|
KEY RESPONSIBILITIES |
|
Position Summary: The Threat & Vulnerability Management Engineer is responsible for the deployment, configuration, and management of vulnerability management tools and delivery of related services. The role of Threat & Vulnerability Management Engineer is to detect security vulnerabilities in information systems and drive resolution in compliance with corporate security policy. You will work with system owners to evaluate vulnerability findings, identify false-positives, and prepare & deploy patches.
Essential Duties and Responsibilities: • Collaborate with key stakeholders including senior leadership to research, develop and implement an efficient architecture to discover vulnerabilities in both shoreside and maritime systems. • Manage the entire vulnerability lifecycle from discovery, triage, remediation, and validation. • Create and evolve a risk prioritization framework that accounts for multiple factors including vulnerability severity, system function, and network accessibility. • Help asset owners create effective solutions to safely patch infrastructure at scale, including assisting with automated deployment of common patches • Promote effective remediation while preserving stakeholder happiness. • Manage day-to-day workflow to ensure vulnerabilities are remediated within proper timelines. • Create process automation including scripting and API integrations
|
|
QUALIFICATIONS AND EDUCATION |
|
• Bachelor's degree in information security or equivalent. Advanced degree preferred • 4+ years of information technology experience, including 2+ years of specialization in vulnerability management • Vulnerability Management experience, especially with vulnerability scanners (e.g. Rapid7 IVM, Tenable, etc.) and experience remediating issues with system owners • Experience hardening system images according to industry baselines, such as CIS Benchmarks • Experience with cloud security posture management tools (e.g. Orca Security, Prisma, Wiz, etc.) and remediating vulnerabilities and misconfigurations in cloud environments • Nexpose Certified Administrator certification strongly preferred • Vulnerability exploitation certifications including GEVA, GPEN, OSCP, or similar preferred • Application Security experience using SAST/DAST/SCA tools preferred • Scripting experience in Python, PowerShell, or similar tools preferred
|
|
FINANCIAL/QUANTITIVE RESPONSIBILITIES |
|
N/A
|
|
COMPARABLE POSITIONS/PEERS |
|
|
|
HOW HAS THE JOB CHANGED/GROWN |
|
(Only needed if we need to re-evaluate and grade the job. Please explain what’s different with the scope from before.)
|
|
INTERNAL/ EXTERNAL RELATIONSHIPS |
|
The role will collaborate closely with Business Application owners, and partner with key GIS teams—including Business Information Security Officers, to remediate vulnerability findings.
|
|
PHYSICAL REQUIREMENTS |
|
|
|
WORKING CONDITIONS |
|
At Royal Caribbean Group, we deliver unforgettable vacations to guests who trust us with life’s greatest moments. We build the best ships, and even better careers, all while doing the right thing. We are passionate. We are innovative. We are unstoppable. We open the world to our employees. Your journey is our journey — chart your own course. Journey with us!
Our culture: What sets the Group apart is the multicultural environment we create with employees from over 126 countries. We cultivate a workplace where employees feel they can be themselves, are appreciated because of their differences and are empowered to become part of the fabric of the Group. We have been repeatedly recognized by the Ethisphere Institute as one of the World’s Most Ethical Companies. For us, it’s a simple three-word phrase: Make good choices. Our employees have a commitment to compliance, doing the right thing and integrity.
Our brands: Royal Caribbean Group (NYSE: RCL) is a cruise vacation company comprised of three award-winning global brands: Royal Caribbean, Celebrity Cruises, and Silversea. Royal Caribbean Group is also a 50% owner of a joint venture that operates TUI Cruises and Hapag-Lloyd Cruises. Together, our brands operate a global fleet traveling to more than 800 destinations worldwide.
Our promise: We deliver the best vacation experiences, responsibly. Every one of our values and actions flows from this promise. To operate the safest ships on the seas. To protect the oceans we sail. To put people and communities first in everything we do.
Link to the careers page: https://careers.royalcaribbeangroup.com/
Take the next step in your career journey