Information Security Engineer - Vulnerability Management
American Red CrossAbout the role
Please use Google Chrome or Mozilla Firefox when accessing Candidate Home.
By joining the American Red Cross you will touch millions of lives every year and experience the greatness of the human spirit at its best. Are you ready to be part of the world's largest humanitarian network?
Join us—Where your Career is a Force for Good!
Job Description:
WHY CHOOSE US?
Joining The American Red Cross is like nothing else – it’s as much something you feel as something you do. You become a vital part of the world’s largest humanitarian network. Joining a team of welcoming individuals who are exceptional, yet unassuming. Diverse, yet uncompromising in unity. You grow your career within a movement that matters, where success is measured in people helped, communities made whole, and individuals equipped to never stop changing lives and situations for the better.
When you choose to be a force for good, you’ll have mentors who empower your growth along a purposeful career path. You align your life’s work with an ongoing mission that’s bigger than all of us. As you care for others, you’re cared for with competitive compensation and benefits. You join a community that respects who you are away from work as much as what you do while at work.
WHAT YOU NEED TO KNOW (Job Overview):
We are actively seeking and experienced Vulnerability Management Analyst to join our Information Security team. In this role, you will be responsible for monitoring and reviewing vulnerability and compliance scan results. Performing detailed research and analysis of scheduled and on demand vulnerability assessments and post results to the system owners. Communicating to the leadership the vulnerability posture of the organization assisting the organization with lowering the overall risk posture for threats to the systems and data. Qualified candidates will have a background in security or systems engineering.
The work location for this position is remote and can be worked from anywhere in the United States with core hours starting by 10am EST for a West coast work location.
This position will also be a part of on call rotation for a week at a time every 2 to 3 months managing tickets/emergencies. Need to have ability to travel to on-site meetings ~2x/year.
WHERE YOUR CAREER IS A FORCE FOR GOOD (Key Responsibilities):
Collaborate with InfoSec engineers to review, assess and provide remediation recommendations regarding discovered vulnerabilities and their potential impact to the organization.
Communicate with system owners the recommended remediation actions providing a comprehensive remediation solution as a collaborative effort to lower the risks to the organization.
Establish communications with the organization for the release of newly identified vulnerabilities.
Conduct research and evaluate technical and cyber threat intelligence to develop in-depth analysis and assessment on threats to vulnerabilities
Track progress of vulnerability remediation with responsible system owners and\or support teams.
Coordination with system owners to ensure remediation efforts are consistent with policy and escalate instances of non-compliance.
Provide organizational vulnerability reporting to leadership with tracking, remediation efforts, etc.
Respond to cyber security incidents
Typically has other unit-specific duties within the scope of the job
Scope: Individual contributor with comprehensive knowledge in specific area. Ability to execute highly complex or specialized projects. Adapt precedent and may make significant departures from traditional approaches to develop solutions.
Note: Qualified candidates must be authorized to work in the United States. The American Red Cross does not sponsor employment visas.
WHAT YOU NEED TO SUCCEED (required/minimum qualifications):
Education: Bachelor's degree in Computer Science, Computer Engineering, or related discipline required.
Experience: Minimum 4 years of related experience or equivalent combination of education and related experience required.
Management Experience: N/A
Technical experience required includes:
Microsoft Windows Server systems hardening, auditing and logging
Linux Operating Systems
Vulnerability Management Programs
Supporting a organization with threat analysis
Demonstrate advanced understanding of the principles of vulnerability assessments
Vulnerability assessment tools (Qua
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s