Support threat intelligence solutions and prioritization of vulnerabilities for remediation.Develop capabilities through gap analysis, process enhancements, and automation tool integration across product lifecycleEvaluate and propose remediation strategies based on software tool analysis findingsEstablish effective collaboration with cross-functional teams throughout product developmentAssist in risk analysis, security gap assessment, and recommendation of cutting-edge solutionsFacilitate creation of comprehensive security process documentation for leadership and stakeholdersDeliver intelligence insights for security patch management of operating systems and third-party softwareCollaborate with development teams to craft solutions for existing security challengesLiaise with stakeholders regarding identified vulnerabilities and proposed remediation approachesAssist with incident response processes and PSIRT activities when addressing identified security eventsDeliver support for penetration testing activities and resulting reportsPartner closely with the Threat Intelligence Manager and support personnel to advance product security initiatives and deliverablesExecute / support annual risk assessments of market-deployed products; document and quantify findings, relay results to development teamsFacilitate annual penetration tests as assigned, develop or assess final reportsMaster SBOM generation using various tools and scripts; become an authority in utilizing and analyzing resultsAssess security updates for potential impacts on market-deployed products and track emerging vulnerabilitiesCompose and / or evaluate patching and update communications for customers and coordinate distributionReady software for SAST, DAST, and fuzzing evaluations; analyze and document results, formulate remediation strategiesDeploy image hardening protocols including implementation of DISA STIGsCompile product risk summaries for semi-annual stakeholder reportingEngage with external vendors, develop / modify / communicate host module requirements, and ensure vendor accountability for deliverablesBachelor's degree in Computer Science or related field; or 4 years of equivalent professional experience
Proficiency in Microsoft development environment scripting, particularly PowerShell
Knowledge of Windows OS services, processes, driver configurations, registry settings, and analysis methodologies
Understanding of Windows and Linux cybersecurity configurations
Experience with security tools including SAST, DAST, SBOM, network forensics tools, fuzzing, and standard penetration testing applications
Networking expertise
Familiarity with Microsoft Visual Studio, ADO, or comparable integrated development environments (IDEs) Capacity to follow instructions, identify challenges, recommend solutions, and deliver high-quality results on schedule
Understanding of Software Development Lifecycle Management (SDLC) methodologies (Agile / Scrum, iterative)
Strong interpersonal and communication abilities to cultivate positive relationships across departments in virtual, remote, and asynchronous work environments