Search jobs > Salt Lake City, UT > Vulnerability analyst

Analyst IT Vulnerability Management

JetBlue Airways
Salt Lake City, UT, US, 84121
Full-time

Position Title : Analyst Vulnerability Management - Network

Position Summary

At JetBlue, cyber security is driven by the concepts of Risk Management and Threat-Informed Defense, the study of current threats, actors and techniques to prioritize risks and adapt defenses, controls and resources to those constantly-changing dynamics.

The Crewmember in this role is responsible for conducting vulnerability assessments in our traditional on-premises and data center environments, analyzing results, and collaborating with cross-functional teams to ensure timely remediation.

Reporting to the Manager of Vulnerability Management, the Analyst will contribute to the effectiveness of our vulnerability management program and assist in safeguarding our systems and data.

Essential Responsibilities

  • Assist the IT and Cyber teams with identification and remediation of vulnerabilities across our traditional on-premises, data center and corporate network environments.
  • Conduct regular vulnerability assessments using automated scanning tools to identify security weaknesses, out-of-date versions and vulnerable systems across our corporate, data-center and multi-cloud environments.
  • Analyze scan results and assess vulnerabilities with regard to severity, impact, and potential risk to the organization and collaborate with system owners and IT teams to prioritize and coordinate remediation via patching and / or mitigating controls.
  • Collaborate with engineering and Quality Assurance (QA) teams to ensure proper Secure Software Development Life Cycle (SSDLC) practices and minimize the release of any vulnerable software through our deployment pipeline.
  • Assist in developing and updating vulnerability management policies and procedures, and in implementing those processes across our hybrid network environment.
  • Generate accurate and concise vulnerability assessment reports, including metrics on risk, vulnerability exposure and remediation progress.
  • Coordinate directly with the threat intelligence and pen-test teams regarding emerging vulnerabilities, active exploits, changes in our attack surface and other factors that influence prioritization and risk.
  • Assist in planning and reviewing penetration and red-team test results to identify and address vulnerabilities that may not be identified through automated scanning.
  • Participate in cross-functional meetings to maintain strong communication with IT, networking, systems owners and Managed Service Providers (MSPs) and collaborate with other contributors to ensure timely remediation or mitigation of security risks.
  • Support our Cyber GRC team to ensure successful compliance with Payment Card (PCI), Sarbanes-Oxley and other required oversight frameworks.
  • Other duties as assigned.

Minimum Experience and Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field; OR demonstrated capability to perform job responsibilities with a combination of a High School Diploma / GED and at least four (4) years of previous related work experience
  • At least one (1) year of experience in vulnerability management, information security, or related roles
  • Proficiency with vulnerability scanning tools such as Nessus, Qualys, Rapid7, or similar
  • Basic understanding of risk assessment methodologies and ability to evaluate vulnerabilities' potential impact to the business
  • Familiarity with patch management tools and processes for deploying security updates
  • Technical understanding of network and system architecture, operating systems, and common vulnerabilities
  • Excellent written and verbal communication skills
  • Ability to work collaboratively across teams, including IT, development, and compliance
  • Detail-oriented approach to analyzing scan results and identifying false positives
  • Available for occasional overnight travel (10%)
  • Must pass a ten (10) year background check and pre-employment drug test
  • Must be legally eligible to work in the country in which the position is located
  • Authorization to work in the US is required. This position is not eligible for visa sponsorship

Preferred Experience and Qualifications

  • At least two (2) years of experience in vulnerability management, information security, or related roles
  • Past experience specifically in Programs beyond / outside of Operating System (OS) and infrastructure level vulnerabilities, e.

g. application, container and cloud (GCP, Azure) vulnerability management

  • Familiarity with security frameworks and standards such as National Institute of Standards and Technology (NIST) Cybersecurity Framework, ISO 27001, or CIS Controls is a plus
  • Entry-level certifications such as CompTIA Security+, Certified Information Systems Security Professional (CISSP) Associate, or equivalent are advantageous

Crewmember Expectations :

  • Regular attendance and punctuality
  • Potential need to work flexible hours and be available to respond on short-notice
  • Able to maintain a professional appearance
  • When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of aircraft
  • Organizational fit for the JetBlue culture, that is, exhibit the JetBlue values of Safety, Caring, Integrity, Fun and Passion
  • Promote JetBlue’s #1 value of safety as a Safety Ambassador, supporting JetBlue’s Safety Management System (SMS) components, Safety Policy and behavioral standards
  • Identify safety and / or security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue’s confidential reporting systems (Aviation Safety Action Program (ASAP) or Safety Action Report (SAR))

Equipment :

Computer and other office equipment

Work Environment :

Traditional office environment

Physical Effort :

Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary)

LI-LL1 #LI-Hybrid

30+ days ago
Related jobs
JetBlue Airways
Salt Lake City, Utah

Analyze scan results and assess vulnerabilities with regard to severity, impact, and potential risk to the organization and collaborate with system owners and IT teams to prioritize and coordinate remediation via patching and/or mitigating controls. Position Title: Analyst Vulnerability Management -...

Promoted
Myriad Genetics
Salt Lake City, Utah

Windows System Administrator (Sysadmin 3). Myriad Genetics is seeking an experienced administrator to join our Identity & Integration Services team at our headquarters in Salt Lake City, UT or as a remote team member. BS degree in Computer Science, Information Systems, or equivalent experience. Stro...

Promoted
BankTalent HQ
Midvale, Utah

Supplier Resilience Business Analyst. Enterprise Business Resilience works to ensure the reliability and continuity of our operations by overseeing joint testing, conducting thorough supplier assessments, establishing robust resilience provisions in supplier contracts, and implementing strategies to...

Promoted
Beacon Hill
Salt Lake City, Utah
Remote

Job Description: Level 3 SOC Analyst (3rd Shift) - 100% Remote. We are seeking a highly experienced Level 3 SOC Analyst to join our IT Security Operations team. Work closely with a team of two other SOC analysts. The ideal candidate will have a strong background in Security Operations Centers (SOC) ...

Promoted
SoFi
Salt Lake City, Utah

SoFi's Business Controls team resides within the 1st Line of Defense (1LOD). ...

Promoted
TalentPlug LLC
Salt Lake City, Utah

As a Business Systems Analyst III, you will work with other Systems Analysts under the direction of the People Systems group to accomplish Client's vision of democratizing data by building a world class People technology platform that allows employees to make an impact. Drive consensus with business...

Promoted
Mountain America Credit Union
Sandy, Utah

Use IT Security Governance principles to accurately represent and collaborate with MACU Risk and Internal Audit teams on a variety of projects requiring IT Security Governance participation and expertise. The IT Security Governance Analyst Principal will have a deep understanding of business process...

Promoted
Federal Reserve Bank of Cleveland
Salt Lake City, Utah

IT Security Analyst with 2+ years of information security related experience in areas such as: security operations, testing, and/or system or security administration, Sr IT Security analyst with 5+ years of experience in areas such as: security operations, testing, and/or system or security administ...

Promoted
Milliman Inc
Salt Lake City, Utah

We are a tech healthcare data company transforming how the industry understands and consumes healthcare data. Healthcare Data Analyst to join our team. Perform ad hoc analyses of healthcare data using Azure Databricks, SQL Server, and other tools. They must also have some experience/ familiarity wit...

Promoted
Deloitte
Salt Lake City, Utah

Responsible for the day-to-day operations of and support for applications and systems to include: Microsoft Exchange servers, Microsoft Outlook, DNS, Active Directory and other applications as deployed by the Unified Communications team. Work with vendors to support Deloitte's email and Active Direc...