Job Information
Western Digital Technologies Senior Vulnerability Management Engineer in Irvine, California
ESSENTIAL DUTIES AND RESPONSIBILITIES:
- Lead Vulnerability Management:Take ownership of the vulnerability management lifecycle, including identification, assessment, prioritization, remediation, and reporting of security vulnerabilities. Oversee regular vulnerability scans, penetration tests, and security assessments to identify weaknesses in systems, networks, and applications.
- Attack Surface Reduction:Analyze and map the organizations attack surface, identifying potential entry points and areas of exposure. Develop and implement strategies to reduce the attack surface across all digital assets, ensuring proactive defense against emerging threats. Continuously monitor changes to the IT environment to ensure the attack surface remains minimized.
- Collaboration and Mentorship:Work closely with cross-functional teams, including IT, DevOps, and security operations, to integrate vulnerability management practices into development and operational processes. Provide mentorship and training to junior security team members.
- Stakeholder Communication:Effectively communicate vulnerability management activities, findings, and risk mitigation strategies to technical and non-technical stakeholders, including senior leadership.
- Critical Decision-Making:Make informed, critical decisions in high-pressure situations, ensuring the protection of the organizations infrastructure and data.
- Governance and Continuous Improvement:Stay current with the latest vulnerability management tools, technologies, and methodologies, and continuously improve the organizations vulnerability management program. Ensure that vulnerability and attack surface management processes comply with industry standards, regulations, and organizational policies.
- Automation and Tooling:Evaluate and implement tools and technologies to automate vulnerability scanning, risk assessment, and remediation tracking. Develop and maintain scripts, tools, and processes to streamline and enhance the effectiveness of the vulnerability management program.
Qualifications
Technical Skills:
- Experience operatingvulnerability analysis tools, ability to articulate the results and explain toolslimitations.
- Deep understanding ofsystems architectureand security technologies. Ability to explain risk and impact of detected vulnerabilities.
- Extensive experience in vulnerability assessment, prioritization, and management within large-scale, complex IT environments, including major clouds.
- Working with large eco systems with a number of security related tools such as Asset Management, Vulnerability Scanners, Endpoint Protection, SEIM, CWPP, etc.
- Proficiency in scripting languages (e.g., Python, Bash, PowerShell) and experience with automation tools.
- Relevant certifications such as CISSP, CISM, or CEH are preferred
Soft Skills:
- Exceptional communication skills, with the ability to translate technical issues into business risks for stakeholders.
- Ability to make critical decisions under pressure and in complex situations.
- High level of integrity, professionalism, and attention to detail.
- Prior experience in a global,large-scale manufacturingenvironment is a plus.