Job description
As the Vulnerability Management Analyst your day-to-day role will be:
- Responsible for reviewing the vulnerability data from multiple sources (i.e. external / internal penetration testing, internal / external vulnerability scanning, etc.) across multiple technologies and a changing environment including infrastructure and applications to determine risk rating of vulnerabilities to business assets.
- Assist in providing support and resolution for scanning and vulnerability remediation reporting issues.
- Assist in working with the Business to effectively communicate the risks of identified vulnerabilities and make recommendations regarding the selection of cost-effective security controls to mitigate identified risks.
- Stay current with vulnerability information across all the products in Pearson
- Assist in improving and automating existing vulnerability management lifecycle. Including but not limited, data ingestion & normalisation, compliance metrics and detections on assets.
- Drive prioritisation of those vulnerabilities through a risk-based approach, to meet common organisational objectives such as regulatory compliance and audit functions.
- Manage the triage of vulnerabilities, ensuring mitigation measures are implemented, and managing the life cycle of vulnerability management for a set of assets, providing tailored advice on ways to improve control mechanisms and mitigate risks.
- Recommend remediation strategies and provide advice on complex configuration changes in support of vulnerability remediation.
- Proactively identify and leverage threat intelligence sources to inform strategic vulnerability mitigation measures.
- Demonstrate developed knowledge and understanding of approaches and tooling for performing vulnerability assessment against large and complex infrastructure.
- Translate vulnerability management standards and best practice into organisation policies, procedures and guidelines and champion standards and best practice outside security functions.
- Develop vulnerability assessment templates and test scripts to meet common organisational objectives such as regulatory compliance and internal audit functions.
- Disseminate the implications of test findings and explain the potential business impact if vulnerabilities are exploited.
- Co-ordinate engagement with internal and external stakeholders to manage and provide appropriate Cyber Security assurance to the required standard and in accordance with policy and regulations.
- Incident Response: Collaborate with incident response teams to investigate and respond to security incidents related to vulnerabilities, assisting with the identification, containment, eradication, and recovery processes.
Essential Skills and Experience for the Vulnerability Manager: You should be able to demonstrate essential skills and experience of:
- Demonstrable hands-on experience with Qualys or Similar Vulnerability platforms
- Management and configuration of vulnerability management tools in multi cloud environments.
- Good understanding of the cyber threat landscape and understanding of threat hunting in a cloud-based environment.
- Ability to articulate the risk presented to services from existing or emerging vulnerabilities and threats.
- Excellent written and verbal communication skills including the ability to relate technical information to a non-technical audience.
- Working with a larger team to deliver a risk-based response with a forward-thinking approach.
What to expect from Pearson
Did you know Pearson is one of the 10 most innovative education companies of 2022?
At Pearson, we add life to a lifetime of learning so everyone can realize the life they imagine. We do this by creating vibrant and enriching learning experiences designed for real-life impact. We are on a journey to be 100 percent digital to meet the changing needs of the global population by developing a new strategy with ambitious targets. To deliver on our strategic vision, we have five business divisions that are the foundation for the long-term growth of the company: Assessment & Qualifications, Virtual Learning, English Language Learning, Workforce Skills and Higher Education. Alongside these, we have our corporate divisions: Digital & Technology, Finance, Global Corporate Marketing & Communications, Human Resources, Legal, Strategy and Direct to Consumer. Learn more at We are Pearson.
We value the power of an inclusive culture and also a strong sense of belonging. We promote a culture where differences are embraced, opportunities are accessible, consideration and respect are the norm and all individuals are supported in reaching their full potential. Through our talent, we believe that diversity, equity and inclusion make us a more innovative and vibrant place to work. People are at the center, and we are committed to building a workplace where talent can learn, grow and thrive.
Pearson is an Affirmative Action and Equal Opportunity Employer and a member of E-Verify. We want a team that represents a variety of backgrounds, perspectives and skills. The more inclusive we are, the better our work will be. All employment decisions are based on qualifications, merit and business need. All qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We strive for a workforce that reflects the diversity of our communities.
To learn more about Pearson’s commitment to a diverse and inclusive workforce, navigate to: Diversity, Equity & Inclusion at Pearson.
If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing [email protected].
Note that the information you provide will stay confidential and will be stored securely. It will not be seen by those involved in making decisions as part of the recruitment process.
Job: TECHNOLOGY
Organization: Corporate Strategy & Technology
Schedule: FULL\_TIME
Req ID: 12022