Jobs and Careers
JP

Security Operations Vice President - Vulnerability Management

JPMorgan Chase & Co.
Jersey City, United Statesfull_timeVerifiedPosted 23 May 2024

About the role

Embrace the challenge of maintaining robust digital security, driving operational excellence, and implementing cutting-edge solutions in cybersecurity.

As a Security Operations Vice President in Cybersecurity and Technology Controls, you will contribute significantly to safeguarding the organization's digital assets and infrastructure by proactively detecting, assessing, and responding to threats, vulnerabilities, and security incidents. You will regularly collaborate with cross-functional teams to develop a coordinated approach to security, ensuring the integrity, confidentiality, and availability of sensitive data and systems. You will apply advanced analytical, technical, and problem-solving skills to enable operational excellence and implement innovative solutions to address complex security challenges. By staying current with industry best practices, policies, and procedures, you will contribute to maintaining a secure digital environment and driving continuous improvement in the firm.

Job responsibilities

As a Vulnerability Management - Senior Operations VP, you will be a key member of the NA team, You will work directly with Line of Business Application Teams, Subject Matter Experts (SME), Production Management Teams, Product Owners, Senior Technology Management, Cyber Security Operations Teams and Risk and Control functions on:

  • Review new vulnerabilities published from multiple sources and identify those that may pose risk to the firm.
  • Define an accurate risk rating in line with proprietary and industry standard risk rating methodologies. 
  • Identifying the impacted assets and/or application(s) at risk.
  • Document the vulnerability providing a detailed write up on the risk and exposure.
  • Assess exploit code and/or conceptual code to determine attack vectors. 
  • Confirm any risk mitigation factors and define the remediation activity if known.
  • Build partnerships and workflows with Cyber Operations partners and leaders to optimize and refine vulnerability exposure checks based on exploit code analysis and attack vectors.
  • Assess security researcher vulnerabilities to drive remediation and identify any additional exposure risk.

In addition, the successful candidate will need to: 

  • Execute and influence the design of comprehensive security strategies, policies, and procedures to enhance threat detection capabilities and protect the organization's digital assets and infrastructure from cybersecurity threats
  • Proactively monitor and analyze complex data and systems to identify indicators of vulnerabilities and compromises, utilizing advanced tools and techniques to detect anomalies and contribute to the development of strategies for security investigation, threat mitigation, and incident response
  • Collaborate with cross-functional teams to ensure a coordinated approach to security, sharing insights, and promoting best practices across the organization
  • Evaluate and enhance the organization's security posture by staying current with industry trends, emerging threats, and regulatory requirements, driving innovation and process improvements

Required qualifications, capabilities, and skills

  • 5+ years of experience in cybersecurity operations, with a focus on threat detection, incident response, and security infrastructure management
  • Demonstrated expertise in multiple security domains, including network security, malware analysis, threat hunting, and security architecture and design, with proficiency in using Security Information and Event Management (SIEM) tools and advanced analytics techniques
  • Advanced knowledge of network and infrastructure configuration/security, including experience in designing and implementing security solutions for on-prem, cloud, or hybrid environments
  • Experience in a Cyber Operations/Vulnerability Management role with a strong knowledge of operational processes supporting Vulnerability Management and the wider SOC; with the ability to demonstrate comprehension of the end-to-end Vulnerability Management workflow (to include industry standards such as CVE, CPE, CVSS, and MITRE ATT&CK).
  • Proven experience in command & control practices like Incident Management and/or Cyber incident response methodologies. 
  • Strong and broad understanding of Cyber Security Controls (Physical, Logical, Processes and Procedures)
  • Strong and broad understanding of leading vendor products/applications e.g., Oracle [Java], VMWare, F5, Citrix, Microsoft; to include product lifecycle & release schedules.
  • Strong and broad understanding of open-source software deployment in a large technology estate. 
  • Strong understanding of Cloud and Public/Private Cloud environments.   

Preferred qualifications

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

JPMorgan Chase & Co.

View company profile →