Info Security Exposure Management Specialist I B

Posted 5 Days Ago
Be an Early Applicant
2 Locations
In-Office
Mid level
Healthtech • HR Tech • Professional Services
The Role
Manage and optimize enterprise vulnerability scanning and exposure management platforms across global regions. Identify coverage gaps, prioritize vulnerabilities by business risk and threat intelligence, perform root cause analysis, coordinate remediation, manage vendor and technology partnerships, support incident response, test emerging security technologies, provide technical guidance, and report strategic updates to senior leadership.
Summary Generated by Built In

Job Description:

About Us

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!


Global Business Services

Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations. Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence and innovation. In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.


Process Overview

The Global Information Security (GIS) is responsible for protecting Bank information systems, confidential and proprietary data, and customer information. The team develops the Bank’s Information Security strategy and policy, manages the Information Security program and identifies and addresses vulnerabilities, Develops, deploys and manages a risk-based controls portfolio, Manages and operates a global security operations center that monitors, detects and responds to cybersecurity incidents.


Job Description

This position will be a member of the GIS Vulnerability Identification team. The Vulnerability scanning deployment & engineering specialist will be primarily responsible for end-to-end technology enablement in support of the global Vulnerability Identification program. To continuously improve vulnerability detection capabilities, the role’s remit will span across the Americas, EMEA and the Asia Pacific regions and will focus on the planning, design, testing, deployment of tactical and strategic solutions. This role requires partnership with solutions vendors and technology infrastructure partners to optimally tailor future solutions to vulnerability identification strategic objectives. The role will require cross-organization collaboration to solve key issues impactful to the enterprise. 


Responsibilities


  • Responsible for vulnerability scanning platforms, optimization and resiliency
  • Responsible for the mapping of vulnerability identification gaps with remedial technology solutions
  • Maintain relationships with Vulnerability Management Solutions Providers and Technology implementation partners
  • Responsible for Technology-based thematic issue tracking, resolution, and reporting
  • Key participants to Vulnerability Identification Incident Management & Response. 
  • Provide technical guidance and mentorship to team members
  • Responsible for the development and execution of the vulnerability identification technology strategy
  • Deliver proof-of-concept testing and validation of emerging vulnerability identification technologies to support strategic security initiatives.
  • Deliver periodic project updates to Senior Leadership

Requirements

 Education : Bachelor’s and/or master’s degree in computer science, Information Technology or related field

Certifications If Any : Qualys VMDR, CASM/EASM preferred, Relevant certifications such as CISSP, CISM, ISO 27001, NIST is a plus

Experience Range : 4-7 Years


 Foundational skills

  • Comfortable working in a fast-paced environment
  • Minimum 4 years of experience in information Security
  • Strong Proficiency in Vulnerability Management and Exposure Management programs (Qualys, Tanium).
  • Strong proficiency in Qualys Query Language (QQL) & Qualys Agent Deployment (QAD).
  • Hands-on experience with Tanium & prioritizing vulnerabilities based on business risk, exploitability, and threat intelligence.
  • Proven experience performing root cause analysis on vulnerability findings, scan coverage gaps, agent deployment issues, false positives/negatives, and remediation failures.
  • Superior sense of urgency and ability to accurately prioritize deliverables
  • Excellent communication and presentation skills, capable of translating technical security findings into clear business risk and executive-level insights.
  • Excellent team player with critical thinking skills

 Desired skills

  • BS or MS in Information technology/security or related areas of study
  • Experience with establishing and maintaining integration between Vulnerability identification tools and Vulnerability Management Workflows (e.g. ServiceNow)
  • Familiarity with mainstream attacker techniques, tactics, and procedures (i.e. MITRE ATT&CK Framework)
  • Experience with deploying and managing Cloud-based Vulnerability scanning solutions
  • Familiarity with compliance regulations, frameworks, and certifications (e.g., NIST, FFIEC.)
  • Working knowledge of Network architecture and Engineering concepts
  • Experience with Vulnerability ratings methodologies
  • Background in Windows & UNIX platform Administration
  • Experience with a scripting language(s)or Power BI

Work Timings : 12:30 pm to 9:30 pm

Job Location : Hyderabad, Chennai  


Skills Required

  • Bachelor's or master's degree in computer science, information technology, information security, or a related field
  • At least 4 years of experience in information security
  • Strong proficiency in vulnerability management and exposure management programs using Qualys and Tanium
  • Strong proficiency with Qualys Query Language and Qualys Agent Deployment
  • Hands-on experience with Tanium and prioritizing vulnerabilities based on business risk, exploitability, and threat intelligence
  • Experience performing root cause analysis on vulnerability findings, scan coverage gaps, agent deployment issues, false positives or negatives, and remediation failures
  • Qualys VMDR certification
  • CASM or EASM certification
  • Certifications such as CISSP, CISM, ISO 27001, or NIST
  • Experience integrating vulnerability identification tools with vulnerability management workflows such as ServiceNow
  • Familiarity with MITRE ATT&CK attacker techniques, tactics, and procedures
  • Experience deploying and managing cloud-based vulnerability scanning solutions
  • Familiarity with compliance regulations and frameworks such as NIST and FFIEC
  • Working knowledge of network architecture and engineering concepts
  • Experience with vulnerability rating methodologies
  • Windows and UNIX platform administration experience
  • Experience with a scripting language or Power BI
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Blue Bell, PA
1,496 Employees
Year Founded: 1993

What We Do

GHR Healthcare is a comprehensive healthcare staffing platform that connects healthcare professionals with facilities, providing nursing, allied, and healthcare IT staffing solutions.

Similar Jobs

Optum Logo Optum

Senior Business Analyst

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Chennai, Tamil Nadu, IND
160000 Employees

Optum Logo Optum

Senior Software Engineering Lead

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Chennai, Tamil Nadu, IND
160000 Employees
Hybrid
Chennai, Tamil Nadu, IND
175633 Employees

Comcast Logo Comcast

Engineer 3, Software Development & Engineering

Digital Media • Information Technology • News + Entertainment
Hybrid
Chennai, Tamil Nadu, IND
115000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
Vitalize Thumbnail
Artificial Intelligence • Healthtech • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account