Vulnerability Management Analyst
WTW
Vulnerability Management Analyst
- 202603459
- Taguig, Metro Manila, Philippines
- Full time
Description
As a Vulnerability Management Analyst at WTW, you will work as part of the Vulnerability Management team, supporting WTW's Vulnerability Management lifecycle to ensure that vulnerability related risks are managed effectively and in a timely manner. The Vulnerability Management Analyst will collaborate closely with both the Cyber Offensive and Defensive teams to ensure that WTW’s attack surface risk is addressed. Your work will involve close coordination with other areas of Offensive and Defensive security, acting as a Vulnerability Management SME supporting these teams as well as engaging with the wider business.
As well as supporting regular BAU activities, such as ensuring the smooth operation of scanning, reporting, prioritization, remediation tracking as well as communicating with the business, the VM Analyst will have opportunities to work on various projects to constantly improve the VM function, as well as building expertise in different areas to support the team. Regular training, staying on top of industry trends and understanding their implications will be critical in keeping WTW resilient against evolving threats.
The Role
Responsible for supporting the Vulnerability Management and ICS teams to help reduce vulnerability related attack surface risk within WTW.
- Expertise in Scanning/CMDB Tools: Develop/enhance expertise in WTW scanning tools (and supporting tools) and support scanning, reporting and data verification activities, to ensure high quality and accurate data for the business and stakeholders
- Tracking Vulnerability Remediation: Attending or leading remediation calls with different areas of the business in order to track and drive vulnerability remediation efforts, escalating where necessary
- Supporting internal projects: Support existing and upcoming internal projects, to enhance WTW’s ability to identify, prioritize and respond to vulnerabilities of varying risk within different areas of the business
- Collaboration with Business/Teams/Stakeholders: Work alongside senior members of both offensive (Red Team, Security Testing Team) and defensive teams. Help ensure that findings from vulnerability scans are communicated clearly to the business and any identified gaps are tracked and addressed
- Explore Emerging Technologies: Stay informed on the latest vulnerabilities and attack techniques in order to bolster WTW’s vulnerability remediation efforts
- Support BAU Processes: Work as an integral part of the team in order to support the WTW vulnerability management lifecycle, built into the company’s corporate controls.
- Report Findings and Metrics: Assist in ensuring vulnerability remediation reports are accurate and fit for purpose, as well as working to ensure that monthly metrics that are provided to stakeholders are accurate, effective and timely
- Continuous Learning: Take advantage of training opportunities available within WTW, as well as self-learning to remain abreast of emerging vulnerability related threats as well as vulnerability related technical details
- Assist with Audits – Assist with both internal and external audits where required
Qualifications
The Requirements:
Technical Requirements:
- Familiarity with Vulnerability Scanning Tools – Overall familiarity with popular vulnerability scanning tools and how they work to identify vulnerabilities (Tenable, Wiz, Qualys, Rapid 7, MDE etc)
- Understanding of Web, Network and Cloud Technologies – A good basic understanding of web and network architecture, as well as traffic at different OSI layers and cloud architecture
- Vulnerability Patching/Remediation – A good understanding of how vulnerability patches and other vulnerability remediation methods work, as well as reasons why patches may not be available, such as End of Life or unsupported products due to update mechanisms etc
- Understanding of CI/CD pipeline security and the shift-left approach to vulnerability management, including integrating security controls early in the software development lifecycle (SDLC).
- Attention to Detail – Ability to analyse large volumes of sometimes complex vulnerability data using PowerBi and Excel spreadsheets, while ensuring that data is complete and accurate
- Exposure to Offensive and Defensive Security: Some basic hands-on experience or academic exposure to both offensive and defensive security practices, with a focus on building knowledge in cyber operations.
- Collaboration Skills: Ability to work alongside more senior Cyber Security Operations team members, helping to support improvements in processes and technology controls.
