Senior Analyst Vulnerability Management
Pennsylvania - Malvern, United States
Why Endo?
We want the best and brightest people at Endo to help us achieve our mission to develop and deliver life-enhancing products through focused execution. Our nearly 3,000 global team members understand the important role we play in delivering healthcare and are dedicated to supporting each other as we work to bring the best treatments forward. Our shared values of Integrity & Quality, Innovation, Drive, Collaboration and Empathy guide our team and enable us to deliver upon our vision of helping everyone we serve live their best life.
At Endo, we are building a diverse, equitable and inclusive workplace, and we are looking for talented individuals to join our team.
Job Description Summary
The Senior Analyst, Vulnerability Management, will develop and implement Endo’s vulnerability management program. The successful candidate will oversee identifying, assessing, prioritizing, and mitigating vulnerabilities across the IT environments. This role requires a deep understanding of vulnerability management processes, tools, and best practices. The ideal candidate will have a strong technical background, excellent analytical skills and written skills along with the ability to communicate effectively with both technical and non-technical stakeholders.Job Description
- Conduct regular vulnerability assessments and scans to identify security weaknesses within the global IT environment.
- Analyze and report on enterprise vulnerability management data.
- Analyze and prioritize vulnerabilities based on risk and potential impact.
- Collaborate cross-functionally across multiple IT teams to develop and implement remediation plans.
- Monitor and track the status of vulnerabilities and remediation efforts.
- Provide detailed reports and recommendations to team leads and IT management.
- Develop metrics and KPIs for program visibility.
- Improve reporting maturity through automation.
- Stay current on the latest vulnerability trends, tools, and best practices.
- Participate in incident response activities as needed
Education & Experience:
- Bachelor’s degree in computer science, or related field, preferred.
- Security certifications (e.g. CISSP, CISM, CEH), preferred.
- 5+ years of relevant IT experience in vulnerability management or related role (e.g., operating systems, networking) with at least 3 years of IT security operational experience.
- Knowledge of vulnerability assessment tools (e.g. Nessus, Qualys, Rapid7).
- Strong background in security management and operations.
- Familiarity with CVSS
- Experience with security frameworks and standards (e.g., HIPAA, PCI-DSS, HITRUST, NIST, ISO, etc.)
Knowledge and proficiency in the following areas:
- Cyber Security
- Desktop/Network operating systems
- Network protocols
- Management systems
- Security scanners
- Network analysis tools
- Network applications
- Messaging systems
- Endpoint Security
Skills and Abilities
- Ability to diagnose, troubleshoot and recommend solutions.
- Ability to determine the root cause of security events; strong research capability.
- Audit and assessment capability.
- Understanding and knowledge of industry best practice methodologies.
Commitment to Diversity, Equity, and Inclusion:
At Endo, our diversity unites and empowers us as One Team, and we are committed to cultivating, and valuing, each person’s unique perspective. We actively promote a culture of inclusion that draws strength from our broad spectrums of diversity, including race, ethnicity, religion, gender identity or expression, national origin, color, sexual orientation, disability status, age, and all our other unique characteristics, qualifications, demonstrated skills, achievements, and contributions, backgrounds, experiences, cultures, styles, and talents.
EEO Statement:
At Endo, we firmly believe in the principles of equal employment opportunity and strive to create an atmosphere where all employees, regardless of their race, color, creed, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability (including pregnancy), age, or military or veteran status, feel valued, respected, and empowered. Our commitment to EEO extends to every aspect of employment, including recruitment, hiring, training, promotions, compensation, benefits, transfers, terminations, and all other employment practices. We are dedicated to ensuring that all employment decisions are based on qualifications, skills, and merit.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation CEH CISM CISSP Computer Science CVSS Endpoint security HIPAA HITRUST Incident response KPIs Nessus NIST Qualys Vulnerabilities Vulnerability management
Perks/benefits: Equity / stock options Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.