Vulnerability Management Analyst
1 week ago
AVEVA is a global leader in industrial software. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life - such as energy, infrastructure, chemicals and minerals - safely, efficiently and more sustainably.
We’re the first software business in the world to have our sustainability targets validated by the SBTi, and we’ve been recognized for the transparency and ambition of our commitment to diversity, equity, and inclusion. We’ve also recently been named as one of the world’s most innovative companies.
If you’re a curious and collaborative person who wants to make a big impact through technology, then we want to hear from you Find out more at
AVEVA Careers
For more information about our privacy policy and how to manage cookies, visit our
Privacy Policy
Job name: Vulnerability Management Analyst
Organization/department: CISO (Security)
Reports to: Head of Vulnerability Management
Job Overview:
The AVEVA Security team are seeking a skilled individual to join a high performing global vulnerability management team.
The Vulnerability Management Analyst is responsible for proactively identifying and managing the remediation of vulnerabilities affecting AVEVA’s infrastructure and services. This role requires a broad technical understanding and to be responsible for vulnerability detection, assessment and driving vulnerability remediation across the organisation.
Roles and Responsibilities:
- Conduct vulnerability assessments to identify known vulnerabilities and configuration weaknesses and assess the effectiveness of existing controls and recommends remedial action.- Maintain current knowledge and understanding of the threat landscape and emerging security threats and vulnerabilities.- Analyze risks associated with vulnerabilities, provide detailed reporting, and recommend actionable remediation strategies- Support compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks.- Serve as an escalation point on issues, dependencies, and risks related to vulnerability scanning and security testing.- Collaborate with multiple stakeholders to prioritize vulnerabilities based on severity, impact, and exploitability.- Support the development of AVEVA’s Vulnerability management policy, process, and procedures.- Managing the end-to-end vulnerability lifecycle from discovery to closure ensuring the relevant resolver team put in place a plan and timely remediation working with both managed service providers and internal IT and Information Security staff.- Utilising information from external vulnerability reporting tools such as Bitsight, RiskRecon, Security Scorecard and vendor vulnerability briefings determine the priority of remediations needed across the AVEVA estate.- Manage security assessment processes, including performing, tracking remediation, validating controls, measuring residual risk, and writing reports.- Coordinate and oversee remediation efforts to ensure timely and effective resolution of security vulnerabilities.
Qualifications/ Experience:
Educational Qualifications and Experience- Minimum of 5 years information and cyber security experience, and experience in IT Vulnerability Management.- Experience using vulnerability scanning tools such as Qualys, Tenable, Rapid7 and vulnerability management platforms (RiskVision, Kenna Security).- Experience managing vulnerability management findings/services for cloud environments (Amazon Web Services, Microsoft Azure, Google Cloud Platform).- Strong understanding of vulnerability management practices and methodologies. Knowledge of common vulnerability frameworks (CVSS, OWASP Top 10).-
- Working knowledge of one or more of the following - cloud technologies, internet security, networking protocols or experience with software development.- Strong analytical skills and ability to identify advanced vulnerability threats.- Knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controls.- Knowledge of and experience in developing and documenting security processes and plans.- Knowledge and experience with implementing common information security management frameworks, such as International Organization for Standardization (ISO) 2700x series, AICPA SOC2 (Service Organization Control), ITIL, COBIT and National Institute of Standards and Technology (NIST) or Centre for Internet Security (CIS) frameworks would be advantageous.
Technical Competency- Having knowledge and experience with as many of the following areas and tools is desired:
- Security certifications such as CEH, GPEN, Security+.-
- Understanding of firewall & networking devices (Cisco, Palo Alto, Checkpoint).-
- Understanding of desktop and server infrastructure (Microsoft, Linux, MacOS).-
- Vulnerability Management tools (Qualys, Tenable/Nessus, Rapid 7 Nexpose).-
- Security rating services such as BitSight, S
-
Vulnerability Management Analyst
4 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia Avensys Consulting Full time 60,000 - 120,000 per yearAvensys is a reputed global IT professional services company, and our service spectrum includes enterprise solution consulting, business intelligence, business process automation and managed services. And we service a client base across banking and financial services, insurance, information technology, healthcare, retail, and supply chain.We are currently...
-
Manager IT
2 weeks ago
Kuala Lumpur, Malaysia Skill Quotient Technologies Inc Full time**Title**: Manager IT - Vulnerability and Threat Management **Location**: Kuala Lumpur **Duration**: 12 months renewable contract **Qualifications & Requirements**: - Bachelor’s Degree in Cybersecurity, Computer Science, IT, or a related field. - A master’s degree in Cybersecurity, or Information Security is highly valued. - Minimum of 7-9 years of...
-
Appsec Vulnerability Triage Analyst
6 days ago
Kuala Lumpur, Malaysia Rapsys Technologies Full time**Job Summary**: **Key Responsibilities**: - To perform vulnerability prioritization based on exploitability, asset criticality and business context. - To perform vulnerability triage operations with effectiveness and efficiency. - To Conduct false positive analysis, de-duplication, and tool output normalization. - Identify and correlate recurring...
-
Vulnerability Management Analyst
2 weeks ago
Kuala Lumpur, Malaysia Avows Technologies Sdn Bhd Full time**Experience**: 1 to 3 years Malaysian Only **Position Objective**: **Roles and Responsibilities**: - Use intelligence feeds such as vulnerability reports and risk assessments to rate and prioritise vulnerabilities within the AIA environment. - Document vulnerabilities which are discovered within the AIA estate and provide guidance on remediation and...
-
Vulnerability Management
2 weeks ago
Kuala Lumpur, Malaysia Skill quotient Full time**Roles and Responsibilities**: - Use intelligence feeds such as vulnerability reports and risk assessments to rate and prioritise vulnerabilities within the AIA environment. - Document vulnerabilities which are discovered within the AIA estate and provide guidance on remediation and mitigations. - Review vulnerabilities with AIA colleagues and technology...
-
Vulnerability Management
2 weeks ago
Kuala Lumpur, Malaysia Terrabit Consulting Full timeGood day!!! I came across your profile on Job portal and was immediately impressed with your experience. I think that your expertise would help us in project we’re working on. TERRABIT CONSULTING GROUP is one of the leaders in the IT Consulting industry across Asia Pacific. Founded in 2009, Terrabit Consulting began its operations in Singapore as a...
-
Desktop Vulnerability Management Analyst
1 week ago
Kuala Lumpur, Malaysia SOFT REFLEXES SDN BHD Full timeReview, test, document, implement, and track software and operation system updates and security patches in the Asia Pacific region - Provide technical support to diagnose, analyze, research, and resolve computer problems in a Windows enterprise environment - Must be able to analyze data from multiple collection points to identify computers and systems that...
-
Vulnerability Management Assessment
1 week ago
Kuala Lumpur, Malaysia Power IT Services Full time**Job title: Vulnerability Management Assessment** **EXPERIENCE AND QUALIFICATIONS**: - Experience in Vulnerability Management & Assessment (Infrastructure and Application). - Strong experience in SAST/DAST onboarding and roll out. - Help challenge vulnerability findings from pentest activity conducted by independent third-party assessor. Strong technical...
-
Vulnerability Management, GIS
4 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia UOB Full time 120,000 - 180,000 per yearAbout UOBUnited Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and...
-
Vulnerability Assessment Engineer
4 days ago
Kuala Lumpur, Kuala Lumpur, Malaysia UOB Full time 120,000 - 180,000 per yearAbout UOBUnited Overseas Bank Limited (UOB) is a leading bank in Asia with a global network of more than 500 branches and offices in 19 countries and territories in Asia Pacific, Europe and North America. In Asia, we operate through our head office in Singapore and banking subsidiaries in China, Indonesia, Malaysia and Thailand, as well as branches and...