Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Vulnerability Analyst image - Rise Careers
Job details

Vulnerability Analyst

Annual Wage Range: $104,000.00 - $143,000.00Other Compensation: Eligibility for the Short-Term Incentive program and other applicable bonusesBenefits: U.S. Employee Benefits Summary (grace.com)Final salary and compensation will be based on several factors including candidate qualifications and experience, geographical location, market, and business considerations.Job DescriptionThe Cybersecurity team at Grace is seeking to hire a versatile and highly motivated vulnerability analyst to join our global team. Reporting to the Grace Deputy CISO, the Vulnerability Analyst will play an important role for our cybersecurity program by supporting a full suite of security assurance services including vulnerability management, configuration management, and application security and will serve as the Grace technical subject matter expert (SME) for associated tools and technologies. This entails managing and maintaining vulnerability management tooling and infrastructure, coordinating authenticated and unauthenticated scans against infrastructure and web applications, assisting with measuring and maintaining secure configuration baseline of infrastructure, maintaining asset ownership, and managing the end-to-end remediation process including coordination with all relevant IT stakeholders.Responsibilities• Support Vulnerability Management, Configuration Management, and Application Security services• Provide input on vulnerability and risk prioritization based on Grace’s environment• Maintain awareness of emerging threats and vulnerabilities• Serve as the technical subject matter expert for all things Vulnerability, Configuration Management, and Application SecurityRequirements• At least 3-5 years of experience within cybersecurity, with a focus on vulnerability management• Hands-on operational experience with enterprise vulnerability management and scanning solutions, such as Tenable or Qualys, and ability to both deploy and manage• Experience with Cloud-Native Application Protection Platform (CNAPP) solutions, such as Wiz or Rapid7• Experience with SAST/DAST scanning technologies, such as Qualys and Checkmarx• Understanding of vulnerability scoring systems and methodologies (i.e.: CVSS, EPSS, CWE, OWASP, etc.)• Familiarity with cloud environments, such as Google Cloud and Microsoft Azure• Practical experience with scripting, use of APIs, and developing automation capabilities• Experience with IT Service Management solutions for ticket assignment• Ability to communicate to both technical and non-technical audiences, including leadership teams• Experience with generating regular metric reports for stakeholders and leadership teams• Ability to work alongside with and support other security-related functions as needed• Prior experience within a service delivery or consultancy role a plus• Passionate about cybersecurity and technologyBenefits• Medical, Dental, Vision Insurance• Life Insurance and Disability• Grace Wellness Program• Flexible Workplace• Retirement Plans• 401(k) Company Match – Dollar to dollar up to the first 6%• Paid Vacation and Holidays• Parental Leave• Tuition Reimbursement• Company Donation Match ProgramGrace is not accepting unsolicited assistance from search firms for this employment opportunity. Please, no phone calls or emails. All resumes submitted by search firms to any employee at Grace via email, the Internet or in any form and/or method without a valid written search agreement in place for this position will be deemed the sole property of Grace. No fee will be paid in the event the candidate is hired by Grace as a result of the referral or through other means.
W. R. Grace & Co. Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
W. R. Grace & Co. DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of W. R. Grace & Co.
W. R. Grace & Co. CEO photo
Ed Sparks
Approve of CEO

Average salary estimate

Estimate provided by employer
$90000 / ANNUAL (est.)
min
max
$85K
$95K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Vulnerability Analyst, W. R. Grace & Co.

Join the Cybersecurity team at Grace as a Vulnerability Analyst in beautiful Columbia, MD! Here, we’re looking for a dedicated, motivated individual who’s eager to protect our organization against emerging threats and vulnerabilities. As part of a global team, you’ll report directly to the Grace Deputy CISO and play a pivotal role in our cybersecurity program. Your daily focus will include managing our vulnerability management toolset and coordinating both authenticated and unauthenticated scans across our IT infrastructure and web applications. You'll also help maintain our secure configuration baselines and ensure smooth asset ownership management. With 3-5 years of experience in cybersecurity, particularly in vulnerability management, you’ll be our go-to technical subject matter expert. You'll utilize tools like Tenable or Qualys to enhance our systems, contribute to risk prioritization, and prepare insightful reports for leadership. If you're passionate about cybersecurity and want to make a real impact, come discover the fantastic benefits we offer, including generous health plans, a flexible workplace, and retirement matching. Step into your next adventure with Grace today!

Frequently Asked Questions (FAQs) for Vulnerability Analyst Role at W. R. Grace & Co.
What are the primary responsibilities of a Vulnerability Analyst at Grace?

At Grace, the Vulnerability Analyst will be responsible for supporting a variety of cybersecurity services, including vulnerability management, configuration management, and application security. This role involves maintaining and managing vulnerability scanning tools, coordinating scans, and assisting in the development of secure configurations. The analyst will also act as a subject matter expert for vulnerability tools and help prioritize risks based on the prevalent threats in Grace's environment.

Join Rise to see the full answer
What qualifications are required for the Vulnerability Analyst position at Grace?