- Awareness of Regulatory Requirements: A basic understanding of regulatory requirements such as DORA, NIST, SOC2, ISO 27001 etc are related to cybersecurity, with an interest in learning how these impact technical controls and processes
- Basic Scripting Knowledge - Some basic knowledge of scripting would be desirable, such as Powershell, KQL, Python etc
- A basic understanding of how evolving technologies such as AI can be leveraged to identify and exploit vulnerabilities
Additionally, the following are desirable but not essential:
- Educational Background: A degree or coursework in Information Technology, Cybersecurity or a related field.
- Certifications: Relevant cybersecurity certifications (such as CompTIA Security+, CEH, MS Azure, CISSP etc) are desirable.
- Interest in Leadership: A willingness to develop leadership and team collaboration skills over time.
Non-Technical Skills:
- Stakeholder Engagement: Ability to communicate effectively with both technical and non-technical team members, with a focus on learning how to build strong working relationships.
- Communication Skills: Strong verbal and written communication skills, with the ability to articulate technical issues clearly to diverse audiences.
- Team Collaboration: A proven ability to work collaboratively in a team setting, with an eagerness to contribute to a supportive and inclusive work environment.
- Problem-Solving Abilities: An interest in developing problem-solving skills, with a commitment to helping resolve issues and continuously improving the security framework.
Risk Awareness & Business Acumen: Understands the balance between security and business needs and can align remediation strategies with organizational priorities.
WTW is an Equal Opportunity Employer
- ...What Pricing Strategy contributes to Cardinal Health Revenue Management is responsible for developing, communicating, and leading the execution of market strategy and profitability optimization through pricing and value-capture activities at both the strategic and...
- ...About the Role The Management Accounting Analyst is responsible for providing support to the business unit leaders and management in making critical business decisions by preparing, analyzing and presenting key financial data and metrics. This position is also responsible...
- ...Product Cost) workstream on critical deployment projects Utilize your process improvement, system implementation, and project management skills to innovate, deliver solutions, and contribute to global transformation projects that impact the results of the company...
775000 $ per day
Grievance & Appeals • Creates complete appeal records for external appeal reviews, using standardized Independent Review Entity (IRE) forms and including all required documentation. • Creates a detailed case summary in narrative format for each appeal. • ...775000 $ per day
...Strategy & Consulting Analyst Join our team in Accenture Strategy & Consulting for an exciting career opportunity to enable our... ...prior work experience to learn and understand the fundamentals of management consulting. You will get a chance to work with a dynamic team...775000 $ per day
...across industries. Practice: CFO & Enterprise Value I Areas of Work: Enterprise Performance Management (EPM), Enterprise Planning & Analytics | Level: Analyst | Location: Manila | Years of Exp: Analyst (2-4 years) Explore an Exciting Career at Accenture...775000 $ per day
...Role Overview: We are seeking a detail-oriented Analyst to support provider roster management operations across both current-state and future-state platforms (Symplr). This role involves data intake, processing, validation, and automation to ensure efficient provider...775000 $ per day
...operations. Act as a subject matter expert (SME) for corporate actions processes, market practices, and asset servicing workflows. Manage and support requirements of high-demand Prime Brokerage and institutional clients . Liaise effectively with Front Office,...775000 $ per day
...RIGHT TO LIVE AND WORK IN THIS COUNTRY ARE ELIGIBLE TO APPLY FOR THIS ROLE--- POSITION TITLE: Risk & Compliance Senior Analyst (License Management) WORK SETUP: Hybrid RESPONSIBILITIES: Compliance License Management • Oversight of Third- Party Administrator licenses...- ...working world for all. Functional Consultant / Business Analyst HRSD/IRM/ITOM/SPM The ServiceNow Business Analyst will lead... ...candidate should be a self-starter who can work without supervision, manage and lead cross-functional discussions, and deliver impactful...
- ...Join us and build an exceptional experience for yourself, and a better working world for all. EY - Consulting – Business Analyst Manager As part of the Business Analyst team, you will lead a group of business analysts to deliver high impact projects for our...
- ...The Data Analyst is focused on the structure, models, and standards of data for large projects and programs. The goal of the data architect... ...metadata, test data, and data quality standards. ~ Manage senior business stakeholders to secure strong engagement for the...
