
Threat and Vulnerability Management Analyst
1 day ago
Apex enables modern investing and wealth management tools through an ecosystem offrictionless platforms, APIs, and services.
Threat and Vulnerability Management AnalystApex Fintech Solutions (AFS) powers innovation and the future of digital wealth management by processing millions of transactions daily, to simplify, automate, and facilitate access to financial markets for all. Our robust suite of fintech solutions enables us to support clients such as Stash, Betterment, SoFi, and Webull, and more than 20 million of our clients' customers.
Collectively, AFS creates an environment in which companies with the biggest ideas in fintech are empowered to change the world. As a global organization, we have offices in Austin, Dallas, Chicago, New York, Portland, Belfast, and Manila.
If you are seeking a fast-paced and entrepreneurial environment where you'll have the opportunity to make an immediate impact, and you have the guts to change everything, this is the place for you.
AFS has received a number of prestigious industry awards, including:
2021, 2020, 2019, and 2018 Best Wealth Management Company - presented by Fintech Breakthrough Awards
2021 Most Innovative Companies - presented by Fast Company
2021 Best API & Best Trading Technology - presented by Global Fintech Awards
ABOUT THIS ROLE
Apex Fintech Solutions (AFS) is seeking a Threat and Vulnerability Management (TVM) Analystwho will serve as a member of our Security Operations Team. The TVM Analyst will play a crucial role in protecting the organization by identifying, assessing, reporting on, and helping to manage and remediate security vulnerabilities across the diverse technology landscape. The analyst will work with other teams on plans to prioritize and mitigate vulnerabilities that pose a risk to the organization, helping to reduce the attack surface and enhance the overall security posture. The role will also work closely with the Security Operation Center and provide support when required on day-to-day security threat monitoring, alerting triage, analysis, and response.
Duties/Responsibilities
Perform regular vulnerability scanning, analysis and reporting across infrastructure, applications and cloud environments using available tooling.
Analyze vulnerability data, threat intelligence, and contextual information to accurately assess, prioritize and validate findings.
Collaborate with IT, systems, networks, engineering and business system owners to track, support and verify timely remediation of identified vulnerabilities according to SLAs.
Responsible for the creation, documentation, assigning, updating and follow-ups on vulnerability tickets.
Assist in the development, documentation, and maintenance of the vulnerability management program, including policies, procedures and standards.
Stay up to date with the latest cyber threats, attack vectors, vulnerability disclosures, and exploitation techniques.
Investigate, document, and report on threats and emerging trends.
Analyze and respond to undisclosed, zero-day, & discovered software and hardware vulnerabilities.
Create clear and actionable vulnerability reports and metrics for various stakeholders, including management and technical teams.
Help provide risk assessments relating to vulnerability findings.
Contribute to the continuous improvement of the TVM program by identifying opportunities for process enhancement, automation and new tooling.
Work within the Security Operation Center (SOC) team to provide support when required, investigating alerts and triaging.
Provide Incident Response (IR) support when analysis confirms an actionable incident.
Education and/or Experience
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent work experience) required
2+ years of professional experience in vulnerability management, information security or similar field.
Proven experience with vulnerability scanning and management platforms.
Required Skills/Abilities
Excellent analytical and problem-solving skills with the ability to assess and prioritize vulnerabilities based on risk, impact and exploitability.
Excellent communication skills, both written and verbal, with the ability to articulate technical vulnerabilities and remediation steps to diverse audiences, both technical and non-technical.
Strong understanding of network protocols (TCP/IP, DNS, HTTP, FTP, SSH, SSL/TLS), operating systems, web application security and cloud security vulnerabilities.
Knowledge of common vulnerability scoring systems, CVSS, EPSS.
Knowledge of technical security solutions (such as but not limited to firewalls, SIEM, NIDS/NIPS/HIDS/HIPS, EDR, DLP, SOAR, proxies, network behavioural analytics, orchestration, automation and cloud security).
Knowledge of network, infrastructure, cloud and application system technologies and practices
Ability to communicate effectively by contributing significantly to the development and delivery of a variety of written and visual documents for diverse audiences.
Ability to change and demonstrate adaptability by adjusting priorities or processes and approaching as needs dictate.
Ability to work independently as a team representative of Information Security as well as showing excellent teamwork skills.
Ability to develop thorough documentation and reports on threats and vulnerabilities.
Ability to work independently with minimal supervision and as a proactive member of a team in a fast-paced, evolving environment.
Desire for continual learning of new technologies and developing knowledge / skills.
This job operates in a hybrid, office environment 2 days per week.
#IT #associate #full-time #LI-AP1 #APEX
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
Our Rewards
We offer a robust package of employee perks and benefits, including a market-leading salary with an annual bonus, 20 days of vacation leave plus regular and special non-working holidays, and a training and development budget. Our benefits also cover private health insurance for medical and dental, as well as life insurance. We emphasize work-life balance with flexible working hours, parental leave, a modern city center office, and a hybrid work schedule that allows for greater flexibility by partially working from home. Additional perks include monthly team lunch-outs, unlimited drinks and snacks, and company recognition & rewards.
