Hiring.Camp

Vulnerability Management Analyst

Chevron

·

Today

Location
Makati City Chevron 6750 Office, Philippines
Type
Full-time
Department
Management
Experience
3+ years
Education
Bachelor
Closing date
Today
Source
Workday

Description

Total Number of Openings

15

The Vulnerability Management Analyst will drive change within vulnerability management. Lead in defining processes and tool recommendations needed to identify vulnerabilities, tests Chevron’s digital security defenses, analyzes malicious code, and leverages all authorized resources and analytic techniques to secure Chevron's environment. Support the Information Risk Strategy Management (IRSM) Vulnerability Management (VM) program reporting to the Vulnerability Management Team Lead.

For Data Engineer – Machine Learning - Cyber

Job Description Summary

We are seeking a highly skilled Cyber Data Engineer to join our team. The ideal candidate will be responsible for designing, developing, and maintaining data pipelines and architectures to support our cybersecurity initiatives. This role requires a deep understanding of data engineering, cybersecurity principles, and the ability to work in a fast-paced, collaborative environment.

The Cyber Data Engineer is a critical member of the Cyber Data team, responsible for establishing and leveraging defensive measures and information collected from various sources to identify, analyze, and report events that occur or might occur within company assets. This role focuses on ensuring the ongoing stability of our SIEM platform, tuning and optimizing data sources, and deploying new applications, configurations, and integrations with Cybersecurity operations teams.

 

Job Description

The Cyber Data Engineer plays a crucial role in our cybersecurity defense strategy by leveraging data to identify and mitigate threats. This position requires a strong understanding of business processes and the ability to translate technical requirements into business solutions. The successful candidate will work closely with cross-functional teams to ensure that our data infrastructure supports our overall business objectives.

Key responsibilities include designing, developing, and maintaining scalable data pipelines and architectures, implementing data security measures to protect sensitive information, utilizing big data technologies such as Hadoop, Spark, and Kafka, developing and maintaining ETL processes, working with data scientists and analysts to provide data solutions, and ensuring data quality and integrity.

 

Required Education / Degrees

  • Bachelor's degree in Computer Science, Information Technology, or a related field.

  • Relevant certifications in data engineering or cybersecurity are a plus.

  • Bachelor’s degree or master’s degree in Information Technology, Computer Science, Engineering, Cybersecurity or related STEM field or direct related work experience. 

Preferred qualifications / certifications  

  • Certified Information Systems Security Professional (CISSP).

  • Splunk Enterprise Certified Admin / Architect.

  • Cribl Certified Admin.

  • Microsoft Azure Administrator Certification (AZ-104)

  • Experience with cloud platforms such as AWS, Azure, or Google Cloud.

  • Experience with User Behavior Analytics (UBA) or Risk-Based Analytics (RBA).

  • Domain knowledge with data warehousing concepts e.g. Data Modeling and ETL Process, Data Pipeline, Data Quality.

  • SOC, Threat intelligence or vulnerability management experience.

Required work experience  

  • 3+ years of experience in data engineering, SIEM technologies or a related field.

  • Experience with cybersecurity data analysis and threat detection.

  • Experience with Linux Administration.

  • Proficiency in scripting or programming languages such as Python, Bash Scripting, PowerShell or Ansible.

Other preferred skills / competencies  

  • Experience with Machine Learning Models and AI for Cyber Security Operations (preferred) 

  • Experience with Syslog or rSyslog Administration.

  • CI/CD Pipeline experience to help automate and script infrastructure provisioning.

  • Familiarity with the NIST framework and cybersecurity-related capabilities and tools.

  • Strong problem-solving and analytical skills.

  • Excellent communication and teamwork abilities.

  • Knowledge of data governance and compliance standards.

  • Ability to work independently and manage multiple tasks simultaneously.

For Vulnerability Management Analyst

Responsibilities include, but are not limited to, the following:

  • Manage the vulnerability remediation process to ensure weaknesses identified through vulnerability scanning and assessments / penetration tests along with any emergency concerns are assigned to owners and tracked to resolution.

  • Responsible for analyzing information/data collected from vulnerability assessments and scans; and in conjunction with the IRSM risk managers, helps recommend mitigations in the form of policies, standards, and controls as they apply to the major risk domains. This person will also support project initiatives to assess vulnerability of Chevron’s IT assets.

  • Support project initiatives to assess vulnerabilities in Chevron’s IT assets and perform validation testing of remediated vulnerabilities from business vulnerability assessments, as needed.

  • Foundational knowledge in cybersecurity and apply that knowledge toward remediation initiatives.

