Vulnerability Management Analyst
5 months ago
AVEVA is a global leader in industrial software. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life - such as energy, infrastructure, chemicals and minerals - safely, efficiently and more sustainably.
We’re the first software business in the world to have our sustainability targets validated by the SBTi, and we’ve been recognized for the transparency and ambition of our commitment to diversity, equity, and inclusion. We’ve also recently been named as one of the world’s most innovative companies.
If you’re a curious and collaborative person who wants to make a big impact through technology, then we want to hear from you Find out more at
AVEVA Careers
For more information about our privacy policy and how to manage cookies, visit our
Privacy Policy
Job name: Vulnerability Management Analyst
Organization/department: CISO (Security)
Reports to: Head of Vulnerability Management
Job Overview:
The AVEVA Security team are seeking a skilled individual to join a high performing global vulnerability management team.
The Vulnerability Management Analyst is responsible for proactively identifying and managing the remediation of vulnerabilities affecting AVEVA’s infrastructure and services. This role requires a broad technical understanding and to be responsible for vulnerability detection, assessment and driving vulnerability remediation across the organisation.
Roles and Responsibilities:
- Conduct vulnerability assessments to identify known vulnerabilities and configuration weaknesses and assess the effectiveness of existing controls and recommends remedial action.- Maintain current knowledge and understanding of the threat landscape and emerging security threats and vulnerabilities.- Analyze risks associated with vulnerabilities, provide detailed reporting, and recommend actionable remediation strategies- Support compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks.- Serve as an escalation point on issues, dependencies, and risks related to vulnerability scanning and security testing.- Collaborate with multiple stakeholders to prioritize vulnerabilities based on severity, impact, and exploitability.- Support the development of AVEVA’s Vulnerability management policy, process, and procedures.- Managing the end-to-end vulnerability lifecycle from discovery to closure ensuring the relevant resolver team put in place a plan and timely remediation working with both managed service providers and internal IT and Information Security staff.- Utilising information from external vulnerability reporting tools such as Bitsight, RiskRecon, Security Scorecard and vendor vulnerability briefings determine the priority of remediations needed across the AVEVA estate.- Manage security assessment processes, including performing, tracking remediation, validating controls, measuring residual risk, and writing reports.- Coordinate and oversee remediation efforts to ensure timely and effective resolution of security vulnerabilities.
Qualifications/ Experience:
Educational Qualifications and Experience- Minimum of 5 years information and cyber security experience, and experience in IT Vulnerability Management.- Experience using vulnerability scanning tools such as Qualys, Tenable, Rapid7 and vulnerability management platforms (RiskVision, Kenna Security).- Experience managing vulnerability management findings/services for cloud environments (Amazon Web Services, Microsoft Azure, Google Cloud Platform).- Strong understanding of vulnerability management practices and methodologies. Knowledge of common vulnerability frameworks (CVSS, OWASP Top 10).-
- Working knowledge of one or more of the following - cloud technologies, internet security, networking protocols or experience with software development.- Strong analytical skills and ability to identify advanced vulnerability threats.- Knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controls.- Knowledge of and experience in developing and documenting security processes and plans.- Knowledge and experience with implementing common information security management frameworks, such as International Organization for Standardization (ISO) 2700x series, AICPA SOC2 (Service Organization Control), ITIL, COBIT and National Institute of Standards and Technology (NIST) or Centre for Internet Security (CIS) frameworks would be advantageous.
Technical Competency- Having knowledge and experience with as many of the following areas and tools is desired:
- Security certifications such as CEH, GPEN, Security+.-
- Understanding of firewall & networking devices (Cisco, Palo Alto, Checkpoint).-
- Understanding of desktop and server infrastructure (Microsoft, Linux, MacOS).-
- Vulnerability Management tools (Qualys, Tenable/Nessus, Rapid 7 Nexpose).-
- Security rating services such as BitSight, S
-
Vulnerability Management Analyst or Security
5 months ago
Kuala Lumpur, Malaysia Skill Quotient Full timeRole: Vulnerability Management Analyst or Security Analyst (Vulnerability Management) Client: Insurance Working Mode: On Site **Job Type**: 12 months contract based & Renewable/Extendable Job Location: Kuala Lumpur OR Cyberjaya Open for locals or expats that in Malaysia only, with valid EP & NOC required **JOB DESCRIPTION** - Use intelligence feeds...
