Vulnerability Management Analyst — Remediation Tracking forNATO with security clearance
Il y a 1 jour
Wallonia, Wallonia, Belgique
WLG
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
Most organisations can scan. Far fewer can say what
the scans mean, who owns each finding and whether anything was
fixed. A multinational defence organisation is looking for the
analyst who closes that gap — half security assessment, half data
engineering, and the coordination that turns a report into a
repaired system. What you would be doing Reading the weekly
assessment results, interpreting the technical findings, and
writing the remediation plan that goes to the right technical
owner. Judging technical impact so that remediation is prioritised
on risk rather than on volume, and advising on hardening at
operating system, database and network level. Building and running
the data side: a structured repository that aggregates raw scan
output from several sources, and the pipeline that ingests it
without manual handling. Designing and maintaining live dashboards
in Power BI or Grafana, and the metrics that make operational and
management reporting meaningful. Acting as the technical contact
for site administrators and system owners, and keeping the
remediation tracking honest and current. Producing the weekly and
monthly reporting, and chairing the coordination meetings where
roadblocks get cleared. Leaving behind documentation good enough
that the platform can be maintained without you. What you would
bring Substantial vulnerability management experience, current
rather than historical, plus a track record of validating that
delivered work meets its security requirements. Practical
familiarity with scanners and their output formats — Nessus,
Qualys, OpenVAS. A working grounding in security architecture:
boundary protection, encryption, identity and access, monitoring
and detection, incident response and risk. Real SQL depth for
modelling and querying large scan datasets, in PostgreSQL or SQL
Server. Advanced Power BI, including data modelling and DAX, or the
Grafana equivalent against SQL and time-series sources. Python with
Pandas or NumPy, or PowerShell, for parsing scan output and
removing manual steps. Ownership: the motivation to carry a task to
its end, alone or in a team, and the writing to show for it. Nice
to have: certifications such as CISSP, CISM or a GIAC, and a data
or business intelligence certification such as PL-300. Extensions
are offered where the work goes well. Applications are reviewed as
they arrive.