Senior Cloud Security and Vulnerability Analyst
New York
Full Time Senior-level / Expert USD 195K - 240K
Bloomberg
Bloomberg delivers business and markets news, data, analysis, and video to the world, featuring stories from Businessweek and Bloomberg News
Senior Cloud Security and Vulnerability Analyst
Location
New York
Business Area
Engineering and CTO
Ref #
10043773
We report to the Chief Information Security Office (CISO) that owns the technical aspects of this mission by ensuring that Bloomberg products, systems, networks and commercial applications are built and maintained to be secure.
We work on purpose. Come find yours.
What’s The Role? We are seeking an IT Security Analyst to help ensure that our Public Cloud IT infrastructure and security processes are resilient against the latest threats. You will be responsible for analyzing and assessing vulnerabilities across a wide range of technologies. You'll engage with various technology partners to validate and manage identified vulnerabilities through remediation. You will work directly with other cross-department security engineering and incident response teams to set strategic direction for our enterprise Threat and Vulnerability Management program.
This is a team that drives company-wide initiatives to improve the effectiveness of Bloomberg’s security posture. Analysts in this role must show exemplary judgment in making technical decisions to achieve business goals. You're expected to always demonstrate resilience and navigate difficult situations with composure and tact.
We'll Trust You To: - Perform IT Security assessments and partner with other security or IT professionals to assess potential impact from vulnerabilities and determine appropriate mitigating controls - Build strong partnerships with technical teams to promote best practices for managing vulnerabilities, initiate and track remediation through to completion - Understand business requirements and work with business partners to define appropriate solutions; meeting both security mandates and business needs - Help standardize workflows, processes, procedures and reporting - Partner with Cloud Engineering teams to establish security baselines and best practices - Provide security guidance to Cloud Engineering teams encompassing perimeter, misconfigurations, asset visibility, policies, container, patching cadence, and vulnerability scanning - Produce metrics and key performance indicators that demonstrate the effectiveness of remediation efforts - Improve the design and usefulness of our IT Security management tools and solutions. - Have excellent interpersonal and effective communications skills
You’ll need To Have: - Solid knowledge of Cloud Security and able to rate vulnerabilities appropriately in the context of the infrastructure & application stack- 10+ years of proven IT operations, systems management, or IT Security related experience - Hands-on expertise working with enterprise and cloud architectures - Understanding of Linux and Windows OS, system administration and engineering - Knowledge of IT security and system hardening best practices - Solid understanding of Public Cloud infrastructure concepts and terminologies - Experience analyzing vulnerability findings from IT and Security management tools - Understanding of industry security standards such as CVE, CPE, CVSS & NIST - Ability to interpret complex data sets to make informed risk-based decisions - Strong organizational skills and can effectively manage complex tasks, projects, and agile framework
We'd love to see: - AWS / Azure Solutions Architect, which is highly preferred - A Certified Cloud Security Professional (CCSP), is a plus - Experience building Cloud Resources and hardening them to CIS standards - SCRUM Master Certification / PMP Certified- Solid understanding of Risk management frameworks and security tools - Ability to learn and implement technologies quickly - Bachelor's degree in Computer Science, Engineering, or other related fields Salary Range = 195000 - 240000 USD Annually + Benefits + Bonus
The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.
We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation, [Exempt roles only], paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.
Description & Requirements
Our Team: The Threat and Vulnerability Management Team (TVM) is dedicated to making our systems and technologies as secure as possible. We protect Bloomberg. We partner with internal technical departments to ensure the confidentiality, integrity, and availability of Bloomberg systems and the data we process. We aim to ensure that our clients see us as a trusted partner.We report to the Chief Information Security Office (CISO) that owns the technical aspects of this mission by ensuring that Bloomberg products, systems, networks and commercial applications are built and maintained to be secure.
We work on purpose. Come find yours.
What’s The Role? We are seeking an IT Security Analyst to help ensure that our Public Cloud IT infrastructure and security processes are resilient against the latest threats. You will be responsible for analyzing and assessing vulnerabilities across a wide range of technologies. You'll engage with various technology partners to validate and manage identified vulnerabilities through remediation. You will work directly with other cross-department security engineering and incident response teams to set strategic direction for our enterprise Threat and Vulnerability Management program.
