What are the responsibilities and job description for the Vulnerability Management Application Security Lead position at Berkley Technology Services?
Company Details
Company URL: https://www.berkleytechnologyservices.com/
Berkley Technology Services (BTS) is the dynamic technology solution for W. R. Berkley Corporation, a Fortune 500 Commercial Lines Insurance Company. With key locations in Urbandale, IA and Wilmington, DE, BTS provides innovative and customer-focused IT solutions to the majority of WRBC’s 60 operating units across the globe. BTS’s wide reach ensures that ideas and opinions are considered at every level of the organization to guarantee we find the best solutions possible.
Driven by a commitment to collaboration, BTS acts as consultants to our customers and Operating Units by providing comprehensive solutions that not only address the challenge at hand, but proactively plan for the “ What’s Next ” in our industry and beyond.
With a culture centered on innovation and entrepreneurial spirit, BTS stands as a community of technology leaders with eyes toward the future -- leaders who truly care about growing not only their team members, but themselves, and take pride in their employees who shine. BTS offers endless ways to get involved and have the chance to grow your career into a wide range of roles you'd never known existed. Come join us as we push forward into the future of industry leading technological solutions.
Berkley Technology Services: Right Team, Right Technology, Simple and Secure.
Responsibilities
The Vulnerability Management Application Security Lead works within Berkley’s Information Security team, interacting directly with stakeholders to address issues related to remediation of vulnerability scanning and assessment. The Vulnerability Management Analyst’s support activities are focused on helping key stakeholders understand their vulnerability results, providing guidance on the remediation of failing threats, and evaluating false positives.
Maintain and improve upon, as necessary, the existing vulnerability management program, including maintenance of documents, procedures, reporting, and stakeholder communications. Provide guidance to stakeholders in support of vulnerability management services, which includes, but is not limited to, sharing goals and road maps of vulnerability management. Analysis and validation of scan/assessment results communicated to clients through reporting and results-review meetings. Provide stakeholders with remediation recommendations and guidance, up to and including remediation tracking and reporting. Provide stakeholders reports that provide the most value based on security maturity and established vulnerability management goals. This requires the ability to be adaptive in report parameters and formats depending on stakeholder needs and target audience. Ability to use analyze large amounts of data using Microsoft and other business tools to report on enterprise level vulnerability data.
Key Responsibilities
Company URL: https://www.berkleytechnologyservices.com/
Berkley Technology Services (BTS) is the dynamic technology solution for W. R. Berkley Corporation, a Fortune 500 Commercial Lines Insurance Company. With key locations in Urbandale, IA and Wilmington, DE, BTS provides innovative and customer-focused IT solutions to the majority of WRBC’s 60 operating units across the globe. BTS’s wide reach ensures that ideas and opinions are considered at every level of the organization to guarantee we find the best solutions possible.
Driven by a commitment to collaboration, BTS acts as consultants to our customers and Operating Units by providing comprehensive solutions that not only address the challenge at hand, but proactively plan for the “ What’s Next ” in our industry and beyond.
With a culture centered on innovation and entrepreneurial spirit, BTS stands as a community of technology leaders with eyes toward the future -- leaders who truly care about growing not only their team members, but themselves, and take pride in their employees who shine. BTS offers endless ways to get involved and have the chance to grow your career into a wide range of roles you'd never known existed. Come join us as we push forward into the future of industry leading technological solutions.
Berkley Technology Services: Right Team, Right Technology, Simple and Secure.
Responsibilities
The Vulnerability Management Application Security Lead works within Berkley’s Information Security team, interacting directly with stakeholders to address issues related to remediation of vulnerability scanning and assessment. The Vulnerability Management Analyst’s support activities are focused on helping key stakeholders understand their vulnerability results, providing guidance on the remediation of failing threats, and evaluating false positives.
Maintain and improve upon, as necessary, the existing vulnerability management program, including maintenance of documents, procedures, reporting, and stakeholder communications. Provide guidance to stakeholders in support of vulnerability management services, which includes, but is not limited to, sharing goals and road maps of vulnerability management. Analysis and validation of scan/assessment results communicated to clients through reporting and results-review meetings. Provide stakeholders with remediation recommendations and guidance, up to and including remediation tracking and reporting. Provide stakeholders reports that provide the most value based on security maturity and established vulnerability management goals. This requires the ability to be adaptive in report parameters and formats depending on stakeholder needs and target audience. Ability to use analyze large amounts of data using Microsoft and other business tools to report on enterprise level vulnerability data.
Key Responsibilities
- Lead Security Initiatives: Spearhead and enhance our application security efforts, including penetration testing and static code analysis.
- Innovate and Optimize: Evaluate and implement improvements to our security tools and explore new technologies to strengthen our security posture.
- Code Analysis and Remediation: Lead projects to continuously analyze source code, identify vulnerabilities, and implement remediation strategies.
- Compliance Management: Oversee the enterprise-wide compliance scanning process to quickly identify and address potential risks.
- Stakeholder Communication: Regularly update and secure buy-in from global engineering, business operating units, security management, and senior leadership teams on the status of Application Security projects.
- Experience: Minimum of 5 years in Information Security or a related field, with expertise in security compliance, penetration testing, vulnerability management, and static code analysis.
- Leadership: Prior experience in project leadership or as a team lead is preferred.
- Education: Bachelor’s degree in Computer Science, Information Security, Network Engineering, or a related technical discipline (or equivalent experience).
- Technical Proficiency: Skilled in commonly used penetration testing tools, web application scanning tools, and static code analysis tools (e.g., Veracode, Fortify, Checkmarx).
- Stakeholder Engagement: Proven ability to engage and secure buy-in from business, technical, and executive stakeholders.
Salary : $88,000 - $154,000