Description & Requirements
For more than 100 years, Xerox has continually redefined the workplace experience. Harnessing our leadership position in office and production print technology, we’ve expanded into software and services to sustainably power the hybrid workplace of today and tomorrow. Today, Xerox is continuing its legacy of innovation to deliver client-centric and digitally-driven technology solutions and meet the needs of today’s global, distributed workforce. From the office to industrial environments, our differentiated business and technology offerings and financial services are essential workplace technology solutions that drive success for our clients. At Xerox, we make work, work. Learn more about us at www.xerox.com.
We are seeking a dedicated and skilled Vulnerability Management Analyst to join the cybersecurity team. This role plays a key part in identifying, assessing, and reporting on security vulnerabilities across the organization’s technology infrastructure, and in working with our partners in IT and Engineering to remediate them. The position is critical to maintaining the security and integrity of systems and data.
WHAT YOU WILL BE DOING
- Analyze scan results to prioritize and categorize risks and vulnerabilities based on their severity and potential impact.
- Collaborate with system owners and support teams to prioritize and facilitate the remediation of identified vulnerabilities, track progress, and ensure timely resolution.
- Perform regular compliance and vulnerability rescans using industry-standard tools to validate remediation of security weaknesses in the organization’s systems, networks, and applications.
- Stay informed about emerging security threats, risks, and vulnerabilities, as well as industry best practices for vulnerability management.
- Perform technical evaluations of vulnerabilities to determine potential remediation paths and/or mitigations.
MUST-HAVE QUALIFICATIONS, SKILLS, EXPERIENCE
- Strong IT background and knowledge of IT business systems.
- Familiarity with security standards, frameworks, and compliance requirements.
- Excellent communication skills, both written and verbal.
- Detail-oriented and able to manage multiple tasks effectively.
- Demonstrated experience in vulnerability management, cybersecurity, or related roles. (Preferred)
- Proficiency with vulnerability scanning tools such as Nessus, Qualys, OpenVAS, or Tenable, and experience with vulnerability assessment methodologies. (Preferred)
- Knowledge of network security architecture concepts, including topology, protocols, components, and principles such as defense-in-depth. (Preferred)
- Understanding of how traffic flows across the network, including TCP/IP, OSI Model, ITIL, and related concepts. (Preferred)
- Knowledge of system and application security threats and vulnerabilities, such as buffer overflow, mobile code, cross-site scripting, PL/SQL injections, race conditions, covert channels, replay, return-oriented attacks, and malicious code. (Preferred)
- Knowledge of penetration testing principles, tools, and techniques. (Preferred)
EXPERIENCE WITH THE FOLLOWING ARE DIFFERENTIATORS
- Ability to work independently and as part of a team.
- Strong organizational skills and the ability to prioritize tasks effectively.
- Ability to think systematically, identify patterns, and solve problems in a structured way.
CERTIFICATIONS (PREFERRED BUT NOT REQUIRED)
· Relevant certifications, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Ethical Hacker (CEH), are a plus.
EDUCATIONAL QUALIFICATIONS
· Bachelor’s degree in Business, Information Technology, Computer Science, Engineering, Cybersecurity, or a related field.
YEARS OF EXPERIENCE IN THIS FIELD
- 3+ years of Information Technology experience; 5+ years preferred.
- 1+ year of experience in vulnerability management; 3+ years preferred.