Cyber Security Vulnerability Engineer - Guadalajara, México - AstraZeneca

AstraZeneca
AstraZeneca
Empresa verificada
Guadalajara, México

hace 1 semana

Rodrigo Fernández

Publicado por:

Rodrigo Fernández

Reclutador de talento para beBee


Descripción

About the AstraZeneca
At AstraZeneca, we put patients first and strive to meet their unmet needs worldwide. Working here means being entrepreneurial, thinking big and working together to make the impossible a reality.

If you are swift to action, confident to lead, willing to collaborate, and curious about what science can do, then you're our kind of person.


Welcome to Guadalajara one of over 400 sites here at AstraZeneca, providing a collaborative environment where everyone feels comfortable and able to be themselves is at the core of AstraZeneca's priorities, it's important to us that you bring your full self to work every day.

To help you maintain your best self, here's a sneak peek into some of the things this site provides for you.


About the team


The Enterprise Technology Services (ETS) team is accountable for all Infrastructure, Security, IT Operations and all End User Services and technologies.

This group will ensure that our IT Services are seamless and secure, and that technology is delivered in an efficient, effective, and agile way, with a strong focus on experience.

It's a dynamic and challenging environment to work in - but that's why we like it.

There are countless opportunities to learn and grow, whether that's exploring new technologies in hackathons, or transforming the roles and work of colleagues, forever.

This is your chance to be part of a team that has the backing to innovate, disrupt an industry and change lives.


About The role


The Cyber Security Vulnerability Senior Engineer will be part of security specialists and analysts, maintaining corporate wide information security to ensure that AstraZeneca's information assets are adequately protected in relation to confidentiality, integrity and availability.

The role is accountable for ensuring that services are delivered in accordance with Service Level Agreements, business requirements and customer experience expectations and meeting required quality and compliance to standards.

The role is also required to work closely with work collaboratively with other IT functions, AZ business areas and suppliers.


Cyber Security Vulnerability Senior Engineer may also be an individual contributor, working in a security speciality supporting the wider security function.


  • Understand that security is a journey and not a destination. Cyber Security is not something that can be "fixed", and we instead need to focus on innovation to maintain sustainable risk position against the evolving threat landscape.
  • Understand that we can't just buy our way out of a Cyber Security problem. Technology may win the battle, but it won't win the war.
  • Understand that Cyber Security is not just dealing with individual hackers. We are potentially working against statesponsored attacks and multibilliondollar organized crime syndicates.
  • Understand attackers, their motivations, and their ways of working to be able to get ahead and keep ahead of them.

The Cyber Security Vulnerability Senior Engineer will be accountable for:

  • Improving and automating existing vulnerability management lifecycle. Including but not limited to, data ingestion & normalisation, compliance metrics and detections on assets.
  • Participate in impact assessments to help define prioritisation and proper monitoring coverage.
  • Develop automation, orchestration, and scripting to reduce manual processes, improving overall efficiency while also enabling new capabilities to meet our rapidly changing needs
  • Strong knowledge of vulnerability management
  • Triage, Prioritise, Remediate, and security threat modelling.
  • Develop relationships with IT teams to resolve aging critical vulnerabilities on assets
  • Analyse requirements to develop and manage program metrics and performance through reporting and active engagement with stakeholders for continuous service improvement.
  • Experience working on vulnerability assessment tools and configuring sites, asset groups, Tags
  • Experience driving vulnerability remediation and governing a team of resources
  • Review new vulnerabilities published from multiple sources and identify those that may pose risk
  • Clear understanding on vulnerabilities and what it requires to remediate
  • Should have good knowledge of analysing vulnerabilities, prioritization based on risk. Driving remediation or closure of the vulnerabilities with remediation teams.
  • Able to provide remediation solutions for the vulnerabilities based on the unique vulnerability categorization. Support teams to understand what is required to remediate vulnerabilities.
  • Provide technical expertise in providing compensating controls for exception vulnerabilities

Requirements:


Essential

  • Extensive experience working in Security, in a complex, multinational, corporate environment
  • A deep understanding of various security technologies and controls
  • Demonstrate a detailed understanding of Cyber security
  • Experience of vulnerability management methodol

Más ofertas de trabajo de AstraZeneca