Information Security Analyst
- Chennai
- Engineering
- ICON Full Service & Corporate Support
Talent Acquisition Business Partner
- Full Service Division
About the role
This vacancy has now expired. Please click here to view live vacancies.
ICON plc is a world-leading healthcare intelligence and clinical research organisation. From molecule to medicine, we advance clinical research providing outsourced services to pharmaceutical, biotechnology, medical device and government and public health organisations.
With our patients at the centre of all that we do, we help to accelerate the development of drugs and devices that save lives and improve quality of life.
Our people are our greatest strength, are at the core of our culture, and the driving force behind our success. ICON people have a mission to succeed and a passion that ensures what we do, we do well.
The Role
We are seeking to hire a Senior Vulnerability Management Analyst to join our global Cyber & Information Security team. The Senior Vulnerability Management Analyst is a hands-on practitioner and representative of the vulnerability management practice in the global Cyber & Information Security team. This is a technical role and candidates must possess a solid understanding of information security, applications, operating systems, networking, cloud infrastructure, and basic attacker tactics, techniques, and procedures (TTPs).
The vulnerability analyst understands that legacy and present-day systems and applications may have weaknesses that can be exploited by external threat actors and potentially lead to compromise. Given that vulnerability management and risk exposure extend across all technical systems enterprise-wide, responsibilities of this position include identifying assets and vulnerabilities, reporting, remediation and continuous assessment. The position must collaborate with other IT, Software Development and Security Operational functions for remediation and additional validation, as well as contribute to other collaborative approaches driven by the Cyber & Information Security team strategy.
Responsibilities
- Work as part of a team to consistently learn and share advanced skills and foster team excellence.
- Manage vulnerabilities across applications, endpoints, databases, networking devices, mobile and cloud assets.
- Conduct continuous discovery and vulnerability assessment of enterprise-wide assets.
- Document, prioritize and formally report asset and vulnerability state, along with remediation recommendations and validation.
- Support various IT and Application teams in remediation efforts and ensuring that vulnerabilities have been appropriately remediated or managed in a timely manner.
- Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business and gain support through influential messaging.
- Leverage vulnerability database sources to understand each weakness, its probability and remediation options, including vendor-supplied fixes and workarounds.
- Collaborate with the IT Security Operations team and wider Information Security teams such as Cyber Risk Management, Security Architecture & Engineering and Cyber Resilience.
- Regularly research and learn new TTPs in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary.
- Perform other duties as assigned.
Requirements
- Minimum of 4 years experience in information security operations, vulnerability management, and minimum of 4 years experience in IT operations or similar role
- Bachelor’s degree in computer science, information security, or other related program
- Information security related certification desired (e.g., GEVA, GCED, GPEN, GCIH, or similar professional certification).
- Understanding of Windows and *nix operating systems, endpoint applications, networking protocols and devices.
- Experience working with a vulnerability management solution (e.g. Tenable, Rapid7, Qualys)
- Preferably some experience with vulnerability management across Amazon Web Services (AWS) or Microsoft Azure.
- Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the software development lifecycle.
- Capable of scripting in Python, Bash, Perl or PowerShell
- Familiar with the laws, regulations, industry standards and guidance pertaining to Data Protection and Information Security
- Able to handle moderate problem resolution with general supervision.
- Analytical and problem-solving mind-set.
- Must have strong interpersonal, teamwork, self-initiative skills.
Benefits of Working in ICON:
Our success depends on the quality of our people. That’s why we’ve made it a priority to build a culture that rewards high performance and nurtures talent.
We offer very competitive salary packages. And to keep them competitive, we regularly benchmark them against our competitors. Our annual bonuses reflect delivery of performance goals – both ours and yours.
We also provide a range of health-related benefits to employees and their families and offer competitive retirement plans – and related benefits such as life assurance – so you can save and plan with confidence for the years ahead.
But beyond the competitive salaries and comprehensive benefits, you’ll benefit from an environment where you are encouraged to fulfil your sense of purpose and drive lasting change.
ICON is an equal opportunity and inclusive employer and is committed to providing a workplace free of discrimination and harassment. All qualified applicants will receive equal consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.
Impactful work. Meaningful careers. Quality rewards.
At ICON, our employees are our greatest strength. That’s why we are committed to empowering you to live your best life, both inside and outside of work. Whether your ambition is lead a global team, become a deep scientific or technical expert, work in-house with our customers or gain experience in a variety of different ICON functions, we will support you in realising your full potential. See all locations Learn more about Our Culture at ICON
Day in the life
Similar jobs at ICON
Salary
Location
Poland, Warsaw
Department
Language Services
Location
Sofia
Prague
Warsaw
Bucharest
Gdansk
Remote Working
Home or Office
Business Area
ICON Full Service & Corporate Support
Job Categories
Engineering
Job Type
Permanent
Description
Solutions Architect, Language Services (AI & Management System Integration) Location: Flexible / RemoteAs a Solutions Architect specializing in language services, you will design, implement, and optim
Reference
JR127895
Expiry date
01/01/0001
Author
Hajni HowardAuthor
Hajni HowardSalary
Location
Ireland, Dublin
Department
Information technology
Location
Dublin
Remote Working
Office Based
Business Area
ICON Full Service & Corporate Support
Job Categories
Engineering
Job Type
Permanent
Description
We are looking to hire a Solutions Architect with a solid understanding of technology, who will be able to develop and size solution options, review with relevant teams and present these to stakeholde
Reference
JR131264
Expiry date
01/01/0001
Author
Damien KehirAuthor
Damien KehirSalary
Location
Poland, Warsaw
Department
Language Services
Location
Sofia
Warsaw
Remote Working
Home or Office
Business Area
ICON Full Service & Corporate Support
Job Categories
Software Engineer
Job Type
Permanent
Description
We are currently seeking a Software Engineer to join our diverse and dynamic Language Services Team. As a Software Engineer at ICON, you will play a crucial role in developing and implementing softwar
Reference
JR131113
Expiry date
01/01/0001