Jobs and Careers
PR

Lead, Attack Surface Management Reporting & Risk-Based Orchestration

Prudential Financial
United Statesfull_timeVerifiedPosted 6 Dec 2024
💰 $186,100/yr($125,000/yr$186,100/yr)

About the role

Job Classification:

Technology - Information Security

Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency? The Global Technology team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, you’ll unlock an exciting and impactful career – all while growing your skills and advancing your profession at one of the world’s leading financial services institutions. 

Your Team & Role   

As a Lead, Attack Surface Management Reporting & Risk-Based Orchestration on the Attack Surface Management team, you will partner with IT Operational Risk teams, Chief Data Office, Chief Technology Office service delivery teams and other ASM leaders to provide technical expertise and solutions across the full lifecycle of vulnerability management. This includes asset management, scanning, threat intelligence, analysis, reporting, and integrations of your solutions.

This role will also require you to partner with stakeholders to support the implementation and alignment of operational best practices. You will need to own tasks and project workstreams, perform analysis and diagnosis of issues related to technology configuration, setup, procedural and/or process challenges, and contribute to deliverables. You will have the opportunity to work on significant and unique challenges where analysis of situations and data requires an evaluation of intangible variables which may impact future concepts, products, or technologies to ensure the security of our products and customers! In addition to software engineering skills and advanced operational experience, you will bring excellent problem solving, communication, and teamwork skills, along with agile ways of working, strong business insight, an inclusive leadership attitude and a continuous learning focus to all that you do.

Here is What You Can Expect on a Typical Day

  • Manage the day-to-day Operations team work, while guiding and transferring knowledge to more junior team members. Guide teams through project work, goals, and alignment of tasks to deliver objectives and meet commitments.  
  • Function as the subject matter expert on workflow orchestration tools, processes, and capabilities critical to the Attack Surface Management team.  Create workflows to resolve business use cases. Collaborate with stakeholders to understand requirements and design capabilities specific to different stakeholder personas (remediation owner, GRC, business owner, service delivery, vulnerability management).
  • Design the system to support optimized lifecycle management processes across multiple assessments (manual and automated).  Design the system for scale (via APIs integrated with assessment tools) and automate as much capability as feasible to enable self-service.
  • Develop and implement detailed technical and configuration specifications to enable the system to support lifecycle management of the various ASM functions (vulnerability management, penetration testing, OSS vulnerability management, EOL management, container vulnerability management, configuration baselines/compliance monitoring, IaC, etc.)
  • Support product management of the orchestration tools used by ASM such as ServiceNow Vulnerability Response (VR) and Configuration Compliance (CC) modules, including design, configuration/development and operational support.
  • Enable UX/UCD (user focused design) to reduce friction in managing remediation efforts, support clear risk-based prioritization and self-service.
  • Function as the escalation point for all Security Operations daily operational and maintenance work as well as project work from more junior staff on the team 
  • Leverage ASM tool/process specific knowledge to resolve complex technical/process/people problems the team faces. 
  • Leverage organizational and industry knowledge to bridge gaps between the ASM teams (Offensive/Product Security, Application Security, VM and Compliance Monitoring) and internal IT/business teams to ensure the team has the information and resources they need to meet team goals.  Ability to innovate and think broadly across multiple platforms required.
  • Partner with leadership to set direction for the future of the Attack Surface Management reporting & risk-based orchestration program, while ensuring an accurate understanding and in-depth knowledge of daily operations to provide ASM orchestration and integration recommendations. 
  • Ensure reporting data validation and metrics to ensure accurate risk posture to leadership and evolve reporting as necessary to support. Must have a clear understanding and familiarity with ETL processes used on source data.
  • Revise processes and

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Prudential Financial

View company profile →