Vulnerability Remediation Analyst (ETS Analyst III Technical Compliance Risk) in Vienna, VA at honor foundations

Date Posted: 11/5/2024

Job Snapshot

Job Description

The Vulnerability Remediation team is part of the Risk, Vulnerability and Security Services at Navy Federal Credit Union.

As a Vulnerability Remediation Analyst, you will be responsible for providing coordination and support of remediation activities for identified vulnerabilities within the Navy Federal Credit Union environment. Your focus will be on compiling, researching, and analyzing vulnerability data for the various stakeholders to develop and determine the best path forward. You will be part of a remarkable and hard-working team of analysts who apply their risk and information security expertise to help remediate vulnerabilities in an efficient and timely manner.

About Us

Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks.

Our approach to careers is simple yet powerful: Make our mission your passion.

  • Best Companies for Latinos to Work for 2024
  • Computerworld® Best Places to Work in IT
  • Forbes® 2024 America’s Best Large Employers
  • Forbes® 2023 The Best Employers for New Grads
  • Fortune Best Workplaces for Millennials™ 2023   
  • Fortune Best Workplaces for Women ™ 2023       
  • Fortune 100 Best Companies to Work For® 2024
  • Military Times 2023 Best for Vets Employers
  • Newsweek Most Loved Workplaces 
  • Ripplematch Campus Forward Award - Excellence in Early Career Hiring
  • Yello and WayUp Top 100 Internship Programs

From Fortune. ©2024 Fortune Media IP Limited. All rights reserved. Used under license. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of, Navy Federal Credit Union.

Equal Employment Opportunity: Navy Federal values and celebrates diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected Veteran.

Hybrid Workplace: Navy Federal Credit Union is a hybrid workplace, and details will be discussed during your interview process.

Disclaimers: Navy Federal reserves the right to fill this role at a higher/lower grade level based on business need. An assessment may be required to compete for this position. Job postings are subject to close early or extend out longer than the anticipated closing date at the hiring team’s discretion based on qualified applicant volume. Navy Federal Credit Union assesses market data to establish salary ranges that enable us to remain competitive. You are paid within the salary range, based on your experience, location and market position.

Bank Secrecy Act: Remains cognizant of and adheres to Navy Federal policies and procedures, and regulations pertaining to the Bank Secrecy Act.

Qualifications
  • Bachelor’s degree in information technology, information security, or the equivalent combination of education, training, and experience
  • Hands-on experience reviewing and analyzing vulnerabilities, assessing the level of risk and ability to provide reasonable recommendations for remediation
  • Strong understanding of Operating Systems and network protocols
  • Hands- on experience with technical concepts, security controls, and best practices related to areas such as networking, system administration, application development, and information security
  • Familiarity with security risk management frameworks and hardening guidelines (e.g., NIST 800-53, CIS Benchmarks)
  • Excellent communication and presentation skills when presenting proof of concepts, findings, conclusions, and other information to a variety of audiences 
  • Outstanding organizational skills with the ability to prioritize and execute 
  • Ability to manage stakeholder relationships

Desired Qualifications

  • Security certifications (e.g, Security+, CEH) or advanced degree
  • Experience in ServiceNow vulnerability response and reporting
  • Hands-on experience with vulnerability management scanning technologies and assessment methodology
  • Understanding of the various vulnerability categories at the OS/Web level
  • System/Process Automation (Orchestration) experience
  • Experience implementing systems/applications using Agile/Scrum

Hours: Monday - Friday, 8:00AM - 4:30PM

Location: 820 Follin Lane, Vienna, VA 22180 | 5550 Heritage Oaks Dr. Pensacola, FL 32526

Job postings are subject to close early or extend out longer than the anticipated closing date at the hiring team’s discretion based on qualified applicant volume.

Responsibilities
  • Collaborate with the Information Security team on the identification and validation of vulnerabilities
  • Coordinate and communicate with stakeholders to plan and ensure corrective actions are implemented to address identified vulnerabilities 
  • Perform comprehensive analysis of vulnerabilities and reports to help develop and implement appropriate remediation strategies 
  • Evaluate vulnerabilities based on prioritization criteria
  • Investigate and conduct root cause analysis on persistent or reoccurring vulnerabilities
  • Serve as a primary point of contact and provide support to the Business Units to address concerns, issues, and escalations related to vulnerability findings and/or remediation plans
  • Maintain current knowledge of best practices and the threat landscape
  • Communicate threat information and critical (e.g., 0-day) vulnerabilities to stakeholders
  • Assist in the development of documentation and presentations on an as-needed basis
  • Assist in the development of key performance indicators, reporting and metrics