Threat Manager - Background:

The Global Threat Management team delivers proactive, protective information security services to Pearson and its applications.

 

Role Description:

The role is to provide first-level analysis of information from vulnerability management and threat intelligence toolsets, and to manage the interface with application and IT owners to effect valid remediation of vulnerabilities, and the reduction of threat across the business.  Candidates need to have a good understanding of Operating System technologies, and particularly a good grasp of OS vulnerabilities.  A knowledge of security fundamentals is essential along with an overall appreciation of security technologies and how they are used.

 

Main Responsibilities:

The main responsibilities of a Threat Manager are as follows:

  • Manage and maintain the Qualys vulnerability scanning toolset and scans
  • Analyse vulnerability data for completeness and immediate risk.
  • Interface with Senior and Principal Threat Managers to deliver Vulnerability Remediation service
  • Raise remediation tickets in response to Senior Threat Manager vulnerability analysis
  • Communicate with technology owners to find and reduce false positives
  • Present escalations for failing remediation to Senior and Principal Threat Managers
  • Analyse and assess intelligence from Threat Intelligence providers in concert with Senior and Principal threat managers
  • Assist Principal and Senior Threat Managers in their role as SME for vulnerability and threat intelligence on Incident Management Bridges
  • Produce security summary and activity reports as required
  • Contributes to project and/or development activities as designated by the GTM Director.
  • Provides assistance to other SecOps team members
  • Any other duties as designated by the GTM Director or their authorised deputies.

 

Key Attributes:

  • Applicants should be able to quickly assess and provide relative risk assessments for various vulnerabilities based on location, criticality and threat vector.
  • They should be calm and able to continue to provide a good service when under pressure

 

Competencies:

  • A clear understanding of Server and Desktop Operating Systems (OS).
  • Thorough understanding of network protocols, TCP/IP fundamentals
  • Good understanding of Industry trends and emerging threats.
  • In depth knowledge of Windows and Linux vulnerabilities and patching strategies

 

Abilities:

  • An ability to build strong relationships with internal teams, and senior leadership, is essential.
  •  Must have concise, detail-oriented approach to written/verbal communications and documentation.
  •  Ability to handle fluctuating workloads, conflicting priorities and concurrent activities.

 

Qualifications:

  • Formal education or equivalent experience (note: this is the minimum requirement. Equivalent experience in lieu of a formal degree should be listed.)
  • Bachelor’s degree or appropriate combination of education and experience.
  • One of or combination of:  CEH / ECSA / Security+ / GCIA / GCIH / GSEC  or other similar qualification. (other vendor specific qualifications helpful such as MCSE, RHCE, CCSA)
  • ITIL V3 Foundations highly preferred.
  • Above all, must have a passion for Security.

 

Please click the link to apply http://pearsonlankavacancies.peopleshr.com/