-
Vulnerability Management
5 months ago
Kuala Lumpur, Malaysia Skill quotient Full time**Roles and Responsibilities**: - Use intelligence feeds such as vulnerability reports and risk assessments to rate and prioritise vulnerabilities within the AIA environment. - Document vulnerabilities which are discovered within the AIA estate and provide guidance on remediation and mitigations. - Review vulnerabilities with AIA colleagues and technology...
-
vulnerability Management
5 months ago
Kuala Lumpur, Malaysia Terrabit Consulting Sdn Bhd Full time**Note**: Skill: Vulnerability management, Security; 5 years; **Task Description**: Support & maintain the vulnerability detection & mitigation best practice Analyse vulnerability feeds & support the CDC operations with IOC/IOA based on vendor advisories, security alerts & threat trending; Detect, analyze, & acknowledged CDC operation & EDR team for latest...
-
Vulnerability Management
5 months ago
Kuala Lumpur, Malaysia Terrabit Consulting Full timeGood day!!! I came across your profile on Job portal and was immediately impressed with your experience. I think that your expertise would help us in project we’re working on. TERRABIT CONSULTING GROUP is one of the leaders in the IT Consulting industry across Asia Pacific. Founded in 2009, Terrabit Consulting began its operations in Singapore as a...
-
Vulnerability Management Assessment
5 months ago
Kuala Lumpur, Malaysia DSS Software Solutions Sdn Bhd Full timeD19494-Vulnerability Management Assessment Vulnerability Management Assessment **Job Description**: **KEY ACCOUNTABILITIES**: 1. Be part of vulnerability management team in Asia and work closely with Global domain teams across the world. security domain. tools like Qualys (DAST), BurpSuite, Silverline F5 WAF, etc. 4. Analyze and assess the impact from...
-
Desktop Vulnerability Management Analyst
5 months ago
Kuala Lumpur, Malaysia SOFT REFLEXES SDN BHD Full timeReview, test, document, implement, and track software and operation system updates and security patches in the Asia Pacific region - Provide technical support to diagnose, analyze, research, and resolve computer problems in a Windows enterprise environment - Must be able to analyze data from multiple collection points to identify computers and systems that...
-
Vulnerability Management Assessment
5 months ago
Kuala Lumpur, Malaysia Power IT Services Full time**Job title: Vulnerability Management Assessment** **EXPERIENCE AND QUALIFICATIONS**: - Experience in Vulnerability Management & Assessment (Infrastructure and Application). - Strong experience in SAST/DAST onboarding and roll out. - Help challenge vulnerability findings from pentest activity conducted by independent third-party assessor. Strong technical...
-
Vulnerability Management Assessment
5 months ago
Kuala Lumpur, Malaysia Emantisit Full timeWe are hiring for Vulnerability Management Assessment with one of our clients in Malaysia. Please find the details below: **Job Type**: 12 months extendable contract Experience: 4+ years Work Location: Kl, Malaysia 1. At least 4 years’ experience in Vulnerability Management & Assessment (Infrastructure and Application). 2. Diploma or Bachelors in...
-
Vulnerability Management Assessment
5 months ago
Kuala Lumpur, Malaysia Avows Technologies Sdn Bhd Full time1. At least 4 years’ experience in Vulnerability Management & Assessment (Infrastructure and Application). 2. Diploma or Bachelors in IT/Computer Science, Engineering, or related fields. 4. Strong experience in SAST/DAST onboarding and roll out. scanning/pentest tools. 7. Help challenge vulnerability findings from pentest activity conducted by independent...
-
Business Analyst
6 months ago
Kuala Lumpur, Malaysia Skill Quotient Full timeRole: Business Analyst Working Mode: On Site **Job Type**: CDM (Contract Direct Hire) - after completing 12 months will convert as Perm employee of Skill Quotient Job Location: Kuala Lumpur Experience: More than 5 years of experience as Business Analyst and Cybersecurity in Software Development Industry Only Local Malaysian preferred **JOB...
