knowledge of security controls based on industry information security standards (NIST Cybersecurity Framework, ISO27001/2, and CIS Top 20 Controls). Reports to the Director, Security Technology and Tools and works collaboratively with technology and business SMEs and corresponding leadership

What you’ll be doing (Job Duties & Responsibilities)
  • Reviewing and analyzing vulnerability data to identify trends and patterns.
  • Facilitating meetings as part of the Vulnerability Management processes, as needed.
  • Advising and assisting Vulnerability Remediation Team(s) on prioritization of vulnerability remediation.
  • Performing risk-based technical assessments on technical vulnerabilities.
  • Assist Vulnerability Remediation teams to develop remediation plans.
  • Lead new technologies to ensure a comprehensive security tool stack configuration to address threats and gaps.
  • Experience implementing and performing security risk assessments for on-premise and cloud-based services
  • Build and present cases on new technologies to address new and emerging risks, as well as gaps identified by external and internal assessors.
  • Lead security controls and requirements identification for large and small technology and business initiatives. Strong IT risk, security and compliance experience to drive structured analysis.
  • Experience in and ability to lead security metrics consolidation and development efforts to measure the Cybersecurity program status according to plan.
  • High proficiency with leading information security frameworks and best practices (NIST Cybersecurity Framework, ISO27001/2, and CIS Top 20 Controls), and experience applying frameworks to identify appropriate security measures
  • Automation, scripting, and business intelligence experience a must (PowerShell, Python, PowerBI, Tableau, and API configuration experience) highly preferred.
  • Strong experience with Cybersecurity policy and standard updates and ability to self-manage updates with no supervision
  • Build strong relationships with other technical personnel so that they are willing to reach out for your opinion / thoughts / insight on security things
  • Contribute to the overall direction/mission/purpose of the Technical Security team
  • Assist in the identification, design, and implementation of security tools that build customer trust in Technical Security services
  • Assist in the identification, design, and implementation of security tools that enable the identification of "concerning" activity around technical services.
What you will need to be successful (Skills, Knowledge, & Experience)
  • 4+ years of experience for an engineer-level role
  • Experience with Vulnerability Management processes.
  • Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
  • Knowledge of application vulnerabilities.
  • Skill in conducting vulnerability scans and recognizing vulnerabilities in security systems.
  • Experience in consulting, advisory or assessment work preferred
  • CISSP or similar security certification preferred
  • Excellent interpersonal skills including the ability to interact efficiently with individuals at all levels; both internal and external
  • Lead multiple tasks/projects simultaneously within inflexible time frames
  • Ability to adapt to frequent priority changes
  • Self-motivated with strong organizational skills and superior attention to detail
  • Possess an in-depth knowledge of securing organizations, cloud-based resources, networks, systems, databases, applications, and processes
  • Capable of developing strong collaborative working relationships with internal partners and able to effectively engage and build consensus among cross-functional teams
  • Demonstrate excellent communication and listening skills
  • Operates with a commitment to customer service excellence
  • Possess a sincere desire to learn, grow, and go beyond personal capabilities

#LI-Remote

This is a remote position.

Salary Range: $92000.00 To $142000.00 / year

Benefits & Perks:

The compensation range describes the typical minimum or maximum base pay range for this position. The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives as part of the total compensation package, in addition to a full range of benefits including:

  • Medical, dental, and vision
  • HSA contribution and match
  • Dependent care FSA match
  • Uncapped paid time off
  • Adventure accounts
  • Paid parental leave
  • 401(k) match
  • Personal and healthcare financial literacy programs
  • Ongoing education & tuition assistance
  • Gym and fitness reimbursement
  • Wellness program incentives

Come be your authentic self:

Why work for HealthEquity

HealthEquity has a vision that by 2030 we will make HSAs as wide-spread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth. Join us and discover a work experience where the person is valued more than the position.

Click here to learn more.

Come be your authentic self

HealthEquity, Inc. is an equal opportunity employer that is committed to inclusion and diversity. We take affirmative action to ensure equal opportunity for all applicants without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, veteran status, or other legally protected characteristics.

HealthEquity is a drug-free workplace. For more information about our EEO policy, or about HealthEquity’s applicant disability accommodation, drug-free-workplace, background check, and E-Verify policies, please visit our Careers page.

HealthEquity is committed to your privacy as an applicant for employment. For information on our privacy policies and practices, please visit HealthEquity Privacy.

placeRemote
By Light supports defense, civilian, and commercial IT customers worldwide. Position Overview: Our firm is seeking an experienced Operations Manager to oversee a mission-critical enterprise Identity and Access Management (IAM) program supporting a major...
placeRemote
operational capabilities to support customers across scientific, clinical, technological, and program management areas. Summary: Headquarters, Department of the Army (HQDA) G9, Directorate of Prevention, Resilience, and Readiness (DPRR) integrates...
electric_boltImmediate start

Identity and Access Management Architect

placeRemote
backgrounds and experiences. The Opportunity Valvoline has a rewarding opportunity as an Identity and Access Management (IDAM) Architect. In this role, you will be responsible for the overall architecture, design and solutioning of IDAM platforms along...