EEO Statement
Apex Fintech Solutions is an equal opportunity employer that does not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, and gender identity), national origin, age, disability, veteran status, marital status, or any other protected characteristic. Our hiring practices ensure that all qualified applicants receive fair consideration without regard to these characteristics.
Disability Statement
Apex Fintech Solutions is committed to creating an inclusive and accessible workplace for all candidates, including those with disabilities. We are dedicated to ensuring equal employment opportunities and providing reasonable accommodations to qualified individuals with disabilities. If you require reasonable accommodations to participate in the application or interview process, please submit your request via the Candidate Accommodation Requests Form . We will work with you to provide the necessary accommodations to ensure your full participation in our hiring process.
Sign up to receive emails when Apex Fintech Solutions posts open positions you might be interested in:
If you click to sign-up above; you will be added to the Apex Fintech Solutions talent network. Your information will not be shared or sold.
#J-18808-Ljbffr-
Manila, National Capital Region, Philippines beBeeSecurity Full time $90,000 - $120,000Job Title:Threat and Vulnerability Management SpecialistJob Description:We are seeking a skilled Threat and Vulnerability Management Specialist to join our Security Operations Team. The ideal candidate will be responsible for identifying, assessing, and helping to manage security vulnerabilities across our diverse technology landscape.The selected individual...
-
Manila, National Capital Region, Philippines Melco Resorts & Entertainment Full timePosition SummaryREQ12937 Analyst, Threat Intelligence, Information Security (Open)The Analyst, Threat Intelligence, Information Security is responsible in identifying, analyzing, and disseminating actionable threat intelligence. This role involves monitoring various sources for potential threats, conducting in-depth analysis, and providing insights to...
-
Manila, National Capital Region, Philippines SM Investments Full timeCybersecurity Vulnerability Management / VAPT ManagerPosition Overview: We are seeking a highly motivated and detail-oriented Cyber Security Vulnerability Specialist to join our team. You will be responsible for conducting various security activities, including feasibility studies, automation initiatives, vulnerability assessments (VA), threat monitoring,...
-
Manila, National Capital Region, Philippines beBeeThreatIntelligence Full time $50,000 - $80,000Job OverviewThe Threat Intelligence Analyst is responsible for identifying, analyzing, and disseminating actionable threat intelligence. This role involves monitoring various sources for potential threats, conducting in-depth analysis, and providing insights to support the organization's cybersecurity efforts.This position requires a strong understanding of...
-
Security Analyst
4 days ago
Manila, National Capital Region, Philippines Verifone Full timeJob SummaryThe Security Analyst will be responsible for monitoring our security infrastructure, identifying and responding to security threats, managing vulnerabilities, and contributing to the continuous improvement of our overall security posture. This role is crucial in safeguarding our organization's systems, data, and reputation against an ever-evolving...
-
Cyber Security Vulnerability Management Specialist
24 hours ago
Manila, National Capital Region, Philippines beBeeVulnerabilityManagement Full time ₱800,000 - ₱1,200,000Job Description:The Cyber Security team is responsible for protecting the bank against all manner of cyber threats. Effective Vulnerability Management is essential to the success of this mission. As a Vulnerability Management Specialist, you will be responsible for detecting, assessing and contextualizing various security vulnerabilities and configuration...
-
Cyber Threat Research Specialist
2 days ago
Manila, National Capital Region, Philippines beBeeCyberthreat Full time ₱50,000 - ₱100,000Job TitleCyber Threat Research SpecialistAbout the RoleWe are seeking a highly skilled Cyber Threat Research Specialist to join our team. As a key member of our threat intelligence team, you will be responsible for researching and analyzing emerging cyber threats, producing concise analyst notes, and communicating findings to both technical and non-technical...
-
Protect Threats Specialist
2 days ago
Manila, National Capital Region, Philippines beBeeCybersecurity Full time ₱1,200,000 - ₱2,400,000Threat Management SpecialistGCash is seeking a Threat Management Specialist to join our team.OverviewThis role requires developing a complete understanding of the company's technology and information systems. The ideal candidate will identify and communicate current and emerging cybersecurity and fraud threats and risks relevant to...
-
Threat Intelligence Research Expert
2 days ago
Manila, National Capital Region, Philippines beBeeCybersecurity Full time ₱150,000Seeking a highly skilled Threat Intelligence Researcher to join our exceptional team of threat researchers and data scientists.About the Role:As a key member of our team, you will be responsible for conducting in-depth research on emerging threats, vulnerabilities, and cyberattacks. You will analyze data from various sources to identify trends and patterns...
-
Senior Vulnerability Researcher
5 days ago
Manila, National Capital Region, Philippines beBeeSecurity Full time $100,000 - $120,000Job OpportunityWe are seeking a seasoned Web & API Security Engineer to identify and exploit vulnerabilities in modern web applications and APIs.Conduct thorough security testing of production-grade web apps and APIs (REST, GraphQL, gRPC)Identify advanced vulnerabilities beyond standard CVEsSimulate adversarial behavior and design attack paths that mimic...