- Full Time
- Company: Velera
- United States (Remote)
Velera
PSCU/Co-op Solutions is now Velera! PSCU and Co-op Solutions became a single entity on January 2, 2024, and our new company name was announced on May 7, 2024. Our new brand represents our combined company’s shared mission and unique ability to drive velocity and positive momentum for credit union success in a new era of financial services.
The Opportunity:
As a Risk Mitigation Engineer II, Vulnerability Management, the incumbent will be responsible for assisting in the core, day-to-day functions of the Risk Mitigation (RM) team. In this role the incumbent acts as a technical support specialist within the larger RM team. This role will promote directives within the team to support IT infrastructure and application teams across the organization to ensure a risk-based approach to vulnerability management is embedded into their daily work. The RM Engineer II will focus the majority of their time on hands-on solutions and tools, such as those that are typically used for monitoring, assessment, tracking, and reporting. The ideal candidate will have excellent technical, organizational, and communication (written and verbal) skills, along with a willingness to assist where needed with overall team tasks. A sense of ownership, and a want and willingness to learn, assume new responsibilities, and an overall initiative-based drive are keys to success in this position and successive/advanced roles within the team.
Day in the Life:
- Assume a critical, supportive, technical role within the RM team. Assist both technical and team initiatives to shape and guide the focus and execution of solutions that provide effective, accurate, comprehensive, and actionable reporting, best practices configurations, timely patching, etc., toward a goal of overall reductions in vulnerabilities across all department accountable technologies.
- Under RM guidance, collaborate with Security and IT Infrastructure to maintain or implement risk-based, actionable remediation requirements for all supported, auditable technologies.
- Assist with or directly maintain and support vulnerability management programs that include regular scans and assessments of the organization’s systems, network and applications to identify security vulnerabilities.
- Improve reporting maturity through automation, consolidation, and other techniques as necessary.
- Work with multiple teams to align scanning, reporting and tracking in compliance with industry best-practices, regulations, and standards related to vulnerability management, such as PCI-DSS, SOC II, NIST, CIS benchmarks, or other compliance regulations required by either industry mandates or Velera standards.
- Perform or assist with recurring and on-demand scanning of organization systems and cloud environments.
- Resolve or assist with the resolution of information security vulnerability findings, including zero-day or targeted threats, and/or internal or external weaknesses in IT platforms, appliances, systems, services, applications or configurations.
- Maintain detailed documentation regarding Velera’s threat management standards, policies, and procedures
- Improve and automate, wherever possible, existing vulnerability management systems
Qualifications:
- Associates degree or competency-based degree in a related IT discipline preferred
- Relevant industry certifications such as S+, CISSP, CISM, or equivalent are a plus
- 2+ years of experience in vulnerability management / compliance monitoring or the equivalent as derived from participating in a role that directly included those responsibilities
- Experience in vulnerability scanning, penetration testing, network admission control, and/or SIEM – direct experience with VM scanning tools like Nessus, Rapid7, Qualys, etc.
- Experience with IT controls monitoring for regulatory and compliance requirements
- Knowledge of vulnerability data management and reporting process automation
- Knowledge of OWASP tools and methodologies a plus
- Knowledge of scripting languages (i.e., Powershell, Python, YAML, etc.) a plus
- Experience with ServiceNow a plus
- Functional knowledge of information security best practices
- Functional knowledge of ITIL principles and practices
- Knowledge of and/or experience with technical concepts such those associated within common server operating systems, cloud computing, automation, networking, and application development
About Velera
At Velera we are committed to fostering a workplace where every employee feels valued, respected, and connected. We understand, attract and engage a diverse workforce where every employee can live up to their full potential; ensuring that our employee base reflects the consumers we serve. The result of this effort is an inclusive environment where diverse talent thrives. We strive to foster a safe and inclusive work environment for people to bring their authentic selves in order to build a better community within our company and with our partners. Learn more about our commitment to Diversity, Equity, and Inclusion HERE!
Pay Equity
$75,800.00
to
$96,700.00
Actual Pay will be adjusted based on experience and other job-related factors permitted by law.
Great Work/Life Benefits!
- Competitive wages
- Medical with telemedicine
- Dental and Vision
- Basic and Optional Life Insurance
- Paid Time Off (PTO)
- Maternity, Parental, Family Care
- Community Volunteer Time Off
- 12 Paid Holidays
- Company Paid Disability Insurance
- 401k (with employer match)
- Health Savings Accounts (HSA) with company provided contributions
- Flexible Spending Accounts (FSA)
- Supplemental Insurance
- Mental Health and Well-being: Employee Assistance Program (EAP)
- Tuition Reimbursement
- Wellness program
- Benefits are subject to generally applicable eligibility, waiting period, contribution, and other requirements and conditions
Velera is an Equal Opportunity Employer. We consider applicants without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, or membership in any other group protected by federal, state or local law.
Similar Remote Jobs
-
Freelance Copywriter
CanvaJapan (Remote)- Freelance
-
Head of Engineering – Risk
MercuryUnited States (Remote)- Full Time
-
Risk Operations Analyst
StripeUnited States (Remote)- Full Time
-
Credit Risk Analyst
PhilipsUnited States (Remote)- Full Time
-
Quality Assurance Engineer
SphereCommerceUnited States (Remote)- Full Time
-
Fraud Investigator – Prevent
MonzoUnited Kingdom (Remote)- Full Time
-
Manager, Leaves and Accommodations
TwilioUnited States (Remote)- Full Time