Demo

Threat and Vulnerability Analyst

Southern Company
Atlanta, GA Full Time
POSTED ON 1/22/2025
AVAILABLE BEFORE 3/22/2025

SCS Technology Security

IT Security Analyst, Special/Senior

Threat and Vulnerability Analyst

Job Description

At Southern Company, our core objective is to ensure safe and reliable computing environment for the consumers of our services, both internally and externally. Our complex environment generates a constant stream of challenges which require continual innovation with an evolving set of technologies. Keeping the network safe and reliable ensures that our users stay connected with our applications, products and services. Southern Company is committed to supporting the professional development and growth of its employees and fosters an environment of diversity, equity, and inclusion.

Position Overview:

Southern Company is seeking a passionate and experienced Team Lead for our Vulnerability Management Program. This is a technical, hands-on role that requires the ability to assess threats, analyze risks and advise strategies to mitigate exposure.

This position is responsible for leading and conducting day-to-day continuous vulnerability management operations and attack surface assessments focused on identifying exposed risks. Work outputs will support implementation of security technologies and controls to improve defensive posture, implementation of processes in support of investigations, and development of detection capabilities.

The ideal candidate will have a have a background in vulnerability management or patch management, be well versed in risk assessments, and have experience working with cross functional teams to build consensus.

Qualifications:

  • Bachelor’s degree in computer science, technology, engineering or security-related field or equivalent experience
  • Minimum 7 years IT or security experience
  • Previous experience supporting vulnerability or patch management programs
  • Experience working with vulnerability scanning tools
  • Understanding of OWASP common vulnerabilities and testing methodologies
  • Understanding of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, code injection, race conditions, covert channel, replay, return-oriented attacks)
  • Understanding and familiarity with different operating systems (e.g., Windows and LINUX/UNIX systems)
  • Knowledge of IT security / hardening best practices; including but not limited to operating systems, web applications, and network devices.
  • Ability to effectively organize tasks, manage multiple priorities/details, meet schedules, and deliver on commitments
  • Experience driving discussions and consensus across a broad group of stakeholders and cross functional teams regarding patching, security recommendations, and mitigations strategies
  • Solid verbal and written communication skills required
  • Strong interpersonal skills and experience interacting with technical and non-technical stakeholders
  • Ability to work independently and with a team

Job Responsibilities:

  • Lead day-to-day operations of the vulnerability management program, including reviewing data, processing reports, escalating findings to key stakeholders, tracking remediation of identified risks and mitigation strategies, assessing mitigation plan dependences, and analyzing trends
  • Drive execution of zero-day workflows and procedures
  • Maintain knowledge of the current security threat landscape by monitoring related internet postings, intelligence reports and other sector specific sources as necessary
  • Maintain awareness of latest available exploits and feasibility to create an exploit
  • Maintain awareness of publicly disclosed vulnerabilities (CVEs) and potential vulnerabilities (rumors, blogs, partial public analysis).
  • Map vulnerability assessment results to asset inventory and key stakeholders
  • Calculate prioritization based on assessment of risk
  • Identify and recommend appropriate measures to manage and remediate vulnerability risk with the focus on reducing potential impacts
  • Support development of vulnerability metrics and remediation-related dashboards and reports
  • Understand enterprise policies and advise policies and technical standards with specific regard to vulnerability management, scanning procedures and secure configuration
  • Coordinate with key business partners to understand, prioritize, and coordinate vulnerability remediation activities
  • Collaborate with peers from across the organization and maintain excellent working relationships with key partners across Technology Organization functions and business partners
  • Understand business requirements and work with business partners to define appropriate solutions, meeting both security mandates and business needs
  • Demonstrate Southern Company values of Safety First, Unquestionable Trust, Superior Performance, and Total Commitment

Job Requirements :

  • Must be willing and able to obtain and maintain US government security clearance
  • Required to submit to a thorough background examination
  • Ability to understand business requirements and present appropriate solutions
  • Ability to work independently or within a team
  • Demonstrated critical, independent thinking; demonstrated ability to conceive and present creative solutions
  • Must pass NERC CIP & Insider Threat Protection background checks
  • One or more relevant industry certifications (GSEC, CISSP, GCIA, GMON, GCFA, GCFE, GREM, CEH, OSCP)
  • Occasional travel to local and regional locations in pursuit of job duties and requirements

Southern Company (NYSE: SO) is a leading energy provider serving 9 million residential and commercial customers across the Southeast and beyond through its family of companies. Providing clean, safe, reliable and affordable energy with excellent service is our mission. The company has electric operating companies in three states, natural gas distribution companies in four states, a competitive generation company, a leading distributed energy infrastructure company with national capabilities, a fiber optics network, and telecommunications services. Through an industry-leading commitment to innovation, resilience, and sustainability, we are taking action to meet our customers’ and communities’ needs while advancing our commitment to net zero emissions by 2050. Our uncompromising values ensure we put the needs of those we serve at the center of everything we do and are the key to our sustained success. We are transforming energy into economic, environmental and social progress for tomorrow. Our corporate culture and hiring practices have earned the company national awards and recognition from numerous organizations, including Forbes, Military Times, DiversityInc, Black Enterprise, J.D. Power, Fortune, Human Rights Campaign and more. To learn more, visit www.southerncompany.com .

Southern Company invests in the well-being of its employees and their families through a comprehensive total rewards strategy that includes competitive base salary, annual incentive awards for eligible employees and health, welfare and retirement benefits designed to support physical, financial, and emotional/social well-being. This position may also be eligible for additional compensation, such as an incentive program, with the amount of any bonus/awards subject to the terms and conditions of the applicable incentive plan(s). A summary of the benefits offered for this position can be found here https://seo.nlx.org/southernco/pdf/SOCO-Benefits.pdf . Additional and specific details about total compensation and benefits will also be provided during the hiring process.

Southern Company is an equal opportunity employer where an applicant's qualifications are considered without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity or expression, or any other basis prohibited by law.

Job Identification: 9749

Job Category: Cybersecurity

Job Schedule: Full time

Company: Southern Company Services

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Threat and Vulnerability Analyst?

Sign up to receive alerts about other jobs on the Threat and Vulnerability Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Southern Company

Southern Company
Hired Organization Address Groom, TX Full Time
Compliance Specialist – SPC Wind Sites The Compliance Specialist is expected to reside in the Central US (Kansas, Oklaho...
Southern Company
Hired Organization Address Atlanta, GA Full Time
Job Details Job Description Data Analytics Analyst JOB SUMMARY The Data and Analytics team within Supply Chain Managemen...
Southern Company
Hired Organization Address Atlanta, GA Full Time
Job Details Job Description ASCEND PROJECT OVERVIEW Southern Company is committed to building the future of energy for t...
Southern Company
Hired Organization Address Atlanta, GA Full Time
Job Details Job Description IT Infrastructure Analyst Purpose: The Infrastructure Operations Center (IOC) is responsible...

Not the job you're looking for? Here are some other Threat and Vulnerability Analyst jobs in the Atlanta, GA area that may be a better fit.

Principal Threat Analyst

Optiv, Decatur, GA

Threat Intelligence Analyst (Remote)

DivIHN Integration Inc, Atlanta, GA

AI Assistant is available now!

Feel free to start your new journey!