AXA GBS Morocco
OffresSala al JadidaVulnerability Management Analyst

Vulnerability Management Analyst

AXA GBS Morocco- Informatique / Electronique- Informatique
Sala al JadidaCDIConfirmé (5 à 10 ans) d'experienceBac +5 et plus Minimum

Creez un compte NewJob.ma avant de continuer sur le site web de l'entreprise.

Description du poste

The main mission of the Security Engineer Vulnerability and threat Management is to perform scans and reports using the Qualys Guard tool.

You’ll be responsible of performing and scheduling compliance and vulnerability scans on AXA network activity and infrastructure and generating reports to different teams (such as server admins, network administrators in order to mitigate scanned vulnerabilities).

The role consists also of integrating and managing different assets in the Qualys Guard modules.

Conduct vulnerability scanning and assessment functions related to various clients, environments, technologies, systems and appliances

Coordinate effectively with representatives of different Business Units and technology specialists

Integrate and manage assets in Qualys

Effectively communicate security vulnerabilities and risks to issue owners and assist in remediation efforts

Govern and enforce cybersecurity policies and vulnerability remediation deadlines

Develop and maintain executive dashboards and/or regular reports to communicate department-specific cybersecurity risks and threats

  • Provide a monthly/Weekly analysis of common vulnerabilities and compliance issues
  • Produce a periodic dashboard demonstrating remediation progress and cases’ status

Profil recherche

Minimum Bac+5 in Networks and Security.

An information Security Certification is highly desired (CCNA R&S, CCNA Security, NSE4, PCCSA, MCSA, CEHv9/v10…or/and equivalent)

Due to the sensitive nature of the task, the role holder must have a demonstrated high level of work ethics, secrecy and discretion. A background check will be performed.

Global technical vision of the main security tools / environments:

PKI, SIEM, SOC, authentication, IPSEC, AD security, operating system security, Windows account security

Experience managing data security programs like Password Vaulting, Privileged Access Management (Cyber Ark)

Experience with Identity Management concepts and processes including authorization, authentication, segregation of duties

Knowledge of best practices around data security

Experience using an ITSM tool such as ServiceNow

Strong fundamentals in networking protocols and troubleshooting

Knowledge of hacking techniques, cyber threats and security trends

At least 2 years’ experience in the cybersecurity industry

  • Experience with vulnerability management tools (e.g. Kenna, Nexpose, Tenable, Qualys, etc.)
  • Hands-on experience with Qualys, a certification is a plus
  • Work on maturing vulnerability management & Compliance program services and processes
  • Develop and improve KPIs, metrics, and trend analysis for vulnerability management functions
  • Take part of the implementation and operational best practices while taking ownership of tasks and/or project workstreams
  • PowerShell and Python scripting skills
  • Coding skills, such as HTML, CSS, Power Query and other languages
  • Analytical thinking, time management and coordination skills
  • Fluent English (Very important)