What are the responsibilities and job description for the System Analyst Vulnerability Management position at Con Edison Company of New York?
Overview
Come join us at Con Edison as a System Analyst - Vulnerability Management! In this pivotal role, you will lead our vulnerability management response efforts, continuously enhancing application security workflows and processes. You'll be at the forefront of configuring and running vulnerability scans, assessing and prioritizing vulnerabilities, and coordinating with application teams to ensure robust security practices. Your expertise will be crucial in communicating risk to stakeholders, remediating vulnerabilities, and staying updated on the latest cybersecurity developments. If you're passionate about application security and eager to make a significant impact, we invite you to bring your skills and dedication to our team.Responsibilities
Core Responsibilities- Lead vulnerability management response efforts and events
- Continuously build and implement improvements to application security workflows and processes, including vulnerability scanning, assessment, prioritization, and tracking/remediation
- Develop new and update existing application vulnerability management policies, procedures, runbooks, and other documentation
- Configure and run vulnerability scans of applications using industry-standard tools
- Coordinate with application teams on scanning and application security practices, providing governance, oversight, and technical expertise
- Remain up to date on cybersecurity news and emerging vulnerabilities
- Assess and prioritize vulnerabilities for impact and cyber risk
- Communicate vulnerability statuses and associated risk to stakeholders and leadership
- Coordinate with stakeholders to remediate vulnerabilities timely, providing technical expertise and support as needed
- Ensure proper escalation and communication of critical vulnerabilities or other issues to leadership in a timely fashion
- Keep abreast of current developments in application security and vulnerability management and propose recommendations to mitigate risk
- Perform validation that vulnerabilities have been remediated/mitigated, working with other teams as required
- Collect, analyze, create dashboards, and report on vulnerability metrics
- Continuously learn, improve, and hone your skills to deliver advanced assessments
- Present to executive-level stakeholders
- Conduct presentations and education efforts on application security/vulnerability management and best practices
- Serve as a technical SME for more junior members of the vulnerability management team
Qualifications
Required Education/Experience- Bachelor's Degree and with a minimum of two (2) years of cybersecurity, application development, or other related IT experience or
- Associate's Degree and with a minimum of four (4) years of cybersecurity, application development, or other related IT experience or
- High School Diploma/GED and with a minimum of five (5) years of cybersecurity, application development, or other related IT experience
- Minimum of 3 years of experience in IT (preferably in Cyber security) is required.
- Previous Computer Incident Response Team (CIRT)/Cyber Security Operations Center (CSOC), and incident management experience is required.
- Previous Computer Incident Response Team (CIRT)/Cyber Security Operations Center (CSOC), and incident management experience is required.
- Strong knowledge of network protocols, network analysis tools, and network architecture is preferred.
- Scripting experience is preferred.
- Knowledge of security tools is preferred.
- Proficiency in Microsoft Office suite is required.
- Excellent oral and written skills.
- Ability to handle multiple assignments and meet deadlines simultaneously.
- Ability to present at different levels of management.
- Driver's License Required
- Must be able to respond to Company emergencies by performing a System Emergency Assignment to restore service to our customers.
- Must be able and willing to travel within Company service territory, as needed.
- Must be available 24/7, on call, and/or participate in off-hour emergency response activities as required.