- ...Job Title: BI Analyst Location: BGC, Taguig (Full Time, Onsite) Job Summary We are seeking a highly analytical and detail-oriented... ..., and operational inefficiencies. Dashboard & Reporting Management Develop and maintain automated dashboards and reports using...
- ...Duties and Responsibilities: Publish yearly budgets and monthly forecasts. Provide monthly management reports on scorecard achievement, budget utilizations and other financial impacting metrics that will help management make an informed decision. Supervise invoice...
- ...will further shape the industry. The Fulfillment Commercial Analyst is responsible for ensuring accurate and timely billing of fulfillment... ...closely with Operations, Finance, Sales, and Key Account Management teams to ensure revenue integrity, customer satisfaction, and...
- ...Business Analyst Job Highlights ~ laptop to be provided Role Summary 1 Responsibilities Analyze the current system... ...problem-solving skills. Excellent communication and client management abilities. Ability to analyze system behavior and document...
- Workforce Analyst Position Description As a Workforce Management Agent, you will support the effective operation of the Transfer Agency Client Service Desk by ensuring appropriate staffing coverage and resource alignment. This role focuses on forecasting workload...
- ...Coordinate with internal teams and external banking partners to resolve payment concerns and transaction issues. Support the management of relationships with payment processors, payout providers, card networks, and alternative payment method providers. Assist in...
- ...reports. Responsible for data integrity, accuracy of all reporting requirements. Works with Workforce leaders, Senior Site managers and Sales leaders to create new or modify existing reporting. Analyses data to ensure integrity and structures data to help support...
- ...Data Analyst ~202603104 ~Taguig, Metro Manila, Philippines ~Full time View favourites Description WTW Investments WTW Investments is a bespoke asset manager that provides investment services to some of the largest pensions, government, and insurance...
- ...Job Title: Risk Data Analyst Location: BGC, Taguig (Full Time, Onsite) About the Role We are looking for a Risk Data Analyst... ...write SQL queries and retrieve data to support risk management, fraud prevention, and collections teams. This role does not...
- ...on strategic planning and decision-making within the COGS departments at Netskope. Responsibilities include: Drive budget management for the Netskope COGS function, including headcount planning, capital planning for data centers, and other discretionary spend budgeting...
- ...What Customer Pricing Analysts contributes to Cardinal Health This role needs someone who has a keen attention to detail, a passion... ...handled and resolved in an accurate and timely fashion • Managing relationships with internal & external customers • Analyzing...
- ...including logging and documenting all inquiries into the case management tools, consulting knowledge resources, and escalating the case... ...management. Referring to the People Services Supervisor and/or Senior Analyst-Team Lead cases that are prone or have already been raised to...
- ...The Information Security Analyst will be a key player in protecting our organization'... ...monitoring security access, conducting vulnerability assessments, and responding to incidents... ...requirements. Knowledge of vulnerability management tools (e.g., Nessus, Qualys) is a plus....
- ...Role: As a Business Analyst on our modernization engagement, you will translate legacy JSF/Java-Bean applications into a modern React single-page application with Java APIs. Youll perform bottom-up code analysis, extract and document business logic and workflows,...
- ...The Senior Tax Analyst is responsible for overseeing the preparation, review, and filing of tax returns for assigned operating companies... ...Internal Revenue (BIR) and Local Government Units (LGUs), to manage tax matters, audits, and compliance requirements. The position...
- ...entries, balance sheet reconciliations, and financial statements Ensure the timely reporting of all monthly financial information Manage own workflow, asking for assistance when necessary, according to their experience and capabilities Assist with the preparation...
- ...logistics network. About the job: The Performance Analytics Senior Analyst is responsible to conduct day-to-day analysis that supports the... ...of the Senior Analyst are (1) to closely communicate with the managers of the ground units their cost and operational targets and...
- ...present relevant insights that drive business decisions and anticipate opportunities to achieve a competitive advantage. This function manages analytic data platforms, the access, design and implementation of reporting/business intelligence solutions, and the application of...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Management Analyst. Be the first to apply!
