Garmin

Cyber Security Vulnerability Analyst 2

Garmin$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's in Computer Science or related field and 1 year of relevant experience, or equivalent combination.
  • Strong analytical skills with composure under pressure.
  • Familiarity with CVSS framework and National Vulnerability Database (NVD).
  • Excellent multitasking ability for managing cross-team activities.
  • Demonstrated effective communication skills in a team setting.
  • Positive team-oriented attitude with collaborative work mindset.
  • Knowledge of defensive security techniques and mitigation controls.

Responsibilities

  • Configure and perform vulnerability scanning and assessments independently.
  • Review and configure automated tools; analyze threats and disclosures to identify vulnerabilities.
  • Collaborate with stakeholders to create and implement remediation plans and timelines.
  • Analyze results of vulnerability scans and prioritize remediation efforts based on risk.
  • Establish scan schedules to ensure accurate results without service interruptions.
  • Build strong relationships to expedite prioritization and remediation of vulnerabilities.
  • Communicate findings and recommendations effectively within the team and across departments.

Benefits

  • Eligibility for Garmin's comprehensive benefits program.
  • Opportunity for professional development and skill enhancement.
  • Supportive work environment with a focus on teamwork and collaboration.
Full Job Description
Overview

We are seeking a full-time Cyber Security Vulnerability Analyst 2 at Garmin's U.S. headquarters in the Greater Kansas City area. In this role, you will be responsible for operating independently to configure and perform vulnerability scanning and assessments to support the identification, analysis, and remediation of risk to networks, operating systems, applications, and other information system components.

Essential Functions
  • Review/configure automated tools, analyze threat feeds, and monitor disclosure programs to identify/prioritize vulnerabilities
  • Work with stakeholders to help determine/implement remediation timelines/plans and is tasked to execute/align remediation plans based on experience and available data on Garmin risks
  • Operate independently to configure and perform vulnerability scanning and assessments to support the identification, analysis, and remediation of risk to networks, operating systems, applications, and other information system components
  • Responsible for reviewing/configuring automated tools, analyzing threat feeds, and monitoring disclosure programs to identify and prioritize vulnerabilities
  • Work with stakeholders to help determine and implement remediation timelines/plans
  • Independently analyze results from internal/external vulnerability scans and charged with using experience and skills to prioritize risk-based remediation plans
  • Coordinate/establish proper scan timelines to avoid service interruption, ensuring complete and accurate results are achieved
  • Establish strong relationships with business stakeholders to facilitate prioritization and timely remediation
  • Develop metrics/timelines in support of the monitoring of vulnerability management program health
  • Work with Cyber Security, System Administration, and System Owners to establish vulnerability mitigations and plans of action
  • Independently build performance metrics that provide advanced and detailed views of remediation performance
  • Ensure that external vulnerability disclosures are assigned to the proper teams and facilitates communications with vulnerability reporters and finders
  • Analyze compliance requirements and develop scanning plans and procedures to test and report on results
  • Coordinate efforts with compliance teams to develop vulnerability and scanning processes in support of governance/compliance requirements
  • Perform system administration activities on vulnerability management systems and applications
  • Communicate in written and verbal form effectively in a large team or departmental setting
  • Authorized to formulate remediation plans and timelines following vulnerability scans using input from system owners
  • Establish/create vulnerability documentation mitigations and remediations
  • Develop, create, and provide reports of vulnerability scan results that are in a consumable/consistent format
  • Help establish/track compliance with vulnerability management policies, standards, and procedures
  • Demonstrate proficient use and knowledge of standards and procedures
  • Understand vulnerability tool configurations and be able to provide guidance or remediation

Basic Qualifications
  • Bachelor's Degree in Computer Science, Information Technology, Management Information Systems, Business, or related field AND a minimum of 1 year relevant experience OR equivalent combination of education and relevant experience
  • Possess analytical skills and strong ability to maintain composure and remain diplomatic under highly stressful situations
  • Familiarity with Common Vulnerability Scoring System CVSS framework, National Vulnerability Database (NVD)
  • Strong multitasking skills to be able to effectively manage multiple activities, including cross-team dependent activities simultaneously
  • Consistently demonstrates quality/effectiveness in work documentation and organization
  • Demonstrated ability/effectiveness to exercise strong and effective verbal, written, and interpersonal communication skills in a small team setting
  • Must be team-oriented, possess a positive attitude and work well with others
  • Familiarity with defensive security techniques and implementation of mitigating security controls

Desired Qualifications
  • Working experience with automated vulnerability scanning tools, to include implementation, configuration, maintenance
  • Information security related experience, in areas such as: security operations, incident analysis, incident handling, system patching, and end point protection
  • Experience with vulnerability scanning in cloud-based environments, to include security posture management
  • Ability to work in a fast paced, dynamic environment
  • Experience with NIST 800-53 and/or NIST Cyber Security Framework (CSF)
  • Familiarity information and event management (SIEM) Platforms
  • Experience with BI tools for data analytic reporting and KPIs
  • System administration experience: Windows and Linux/Unix Scripting OR development experience (Python, JavaScript, PowerShell, C#, Perl)


This position is eligible for Garmin's benefit program. Details can be found here: Garmin Benefits

About Garmin

Garmin Ltd. is an American multinational technology company founded in 1989 by Gary Burrell and Min Kao in Lenexa, Kansas. The company specializes in GPS technology for automotive, aviation, marine, outdoor, and sport activities. Garmin's products serve aviation, marine, automotive, wireless, outdoor recreation, and fitness markets. The company's goal is to create navigation and communication devices that can enrich customers' lives. Garmin has offices in the United States, Europe, and Asia. The company's products are sold in over 100 countries.
Learn more about Garmin
Size
18,700 employees
Market Cap
$17.5 billion
Industry
Net Income
$992.3 million
Founded
1989
5 Year Trend
+10.3%
Revenue
$4.1 billion
NASDAQ

Similar Jobs

More Jobs at Garmin

More Information Technology Jobs

Find similar Cyber Security Vulnerability Analyst 2 jobs: