CASY-MSCCN Jobs

CASY-MSCCN Logo

Job Information

IQVIA Senior Vulnerability Management Analyst in Warsaw, Poland

Location: Portugal, Poland, Brazil

Work model: Hybrid (1-2 days per week in the office)

This is one of a key cybersecurity role within the global Information Security organization.

The individual fulfilling this Information Security Manager role in Vulnerability Management team will partner closely with IT professionals both within the core Global Information Security organization and those in the Global Business Units performing assessments of systems and networks within the network environment or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy and management.

RESPONSIBILITIES

  • Delivering on a portfolio of tasks as part of Vulnerability Management Service

  • Supporting the Vulnerability Management team in vulnerability scanning and other ad hoc testing, identifying and evaluating vulnerabilities in web applications and infrastructure

  • Conducting comprehensive vulnerability assessments and continuous monitoring across IQVIA

  • Apply IQVIA’s vulnerability ratings to externally rated vulnerabilities to help the business prioritize remediation

  • Support the business lead vulnerability remediation activities

  • Maintain an oversight of existing vulnerabilities in the IQVIA estate

  • Develop and document operational procedures and metrics in relation to carried out activities

  • Utilize information security technical safeguards and associated procedures, analyzing output and producing relevant management information reports for further improvements in the security safeguards landscape, including vulnerability assessment, threat intelligence and patching

  • Support audit efforts that identify technical and procedural findings, and provide recommended remediation strategies/solutions

  • Collaborate with the business, technology teams and information security management to ensure that control deficiencies are registered and remediated

  • Reporting regularly to management on the status of assigned activities including issues, risks and remediation actions.

  • Support and laisse on penetration testing activities for business units

All responsibilities are essential job functions unless noted as nonessential (N).

REQUIRED KNOWLEDGE, SKILLS AND ABILITIES

  • Information system security management, information security, troubleshooting, information systems, quality assurance and control, network security, cyber threat modeling

  • Knowledge of computer networking concepts and protocols, and network security methodologies and OSI

  • Knowledge of industry tools for security scanning and vulnerability management solutions (Qualys, Tenable Nessus or Nexpose)

  • Working knowledge of enterprise IT and cloud technologies such as networking, server infrastructure, operating systems (MS Windows and Linux), web applications and databases

  • Working knowledge of cybersecurity principles, algorithms, protocols and technologies supporting encryption, authentication, access control, information systems attack patterns, intrusion detection, and network security

  • Knowledge of IT processes (ITIL) in regulated environments

  • Knowledge of ethical hacking principles and techniques, and Application Security Risks (eg. OWASP)

  • Excellent written and verbal communication skills

  • Effective organization and time management skills

  • Ability to write with purpose, clarity and accuracy

  • Ability to work both within a team environment and independently to initiate and prioritize tasks

  • Ability to establish and maintain effective working relationships with coworkers and management in a global environment.

  • Hands-on experience in security testing of web applications and infrastructure is a plus

  • Know-how of scripting languages is a plus

  • Experience in ServiceNow is a plus.

MINIMUM REQUIRED EDUCATION AND EXPERIENCE

  • Candidate should have a minimum of 3 years Vulnerability Management experience or 5 years prior experience in information assurance, incident handling, vulnerability management and vulnerability analysis, and assistance programs

  • Candidates should possess an Bachelor's degree in Computer science, cybersecurity, information technology, software engineering, information systems, computer engineering and preferably have experience within a regulated industry environment

  • An ITIL or project management certificates are not required but beneficial.

  • A relevant qualification: CompTIA Security, CASP+, CEH, GIAC (GSEC, GCED etc.), SSCP or similar is a plus.

IQVIA is a leading global provider of advanced analytics, technology solutions and clinical research services to the life sciences industry. We believe in pushing the boundaries of human science and data science to make the biggest impact possible – to help our customers create a healthier world. Learn more at https://jobs.iqvia.com

IQVIA is a world leader in using data, technology, advanced analytics, and expertise to help customers drive healthcare – and human health – forward. Together with the companies we serve, we are enabling a more modern, more effective and more efficient healthcare system, and creating breakthrough solutions that transform business and patient outcomes.

To get there, it takes diverse skills and a curiosity to explore new possibilities. No matter your role, everyone at IQVIA, including our colleagues at Q² Solutions, contributes to our shared goal of improving human health. Thank you for your interest in growing your career with us.

EEO Minorities/Females/Protected Veterans/Disabled

DirectEmployers