IT Security Analyst / Vulnerability Management EngineerRemote
Description:Diversified Systems is searching for an IT Security Analyst / Vulnerability Management Engineer responsible for planning, implementing, managing, monitoring, and upgrading security measures for the protection of data, systems, and networks. The consultant will support vulnerability management, patch management, SCCM/MECM administration, security operations, remediation efforts, and enterprise security initiatives.
Responsibilities: - Plan, implement, manage, monitor, and upgrade security measures for the protection of data, systems, and networks.
- Respond to all system and/or network security breaches.
- Design and maintain enterprise SCCM/MECM patching strategies for Windows endpoints and supported server environments.
- Create and manage SCCM device collections, deployment groups, maintenance windows, software update groups, and deployment schedules.
- Coordinate vulnerability information from Qualys with SCCM patching data to identify vulnerable systems requiring remediation.
- Perform vulnerability-first remediation by identifying affected assets and determining the appropriate patch, configuration change, software upgrade, or compensating control.
- Analyze patch compliance, deployment status, failed installations, pending reboots, missing updates, and non-reporting devices.
- Manage Software Update Points (SUP), WSUS synchronization, software update groups, deployment packages, and Automatic Deployment Rules (ADRs).
- Troubleshoot SCCM client installation, client health, policy retrieval, software update scanning, deployment evaluation, and content download failures.
- Develop procedures for emergency patch deployment when critical or actively exploited vulnerabilities require accelerated remediation.
- Package and deploy third-party application updates and security fixes where Microsoft updates do not provide remediation.
- Create and maintain SCCM operational runbooks, patching procedures, troubleshooting guides, deployment standards, and rollback procedures.
- Perform testing and identify network and system vulnerabilities.
- Evaluate the organization's security needs and establish best practices and standards accordingly.
- Take appropriate security measures to ensure that infrastructure and existing data are kept safe.
- Perform scheduled and ad-hoc vulnerability scans across networks, servers, and endpoints.
- Work with server, endpoint, security, network, and application teams to resolve cross-platform remediation dependencies.
- Tune scans and reduce false positives to improve data accuracy.
- Develop vulnerability metrics, dashboards, and executive-level reports.
- Conduct testing and scans to identify vulnerabilities in the network and system.
Requirements: - 10 years of experience in network security, threat detection, incident response, and vulnerability management required.
- 10 years of hands-on experience administering Qualys, remediation documentation, and patch management processes required.
- 10 years of Microsoft SCCM/MECM administration experience required.
- Experience with vulnerability scan reports and remediation tracking, risk assessment, and compliance documentation highly desired.