This is a team that drives company-wide initiatives to improve the effectiveness of Bloomberg’s security posture. Analysts in this role must show exemplary judgment in making technical decisions to achieve business goals. You're expected to always demonstrate resilience and navigate difficult situations with composure and tact.
We'll Trust You To: - Perform IT Security assessments and partner with other security or IT professionals to assess potential impact from vulnerabilities and determine appropriate mitigating controls - Build strong partnerships with technical teams to promote best practices for managing vulnerabilities, initiate and track remediation through to completion - Understand business requirements and work with business partners to define appropriate solutions; meeting both security mandates and business needs - Help standardize workflows, processes, procedures and reporting - Partner with Cloud Engineering teams to establish security baselines and best practices - Provide security guidance to Cloud Engineering teams encompassing perimeter, misconfigurations, asset visibility, policies, container, patching cadence, and vulnerability scanning - Produce metrics and key performance indicators that demonstrate the effectiveness of remediation efforts - Improve the design and usefulness of our IT Security management tools and solutions. - Have excellent interpersonal and effective communications skills
You’ll need To Have: - Solid knowledge of Cloud Security and able to rate vulnerabilities appropriately in the context of the infrastructure & application stack- 10+ years of proven IT operations, systems management, or IT Security related experience - Hands-on expertise working with enterprise and cloud architectures - Understanding of Linux and Windows OS, system administration and engineering - Knowledge of IT security and system hardening best practices - Solid understanding of Public Cloud infrastructure concepts and terminologies - Experience analyzing vulnerability findings from IT and Security management tools - Understanding of industry security standards such as CVE, CPE, CVSS & NIST - Ability to interpret complex data sets to make informed risk-based decisions - Strong organizational skills and can effectively manage complex tasks, projects, and agile framework
We'd love to see: - AWS / Azure Solutions Architect, which is highly preferred - A Certified Cloud Security Professional (CCSP), is a plus - Experience building Cloud Resources and hardening them to CIS standards - SCRUM Master Certification / PMP Certified- Solid understanding of Risk management frameworks and security tools - Ability to learn and implement technologies quickly - Bachelor's degree in Computer Science, Engineering, or other related fields Salary Range = 195000 - 240000 USD Annually + Benefits + Bonus
The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.
We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation, [Exempt roles only], paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.
Job stats:
1
0
0
Categories:
Analyst Jobs
CloudSec Jobs
Tags: Agile AWS Azure CCSP CISO Cloud Computer Science CVSS Incident response IT infrastructure Linux NIST Risk management Scrum Security assessment Vulnerabilities Vulnerability management Windows
Perks/benefits: 401(k) matching Flex vacation Health care Insurance Wellness
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Senior Cybersecurity Engineer jobsSystems Engineer jobsSenior Security Analyst jobsSenior Cloud Security Engineer jobsSystems Administrator jobsCybersecurity Editor jobsCybersecurity Content Editor jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsSenior Network Security Engineer jobsIT Security Analyst jobsChief Information Security Officer jobsSenior Information Security Engineer jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsSecurity Specialist jobsIT Security Engineer jobsSenior Product Security Engineer jobsInformation Systems Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Cyber Security Engineer jobsSenior Software Engineer jobsSecurity Operations Analyst jobsCyber Security Architect jobs
Encryption jobsJava jobsBash jobsTS/SCI jobsCEH jobsThreat detection jobsTop Secret jobsTerraform jobsSplunk jobsSDLC jobsRMF jobsMalware jobsSQL jobsSOC 2 jobsIDS jobsIPS jobsDocker jobsFinance jobsCompTIA jobsActive Directory jobsForensics jobsITIL jobsOWASP jobsIntrusion detection jobsVPN jobs
Ansible jobsGIAC jobsHIPAA jobsIT infrastructure jobsCRISC jobsTCP/IP jobsDoDD 8570 jobsClearance Required jobsOSCP jobsZero Trust jobsCCSP jobsDNS jobsMITRE ATT&CK jobsData Analytics jobsJira jobsSOX jobsIndustrial jobsJavaScript jobsCISO jobsNIST 800-53 jobsMachine Learning jobsArtificial Intelligence jobsBanking jobsSOAR jobsUNIX jobs