To qualify for the Vulnerability Analyst role at Grace, candidates should have 3-5 years of experience in cybersecurity with a strong focus on vulnerability management. This includes hands-on experience with tools like Tenable or Qualys, as well as knowledge of Cloud-Native Application Protection Platforms (CNAPP) such as Wiz or Rapid7. Familiarity with SAST/DAST scanning technologies, as well as an understanding of vulnerability scoring systems like CVSS, is also needed.

Join Rise to see the full answer
What tools and technologies does a Vulnerability Analyst at Grace use?

The Vulnerability Analyst at Grace works with various enterprise vulnerability management and scanning solutions, primarily Tenable and Qualys. They also engage with Cloud-Native Application Protection Platforms such as Wiz or Rapid7 and utilize SAST and DAST technologies for vulnerability assessment. Moreover, practical experience with scripting and automating processes through API integration forms a crucial part of this role.

Join Rise to see the full answer
How does the Vulnerability Analyst contribute to Grace's cybersecurity strategy?

The Vulnerability Analyst plays a vital role in the overall cybersecurity strategy at Grace by providing technical expertise in vulnerability assessment and management. They assess emerging threats, help prioritize vulnerabilities, and collaborate with other IT stakeholders to coordinate remediation efforts effectively. Their reporting also aids leadership teams in understanding the security posture and risks, which allows for more informed decision-making.

Join Rise to see the full answer
What are the benefits of working as a Vulnerability Analyst at Grace?

Working as a Vulnerability Analyst at Grace comes with a range of attractive benefits. Employees enjoy comprehensive medical, dental, and vision insurance, life insurance, and a wellness program. Grace ensures work-life balance with flexible workplace options, generous vacation time, and a solid retirement plan with 401(k) matching. Additionally, tuition reimbursement and a donation match program add further value to being part of the Grace team.

Join Rise to see the full answer
Common Interview Questions for Vulnerability Analyst
Can you explain your experience with vulnerability management tools?

When answering this question, focus on the specific tools you have used, such as Tenable or Qualys. Describe projects where you've implemented these tools, details regarding your role in configuring scans, and how you interpreted the results to inform security decisions. Highlight your problem-solving skills and adaptability with technology.

Join Rise to see the full answer
How do you prioritize vulnerabilities in a dynamic environment?

Discuss your approach toward risk assessment using frameworks like CVSS or OWASP. Highlight how you analyze the potential impact and exploitability of vulnerabilities based on the organizational context. Use examples to demonstrate your decision-making process under pressure.

Join Rise to see the full answer
What strategies do you use to stay updated on emerging threats?

Explain your methods for continuous learning and staying informed about cybersecurity trends. Mention sources such as industry websites, threat intelligence reports, forums, and professional groups. Show an understanding of the importance of proactive vigilance in cybersecurity.

Join Rise to see the full answer
Describe a challenging vulnerability you encountered and how you addressed it.

Share a specific instance where you faced a significant vulnerability. Discuss the steps you took to analyze, document, and remediate it, emphasizing teamwork or communication with stakeholders. Offer insights into the lessons learned and how it improved your overall approach.

Join Rise to see the full answer
How do you communicate technical information to non-technical stakeholders?

Illustrate your communication skills by explaining how you tailor your messaging to different audiences. Provide examples of reports or briefings you’ve conducted, emphasizing simplification of complex concepts without oversimplifying the risks involved.

Join Rise to see the full answer
What experience do you have with cloud security and vulnerability management?

Detail your experience with cloud environments such as Google Cloud or Microsoft Azure. Discuss specific challenges related to securing cloud infrastructure and how you’ve applied tools for managing vulnerabilities in these contexts.

Join Rise to see the full answer
Can you share an example of generating security reports for leadership?

Describe the process you followed in creating security reports, including data collection, analysis, and visualization. Comment on the significance of providing actionable insights and how these reports influenced decision-making within the organization.

Join Rise to see the full answer
How do you manage the remediation process for identified vulnerabilities?

Outline your approach to vulnerability remediation, from identifying issues to coordinating efforts with IT stakeholders. Highlight how you ensure timely remediation actions and follow-up checks to confirm effectiveness, showcasing your project management skills.

Join Rise to see the full answer
What role do you think scripting plays in vulnerability management?

Emphasize the importance of scripting in automating tasks and improving efficiency in vulnerability management processes. Share examples of scripts you’ve developed to enhance scanning, reporting, or remediation workflows.

Join Rise to see the full answer
Why do you want to work at Grace as a Vulnerability Analyst?

Reflect on Grace’s values, mission, and innovative culture. Share how your background aligns with their goals in cybersecurity and express your enthusiasm for being part of their team. Highlight your eagerness to contribute and grow within their organization.

Join Rise to see the full answer
Similar Jobs
Weisiger Group Hybrid No location specified
Posted 14 days ago
Photo of the Rise User
Posted 4 hours ago
Photo of the Rise User
iT1 Hybrid No location specified
Posted 9 days ago
Photo of the Rise User
Posted 2 days ago

Our promise to customers, to our communities, and to ourselves is to deliver value; safely, reliably, and creatively. When we do, the lives touched by our products and those of our customers are made better.

9 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 3, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!