Threat & Vulnerability Analyst

Regeneron

  • Bangalore, Karnataka
  • Permanent
  • Full-time
  • 29 days ago
At Regeneron, we believe that when the right idea finds the right team, powerful change is possible. As we work across our growing global network to invent, develop and commercialize life-transforming medicines for people with serious diseases, we're establishing new ways to think about science, manufacturing and commercialization. And new ways to think about health. TVM Analysts focus on cybersecurity vulnerability identification, facilitate priority-based patching, and validate remediation effectiveness. Operational requirements include leveraging TVM and information technology service management (ITSM) platforms to provide visibility, quantification, and accountability for remediation efficacy. JOB DUTIES: Manage cybersecurity vulnerabilities and risks across Regeneron including identifying, supporting application and system owners to manage risks and remediate vulnerabilities. Conduct vulnerability assessments of scans of servers, websites, workstations, serverless technology, network devices, cloud infrastructure, and other assets using various vulnerability management platforms and tools. Analyze enterprise cybersecurity policies and configurations to evaluate compliance with regulations and enterprise policies and standards. Assist with selection of industry best of breed cybersecurity controls to mitigate risk. Collection, reporting, and metrics generation for multiple cyber TVM datasets. This includes patching efficiency, identifying system misconfigurations, and security hygiene assessments. Support the process of Security Compliance assessments of systems and multi-tenant cloud services, leveraging industry best practices, to include, Center for Internet Security (CIS) hardening guidelines. Analysis and monitoring of cybersecurity feeds, cyber threat intelligence, and open-source intelligence on trending vulnerabilities and exploits. Partner with IT service providers to operate, maintain, and enhance TVM platforms. This includes native Operating System, cloud security, and data aggregation platforms. Required: Knowledge and Experience Five or more years' experience; Vulnerability Management, cybersecurity operations, Information technology, Information Security tools and techniques Knowledge, proven ability, and skills in vulnerability assessment, prioritization, assignment, validation, and tracking. Experience and working knowledge of vulnerability management tools such as Nmap, Qualys, Tenable, Nessus, Microsoft Defender, Wiz, Rapid7, AWS Inspector, Orca. Familiarity with OWASP (Open Web Application Security Project) Top 10, CIS Security Controls, MITRE ATT&CK Framework Working knowledge of multi-tenant cloud environments (AWS, Azure, GCP), vulnerability mitigation techniques, and system hardening. Collaboration Collaborate and partner with cross-departmental peers (technical and non-technical) to report, synthesize, and prioritize vulnerabilities and threats based on contextual assets and relationship data. Innovation Leverage industry and compute environment data to assess current and alternative technical solutions and processes for continuous enhancement and issue resolution. Skills/Tools Proven threat and vulnerability assessment skills or knowledge gained through experience or academia. Ability to understand threat modeling and apply technical, administrative, and security control risk mitigation. Organized, reliable, detail oriented. Proven or conceptual abilities to navigate levels through thought equity. Preferred: Cybersecurity tool familiarity. E.g., SIEM (Security Information and Event Management), IDS/IPS, Email Protection, Firewalls, DLP (Data Loss Prevention), EDR (Endpoint Detection and Response), etc. Experience gained through a complex organization and managed security providers and vendors. Excellent problem-solving skills and attention to detail. Proven experience in customer service, communication, and relationship building. Ability to work independently and as part of a team. Required Licenses & Certificates: CISSP, CEH, Security+, Network+ or equivalent are preferred. Not required. Connect with us, so we can learn more about you, and you can learn more about our medicines. And Join us in shaping the future of healthcare. Regeneron is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion or belief (or lack thereof), sex, nationality, national or ethnic origin, civil status, age, citizenship status, membership of the Traveler community, sexual orientation, disability, genetic information, familial status, marital or registered civil partnership status, pregnancy or parental status, gender identity, gender reassignment, military or veteran status, or any other protected characteristic in accordance with applicable laws and regulations. We will ensure that individuals with disabilities are provided reasonable accommodations to participate in the job application

foundit

Similar Jobs

  • Threat & Vulnerability Analyst

    Regeneron

    • Bangalore, Karnataka
    Threat & Vulnerability Management (TVM) Analysts support Regeneron's TVM capability to identify, assign, and validate remediation of compute environment vulnerabilities. This encom…
    • 24 days ago
  • Sr. Threat Analyst | On-site, Bangalore

    Optiv

    • Bangalore, Karnataka
    The Senior Threat Analyst will provide deep-level analysis for client investigations utilizing customer-provided data sources, audit, and monitoring tools at both the government an…
    • 24 days ago
  • Threat Analyst I On-site, Bangalore

    Optiv

    • Bangalore, Karnataka
    The Threat Analyst will provide intrusion/incident monitoring and detection utilizing customer provided data sources, audit, and monitoring tools at both the government and enterpr…
    • 24 days ago