-
Business Analyst
5 months ago
Kuala Lumpur, Malaysia Skill Quotient Full timePET# 269 Role: Business Analyst Working Mode: On Site **Job Type**: CDM (Contract Direct Hire) - after completing 12 months will convert as Perm employee of Skill Quotient Job Location: Kuala Lumpur Experience: More than 3 years of experience as Business Analyst in Software Development Industry Only Local Malaysian preferred **JOB DESCRIPTION** -...
-
Business Analyst
5 months ago
Kuala Lumpur, Malaysia Skill Quotient Resources Sdn. Bhd Full time**Responsibilities**: - Perform business analysis across diverse projects and operational tasks. - Capture and evaluate user requirements from internal and external clients and building buy-in for your proposed solution. - Document vulnerabilities and penetration test findings, technical specifications, and workflows to support vulnerability management...
-
Junior Security Analyst
5 months ago
Kuala Lumpur, Malaysia HECTADATA Sdn Bhd Full time**Junior Security Analyst** We are seeking a motivated and eager Junior Security Analyst to join our growing security team and play a vital role in safeguarding our critical systems and data. This role provides an exciting opportunity to learn from industry-leading cybersecurity experts and contribute to a fast-paced and dynamic...
-
Cyber Security Analyst
6 months ago
Kuala Lumpur, Malaysia SSquad Global Full time**RESPONSIBILITIES** A cybersecurity analyst protects company hardware, software, and networks from cybercriminals. The analyst's primary role is to understand company IT infrastructure in detail, to monitor it at all times, and to evaluate threats that could potentially breach the network. **RESPONSIBILITIES** **To support regional operation**: -...
-
Cyber Security Analyst
5 months ago
Kuala Lumpur, Malaysia SSquad Global Full time**RESPONSIBILITIES** A cybersecurity analyst protects company hardware, software, and networks from cybercriminals. The analyst's primary role is to understand company IT infrastructure in detail, to monitor it at all times, and to evaluate threats that could potentially breach the network. **RESPONSIBILITIES** **To support regional operation**: -...
-
IT Security Analyst
5 months ago
Kuala Lumpur, Malaysia Tech-Matrix Sdn Bhd Full time**The Role** We are looking for IT Security Analyst to join our growing team. You will play a crucial role in safeguarding our company's IT infrastructure and data from cyber threats. You will be responsible for a variety of tasks, including security assessments, vulnerability management, incident response, and user security awareness...
-
Security Analyst
5 months ago
Kuala Lumpur, Malaysia amIT Global Solution Full time**Job Summary** Prometric is looking to fill the role of Security Analyst who will be responsible for implementing security measures, monitoring security processes and procedures, installing and configuring security infrastructure and periodically assisting with risk assessments and internal audits The security analyst will stay abreast of IT Security...
-
Cybersecurity Threat Analyst
6 months ago
Kuala Lumpur, Malaysia Technip Energies Full time**About Technip Energies At Technip Energies, we believe in a better tomorrow and we believe we can make tomorrow better. With approximately 15,000 talented women and men, we are a global and leading engineering and technology company, with a clear vision to accelerate the energy transition. Designing and delivering added value energy solutions is what we...
-
Cyber Security Response Analyst
5 months ago
Kuala Lumpur, Malaysia Aveva Full timeAVEVA is a global leader in industrial software. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life - such as energy, infrastructure, chemicals and minerals - safely, efficiently and more sustainably. We’re the first software business in the world to have our sustainability targets validated by the SBTi, and...
-
Security Analyst
5 months ago
Kuala Lumpur, Malaysia Bright Nexus (M) Sdn Bhd Full time**Key Roles & Responsibilities**: Monitor and protect customer networks, systems and data from cyber-attacks. Security Analysts are expected to provide proactive monitoring, analysis and escalation when detecting suspicious security events. - Working in shift schedule (including public holiday), in a 24x7 Security Operation Center (SOC) environment. -...