Jobs and Careers
DI

Vulnerability Analyst

Discover
Riverwoods, IL, United Statesfull_timeVerifiedPosted 21 Jun 2024
💰 $149,300/yr($88,500/yr$149,300/yr)

About the role

Discover. A brighter future.

With us, you’ll do meaningful work from Day 1. Our collaborative culture is built on three core behaviors: We Play to Win, We Get Better Every Day & We Succeed Together. And we mean it — we want you to grow and make a difference at one of the world's leading digital banking and payments companies. We value what makes you unique so that you have an opportunity to shine.

Come build your future, while being the reason millions of people find a brighter financial future with Discover.

Job Description:

At Discover, be part of a culture where diversity, teamwork, and collaboration reign. Join a company that is just as employee focused as it is on its customers and is consistently awarded for both. We’re all about people, and our employees are why Discover is a great place to work. Be the reason we help millions of consumers build a brighter financial future and achieve yours along the way with a rewarding career. 

As a Vulnerability Analyst you will:

  • Write comprehensive cybersecurity risk assessments identifying threats & vulnerabilities and recommend remediation.

  • Conduct formal, systematic threat modeling of IT systems using STRIDE methodology.

  • Apply deep knowledge of procedure-based controls of a cybersecurity program including qualitative risk analysis steps, vulnerability and patch management, threat modeling, Identity and Access Management (IAM), cybersecurity frameworks (NIST CSF, PCI-DSS and CIS).

  • Practice expert level assessment skills using technology-based controls of a cybersecurity program including cloud security, Artificial Intelligence / GenAI risks, penetration testing results, cryptography & network security fundamentals, malware defense, data loss prevention and endpoint security.

  • Compile professional security assessment reports, slides, and lead discussions to effectively communicate the risks and remediation options to partners.

  • Demonstrate sound knowledge of Incident Management Respond and Recover functions from a cyber resiliency perspective.

Responsibilities 

  • Work independently to identify vulnerabilities in deployment of technologies, severity, and impact, and recommend risk-based options for remediation. 

  • Actively collaborate with business partners, application architects and partner security teams to research and build security solutions aligned to business goals.

  • Learn advanced cybersecurity concepts including new and modern threat exploitation techniques of threat actors.

  • Achieve team commitments (and influence others to do the same) by using informal leadership & advanced communication skills. 

  • Actively manage and escalate risk and customer-impacting issues within the day-to-day role to management. 

  • Demonstrate excellent technical writing skills.

  • Mentor novices by providing learning tasks as well as work related tasks, direct the work of advanced beginners, and help them continue to grow.

  • Communicate effectively and promptly every day and lead cybersecurity discussions at Discover. Provide oversight on security programs impacting decisions. Guide team to achieve key results for the assigned security assessment tasks.

Minimum Qualifications

At a minimum, here is what we need from you: 

  • Bachelors – Computer Science, Information Security, Engineering

  • 4+ years – Information Security, Cybersecurity, Computer Science, Data Analytics or related 

  • In lieu of a degree 6+ years – Information Security, Cybersecurity, Computer Science, Data Analytics or related. 

  • Internal applicants only: technical proficiency rating of competent on the Dreyfus cybersecurity scale. 

Preferred Qualifications:

If we had our say, we would also look for: 

  • Cyber certifications such as CISSP, CISM and GIAC.

  • 4+ years of experience in cybersecurity controls assessment integrated with risk management steps.

  • Familiarity with Zero Trust architecture.

  • Risk Management framework and experience in Agile methodology.

  • 3rd party vendors cyber risk assessment.

  • Experience assessing security for cloud platforms (SaaS, PaaS, IaaS).

  • Experience in network / OS / database system security administration.

What are you waiting for? Apply today! 

And

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Discover

View company profile →