Full-Time

Lead – Attack Surface Management Reporting & Risk-Based Orchestration

Confirmed live in the last 24 hours

Prudential Financial

Prudential Financial

10,001+ employees

Provides insurance, investment, and retirement solutions

Fintech
Financial Services

Compensation Overview

$125k - $186.1kAnnually

+ Yearly Bonus Potential + Additional Compensation

Senior

Newark, NJ, USA

Category
Cybersecurity
IT & Security
Required Skills
PowerShell
Power BI
Python
JavaScript
Git
JIRA
REST APIs
Development Operations (DevOps)
Requirements
  • Bachelor of Computer Science or Software Engineering or experience in related fields
  • Scripting / programming skills (e.g., Python, PowerShell, JavaScript, Glide)
  • CIS Vulnerability Response or CIS-Configuration Compliance certification
  • Significant experience and/or deep expertise with several of the following: Development of a risk rubric across assessment tools to support consistent, predictive analytics and prioritization, Service Now development, administration, implementation, and integration experience with core orchestration capabilities (Vulnerability Response Enterprise – Including Application Vulnerability Response, Container Vulnerability Response, Patch Orchestration, Cloud Container Security, CSAM, SBOM and Configuration Compliance).
  • Experience with utilizing Power BI for dashboard reporting
  • Candidates must have operational knowledge of the vulnerability assessment lifecycle, including identification of vulnerabilities, risk rating, threat correlation, asset-based remediation management, reporting, and exceptions management.
  • Candidates must be familiar with various vulnerability and security scanning tools, should be familiar with CVEs, CVSS, DevOps, CIS Benchmarks, OWASP, and Mitre as well as other industry specific vulnerability classification standards, frameworks, and best-practices.
Responsibilities
  • Manage the day-to-day Operations team work, while guiding and transferring knowledge to more junior team members.
  • Function as the subject matter expert on workflow orchestration tools, processes, and capabilities critical to the Attack Surface Management team.
  • Create workflows to resolve business use cases.
  • Collaborate with stakeholders to understand requirements and design capabilities specific to different stakeholder personas (remediation owner, GRC, business owner, service delivery, vulnerability management).
  • Design the system to support optimized lifecycle management processes across multiple assessments (manual and automated).
  • Design the system for scale (via APIs integrated with assessment tools) and automate as much capability as feasible to enable self-service.
  • Develop and implement detailed technical and configuration specifications to enable the system to support lifecycle management of the various ASM functions (vulnerability management, penetration testing, OSS vulnerability management, EOL management, container vulnerability management, configuration baselines/compliance monitoring, IaC, etc.).
  • Support product management of the orchestration tools used by ASM such as ServiceNow Vulnerability Response (VR) and Configuration Compliance (CC) modules, including design, configuration/development and operational support.
  • Enable UX/UCD (user focused design) to reduce friction in managing remediation efforts, support clear risk-based prioritization and self-service.
  • Function as the escalation point for all Security Operations daily operational and maintenance work as well as project work from more junior staff on the team.
  • Leverage ASM tool/process specific knowledge to resolve complex technical/process/people problems the team faces.
  • Leverage organizational and industry knowledge to bridge gaps between the ASM teams (Offensive/Product Security, Application Security, VM and Compliance Monitoring) and internal IT/business teams to ensure the team has the information and resources they need to meet team goals.
  • Partner with leadership to set direction for the future of the Attack Surface Management reporting & risk-based orchestration program, while ensuring an accurate understanding and in-depth knowledge of daily operations to provide ASM orchestration and integration recommendations.
  • Ensure reporting data validation and metrics to ensure accurate risk posture to leadership and evolve reporting as necessary to support.
  • Revise processes and procedures, metrics, and documentation that continue to improve orchestration and attack surface tracking capabilities.
  • Ingestion and maintenance of common vulnerability feeds from government, vendor, and open-source communities.
  • Work with IT peers and business stakeholders to ensure remediation efforts adhere to corporate standards and policies.
  • Align reporting to business operational models and compliance controls (SOX, NIST CSF).
  • Create team run books for scanning and reporting processes developed.
  • Develop and maintain integration documentation, including data flow diagrams, mapping, and technical specifications.
  • Design, configure, and support data integrations (use and understanding of REST API or creation of integration points outside of those directly supported by vendors) for Qualys, Wiz, Threat Intelligence, Xray, HackerOne, Checkmarx, GitHub, AquaSec, NVD, JIRA, Guardium, ServiceNow Change Mgmt, etc.
  • Design, configure and support Flow Designer flows and sub-flows leveraging REST API for data exchange.
  • Liaison with CMDB team to enhance CMDB as it relates to VR and CC data requirements.
  • Enhance reporting capability of both VR and CC as it relates to dashboards, Power BI reports, and performance analytics.
  • Customize VR and CC roles and groups.
  • Build a roadmap and plan to support VR and CC dependencies and upgrades.
  • Monitor and troubleshoot integration and workflow issues to ensure system reliability and performance.
  • Ensure data security and compliance with relevant regulations and standards during integration, development, and process workflow designs.

Prudential Financial provides a variety of financial services, including insurance, investment management, and retirement planning. Their products help individuals and institutions achieve financial security and growth. Prudential offers life insurance, annuities, mutual funds, pension services, and asset management. The company generates revenue through premiums, fees, and investment income. What sets Prudential apart from its competitors is its focus on building long-term relationships with clients and offering comprehensive financial planning to ensure they are prepared for the future.

Company Stage

IPO

Total Funding

N/A

Headquarters

Newark, United Kingdom

Founded

N/A

Simplify Jobs

Simplify's Take

What believers are saying

  • Prudential's leadership in the financial services industry is reinforced by its strategic investments and acquisitions, which can lead to enhanced growth opportunities.
  • The company's recognition as a top company for executive women highlights its commitment to diversity and inclusion, potentially attracting top talent.
  • Prudential's focus on outcome-based work and strategic workforce management can lead to increased productivity and employee satisfaction.

What critics are saying

  • The financial services industry is highly competitive, and Prudential must continuously innovate to maintain its market position.
  • Economic downturns or changes in regulatory environments could impact Prudential's revenue streams from premiums, fees, and investment income.

What makes Prudential Financial unique

  • Prudential Financial's global reach and comprehensive suite of financial services, including insurance, investment management, and retirement planning, set it apart from competitors who may focus on narrower market segments.
  • The company's focus on long-term relationships and comprehensive financial planning ensures a personalized approach that is often lacking in more transactional financial service providers.
  • Prudential's strategic investments, such as its stake in Qianhai Re and leadership in funding rounds like FIDx, demonstrate its commitment to innovation and market expansion.

Help us improve and share your feedback! Did you find this helpful?