Lansing, MI, 48915, USA
16 hours ago
REMOTE - Principal Vulnerability Analyst
**General information** **Ref #** 19019 **Remote?** Yes **Ally and Your Career** * Ally Financial only succeeds when its people do - and that’s more than some cliché people put on job postings. We live this stuff! We see our people as, well, people - with interests, families, friends, dreams, and causes that are all important to them. Our focus is on the health and safety of our teammates as well as work-life balance and diversity and inclusion. From generous benefits to a variety of employee resource groups, we strive to build paths that encourage employees to stretch themselves professionally. We want to help you grow, develop, and learn new things. You’re constantly evolving, so shouldn’t your opportunities be, too? **The Opportunity** This role can be worked from Ally Charlotte, Ally Detroit, or remote within the United States. At Ally, you get a startup feel, but experience the benefits of a company that’s worked out the kinks and is fulfilling its purpose. We’re always evolving and see that as a good thing. From owning our work to seeing its impact in the real world, our team is relentless in finding new ways technology can help make experiences better and help people. We are problem solvers, we value diverse thinking, we support one another, and we challenge ourselves to think bigger in the journey to deliver customer-obsessed tech solutions. To read more about what our tech team does, be sure to visit our tech blog at ally.tech We are looking for a self-driven Vulnerability Analyst to help remediate security vulnerabilities on technology infrastructure and applications as well as deliver technical enhancements to the Vulnerability Management Program. Primary responsibilities include providing subject matter expertise for the resolution of vulnerabilities, identifying and implementing tactical and strategic solutions to enhance vulnerability management processes and expedite remediation, evaluating vulnerability technical risk and developing risk treatment requests, and being a leader and mentor on the team. The ideal candidate in this role must be able to bridge the gap between technology professionals who patch computers and risk management practices by using their knowledge of system administration to troubleshoot sticking points in patching processes. The candidate is self-motivated to soundly reduce vulnerability risk through persistent analysis, research, and investigation. To ensure success, the candidate should have advanced knowledge of computer and internet security systems and the ability to automate processes, reporting, and governance activities. **The Work Itself** * Analyze vulnerabilities and connect with technology teams to put in place action plans for their resolution, seeking opportunities that will best reduce the most risk for the lowest cost in terms of effort and time * Be a responsive and helpful engagement point for technology teams attempting to resolve their vulnerabilities * Follow escalation procedures when vulnerability remediation expectations are not met to include evaluating technical risk and developing risk treatment requests * Be able to work independently and when problems arise that require management engagement, be able to recommend solutions * Ability to interact with company personnel at all levels and across all business units to comprehend business imperatives. A strong customer/client focus, with the ability to manage expectations appropriately, to provide a superior customer/client experience and build long-term relationships * Develop solutions that improve the effectiveness or efficiency of vulnerability identification and reporting * Lead small projects to deliver vulnerability management process efficiencies * Ability to guide and mentor junior team members **The Skills You Bring** Required: * Proven work experience with vulnerability scanners such as Qualys or Tenable * 5+ years of foundational technical experience in system administration / operating system experience, networking or security. Candidates do NOT need to have experience in every platform, OS, or enterprise business application, but should have well-rounded technology knowledge. * Clear understanding of enterprise-class application, network, and infrastructure security architecture * Basic scripting abilities to better process data or to help automate patching jobs in languages such as Python, JavaScript, or PowerShell * Solid understanding of a variety of common server, middleware, OR desktop class applications such as java JDKs, Adobe products, and Apache products * Solid understanding of cloud and container technologies, platforms, and environments * Passionate analytical skills with the ability to manage multiple demands under challenging timelines * Strong writing skills to produce detailed reports for consumption by stakeholders at all levels from operations to executive Preferred: * Security+, CISSP, or similar security certifications * System administration certifications such as RHCSA or MCSE * Bachelor’s degree in Information Technology or Computer Science * The ability to adapt to new situations, natural curiosity, and the desire to learn and stay current with security trends, threats, and risks * Experience with enterprise vulnerability and CMDB workflow systems such as ServiceNow \#LI-Remote **How We'll Have Your Back** * Ally's compensation program offers market-competitive base pay and pay-for-performance incentives (bonuses) based on achieving personal and company goals. But Ally’s total compensation - or total rewards - extends beyond your paycheck and is designed to support and enrich your personal and professional life, including: * Time Away: competitive holiday and flexible paid-time-off, including time off for volunteering and voting. * Planning for the Future: plan for the near and long term with an industry-leading 401K retirement savings plan with matching and company contributions, student loan and 529 educational assistance programs, tuition reimbursement, and other financial well-being programs. * Supporting your Health & Well-being: flexible health and insurance options including dental and vision, pre-tax Health Savings Account with employer contributions and a total well-being program that helps you and your family stay on track physically, socially, emotionally, and financially. * Building a Family: adoption, surrogacy, and fertility support as well as parental and caregiver leave, back-up child and adult/elder day care program and childcare discounts. * Work-Life Integration: other benefits including LifeMatters® Employee Assistance Program, subsidized and discounted Weight Watchers® program and other employee discount programs. Who We Are: Ally Financial is a customer-centric, leading digital financial services company with passionate customer service and innovative financial solutions. We are relentlessly focused on "Doing it Right" and being a trusted financial-services provider to our consumer, commercial, and corporate customers. For more information, visit www.ally.com. Ally is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to age, race, color, sex, religion, national origin, disability, sexual orientation, gender identity or expression, pregnancy status, marital status, military or veteran status, genetic disposition or any other reason protected by law. Where permitted by applicable law, must have received or be willing to receive the COVID-19 vaccine by date of hire to be considered, if not currently employed by Ally. We are committed to working with and providing reasonable accommodation to applicants with physical or mental disabilities. For accommodation requests, email us at work@ally.com. Ally will not discriminate against any qualified individual who is capable of performing the essential functions of the job with or without reasonable accommodation. **_Base Pay Range:_** An individual's position in the range is determined by the scope and responsibilities of the role, work experience, education, certification(s), training, and additional qualifications. We review internal pay, the competitive market, and business environment prior to extending an offer. **Emerging:** 110000 **Experienced:** 145000 **Expert:** 180000 Incentive Compensation: This position is eligible to participate in our annual incentive plan
Confirm your E-mail: Send Email