  • Foundational skills in cybersecurity toolsets including infrastructure and application scanning, phishing campaigns, cloud access security broker, and other cross functional security tools.

  • Engage technical resources and leaders across the enterprise to share results and gain commitment.

Technical

  • Demonstrated ability in vulnerability management or related field such as penetration testing, SOC, or threat intelligence.

  • Understanding of attacker mindset, exploitation, and how vulnerabilities are leveraged. 

  • Knowledge of Cybersecurity principles and various information security technologies (i.e., IDS/IPS, HIPS, DLP, firewalls, network engineering, database, etc.).

  • In-depth experience with cybersecurity concepts, vulnerability scanning tools, and other security techniques such as active/passive reconnaissance, vulnerability identification, exploitation, phishing, social engineering, and command and control techniques.

  • Broad understanding in one of the following information technology areas used to support and manage the business (i.e., web, networking, database, cloud, telephony, mobile, applications, etc.).

Domain Knowledge

  • Must understand IT systems (Operating Systems, databases, and applications).

  • Experience in one of the following areas: a system administrator, application developer, programmer familiarity with MS Windows or UNIX/Linux operating systems.

  • Strong desire to learn new tools and technologies highly motivated to apply that knowledge toward understanding and communicating the sources of vulnerabilities.

Communication

  • Candidates should demonstrate strong verbal, written and presentation skills, as well as an ability to communicate technical information to different audiences (management, non-technical, IT Professionals, PCN Professionals). Able to engage and interview stakeholders requesting vulnerability management services to capture key information needed to effectively understand, clearly articulate, and document remediation plans.

Chevron participates in E-Verify in certain locations as required by law.

Skills

PythonAWSAzureAnsibleCI/CDLinuxMachine LearningSparkHadoopData EngineeringETLCybersecurityPenetration TestingSIEMSOCSplunkComplianceCISSP

Similar Jobs

23

Vulnerability Management Analyst

LON3 London - 51 Lime Street · Taguig, National Capital, Philippines

2 months ago

Vulnerability Management Analyst

Hapag-Lloyd · Chennai, India · Hybrid

8 months ago

Vulnerability Management Analyst

Decisionpointcorp · , US · Remote

1+ year ago

Senior Vulnerability Management Analyst

Income Insurance Limited · Singapore, SG

4 days ago

Senior Analyst, Vulnerability Management and Vulnerability Operations (VulnOps)

Edwards · India-Pune

5 days ago

GRC, Vulnerability Management Analyst

Acrisure · 1170 Peachtree St Ste 1200 - ATLANTA, GA, United States of America +1

1 week ago

Information Security Analyst, Vulnerability Management

bet365 · Manchester, England, United Kingdom · Hybrid

1 week ago

Information Security Analyst, Vulnerability Management

bet365 · Stoke-on-Trent, England, United Kingdom · Hybrid

1 week ago

Cyber Security Analyst & Vulnerability Management Engineer

Loenbro · Westminster, CO

1 week ago

Information Security Analyst (Vulnerability Management)

Jda · BYDS Dallas, United States of America · Remote, Hybrid, Onsite

1 week ago

Vulnerability Management I Analyst II

Vertiv · Mandaluyong City, Philippines

2 weeks ago

DFC - Vulnerability Management Analyst

cFocus Software Incorporated · Washington, DC · Remote

4 weeks ago

Senior Cybersecurity Analyst – Vulnerability Management

Digital Realty Global · LONDON, United Kingdom, GB · Onsite

1 month ago

Threat Intelligence & Vulnerability Management Analyst

Duplo · Lagos, Lagos, Nigeria

1 month ago

Threat and Vulnerability Management Analyst

Centrica · UK - Windsor - Millstream, United Kingdom +1 · Hybrid

2 months ago

Senior Vulnerability Management Analyst

Advisorgroup · Scottsdale, AZ, United States of America · Hybrid

2 months ago

Vulnerability and Cybersecurity Operations Management Analyst

Lam Research · Bengaluru, KA,IN, IN

3 months ago

Vulnerability Management Analyst & Automation specialist

Euroclear · Poland, PL

3 months ago

Mustang: Senior Analyst Vulnerability Management

Continental · Bengaluru, KA, India

9 months ago

Mustang: Senior Analyst Vulnerability Management

Continental · Bengaluru, KA, India

10 months ago

Cloud Vulnerability Management Analyst

Rockwell Automation · Mexico Mexico City (remote) +3 · Hybrid

1+ year ago

Cloud Vulnerability Management Analyst

Rockwellautomation · Mexico Mexico City (remote) +3 · Hybrid

1+ year ago

Security Vulnerability Management Analyst

Qmulos · Washington, DC, United States

1+ year ago