Job Description
Please note: This position does not offer work authorization sponsorship now or in the future. Applicants must have valid U.S. work authorization that does not require employer sponsorship.
Job Overview:
LPL Financial is in search of a Senior Vulnerability Management Engineer who can execute and mature the existing Vulnerability Management program at LPL and its subsidiaries. As a member of the Cyber Security organization, the Senior Vulnerability Management Engineer plays a key role in securing systems built and/or used by LPL Financial. A successful candidate can expect to manage Vulnerability Scanning tools and work closely with infrastructure, cloud, engineering, and application teams, as well as third party vendors to ensure that vulnerabilities are effectively managed throughout the environment.
Responsibilities:
Perform as a vulnerability management SME in one or more of the following areas: Microsoft platform (Server, workstation, applications), Open Systems platforms (Linux, UNIX, VM Ware ESX), virtualization platforms (e.g. Citrix), Networking, Databases (Oracle, SQL Server, DB2, IMS), and Cloud (AWS, Azure, Google).
Lead efforts to define/implement processes, policies, and procedures to govern vulnerability remediation efforts and track open vulnerabilities from identification to resolution, following up with remediation owners and escalating risk as necessary
Lead and drive large initiatives with enterprise level visibility to improve the Vulnerability Management program
Be able to successfully partner with other security and IT professionals to assess potential impact from vulnerabilities specific to LPL Financials environment, and determine and implement mitigating controls.
Identify and recommend appropriate measures to manage and remediate vulnerabilities and reduce potential impacts on information resources to a level acceptable to the senior management of the company.
Build strong partnerships with technical teams to promote best practices for managing vulnerabilities in an agile manner and within cloud solutions.
Be a champion for vulnerability management and information security including broadening awareness and use of the team’s services, education of security best practices and integration with other business areas.
Assist with the management and maintenance of vulnerability management platforms/tools, including troubleshooting and resolving technical/functional issues and ensuring successful platform operations
Review, implement, and maintain cloud security posture management policies to identify misconfigurations or vulnerabilities in cloud resources
Partner with Security Engineering to implement and manage Cloud Security Posture Management tools to perform automated security scanning/analysis of cloud resources, including containers and serverless functions
Understands vulnerability exploitation techniques and stays up to date on the latest vulnerabilities and exploits
Develop and improve KPIs, metrics, and trending for vulnerability management functions.
Participate and lead new projects as needed.
What are we looking for?
We want strong collaborators who can deliver a world-class client experience. We are looking for people who thrive in a fast-paced environment, are client-focused, team oriented, and are able to execute in a way that encourages creativity and continuous improvement.
Requirements:
5+ years of practical experience in information security field within a large enterprise environment
5+ years of vulnerability management experience working with vulnerability management tools (e.g. Qualys, InsightVM/Rapid7, Wiz, Nessus, etc.)
Preferences:
Bachelors and/or Master’s Degree or in Information Security, Engineering, Computer Science.
Familiar with industry standard security best practices and vulnerability management processes including identification, analysis, reporting, and remediation.
Advanced level of knowledge of the major Cloud platforms, the types of resources that can be deployed within each platform, common cloud misconfigurations/vulnerabilities and how to fix such issues
In depth understanding of types of vulnerabilities and techniques/compensating controls to mitigate associated risk
Experience managing and using Cloud Security Posture Management tools such as Wiz, XPanse, Prisma, Laceworks, Orca
Experience with reviewing, analyzing, managing, and remediating security vulnerabilities and misconfigurations in cloud resources
Experience at a financial services/technology company or in a regulated industry.
Ability to communicate with both technical and non-technical stakeholders at all levels of the organization.
Strong analytical, interpersonal and communication skills
Please note: This position does not offer work authorization sponsorship now or in the future. Applicants must have valid U.S. work authorization that does not require employer sponsorship.
#LI-Hybrid
Pay Range:
$100,631.00 - $167,787.00
Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play – such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer!