refresh

热门公司

Trending

招聘

JobsRegeneron

Attack Surface & Vulnerability Analyst

Regeneron

Attack Surface & Vulnerability Analyst

Regeneron

SLEEPY HOLLOW

·

On-site

·

Full-time

·

1w ago

Compensation

$80,300 - $131,100

Benefits & Perks

Healthcare

Dental

Vision

Life Insurance

Disability Insurance

Gym

401(k)

Equity

Parental Leave

Paid Time Off

Healthcare

Gym

401k

Equity

Parental Leave

Required Skills

Vulnerability assessment

Threat modeling

Cloud security

Security compliance

Problem-solving

Attention to detail

Attack Surface & Vulnerability Management (ASVM) Analysts support Regeneron's ASVM capability to identify, assign, and validate remediation of compute environment vulnerabilities and misconfigurations. This encompasses Regeneron’s on-prem, hybrid, and multi-tenant cloud environments. This position supports and enables Regeneron’s, global (US (United States), EU (European Union), APAC) Science to Medicine business objectives through enriching the cybersecurity defense posture.
ASVM Analysts focus on cybersecurity attack surface management, vulnerability identification, security control and visibility gap coverage, facilitate priority-based patching, validate remediation effectiveness, and support the tooling enabling the discovery mechanisms. Operational requirements include leveraging ASVM and information technology service management (ITSM) platforms to provide visibility, quantification, and accountability for remediation efficacy. This includes the utilization of reporting, executive summaries, and real-time dashboards.

As an Analyst, a typical day may include:

  • Manage cybersecurity vulnerabilities and risks across Regeneron including identifying and supporting application and system owners to manage risks and remediate vulnerabilities.
  • Conduct vulnerability and security compliance assessments of scans of servers, websites, workstations, serverless technology, network devices, cloud infrastructure, and other assets using various vulnerability management platforms and tools.
  • Create/edit/analyze enterprise cybersecurity policies and configurations to evaluate compliance with regulations and enterprise policies and standards.
  • Collection, reporting, and metrics generation for multiple cyber ASVM datasets. This includes patching efficiency, identifying system misconfigurations, and security hygiene assessments.
  • Support the process of Security Compliance assessments of systems and multi-tenant cloud services, leveraging industry best practices, to include, Center for Internet Security (CIS) hardening guidelines
  • Analysis and monitoring of cybersecurity feeds, cyber threat intelligence, and open-source intelligence on trending vulnerabilities and exploits.
  • Partner with IT service providers to operate, maintain, and enhance ASVM platforms. This includes native Operating System, cloud security, and data aggregation platforms

To be considered for this role, you must meet the following:

  • Knowledge, proven ability, and skills in defense-in-depth security control coverage and vulnerability assessment, prioritization, assignment, validation, and tracking.
  • ASVM/ASM focused Cybersecurity tool familiarity E.g., CAASM (Cyber Asset Attack Surface Management), EASM (External Attack Surface Management), RBVM (Risk Based Vulnerability Management), CNAPP (Cloud Native Application Protection Platform), EDR (Endpoint Detection and Response), etc.
  • Familiarity with CIS Security Controls, MITRE ATT&CK Framework
  • Working knowledge of multi-tenant cloud environments (AWS, Azure, GCP), vulnerability mitigation techniques, and system hardening.

Collaboration

  • Collaborate and partner with cross-departmental peers (technical and non-technical) to report, synthesize, and prioritize vulnerabilities and threats based on contextual assets and relationship data.

Innovation

  • Leverage industry and compute environment data to assess current and alternative technical solutions and processes for continuous enhancement and issue resolution.

Skills/Tools

  • Proven threat and vulnerability assessment skills or knowledge gained through experience or academia.
  • Ability to understand threat modeling and apply technical, administrative, and security control risk mitigation.
  • Organized, reliable, detail oriented.
  • Proven or conceptual abilities to navigate levels through thought equity.

Preferred:

  • Experience and working knowledge of multi-faceted attack surface management and aggregation tools used by ASVM to include Wiz, Censys, Safe Breach, Axonius, Seemplicity
  • Experience gained through a complex organization and managed security providers and vendors.
  • Excellent problem-solving skills and attention to detail.
  • Proven experience in customer service, communication, and relationship building.
  • Ability to work independently and as part of a team.

Does this sound like you? Apply now to take your first step towards living the Regeneron Way! We have an inclusive culture that provides comprehensive benefits, which vary by location. In the U.S., benefits may include health and wellness programs (including medical, dental, vision, life, and disability insurance), fitness centers, 401(k) company match, family support benefits, equity awards, annual bonuses, paid time off, and paid leaves (e.g., military and parental leave) for eligible employees at all levels! For additional information about Regeneron benefits in the US, please visit https://careers.regeneron.com/en/working-at-regeneron/total-rewards/. For other countries’ specific benefits, please speak to your recruiter.Please be advised that at Regeneron, we believe we are most successful and work best when we are together. For that reason, many of Regeneron’s roles are required to be performed on-site. Please speak with your recruiter and hiring manager for more information about Regeneron’s on-site policy and expectations for your role and your location.

Regeneron is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion or belief (or lack thereof), sex, nationality, national or ethnic origin, civil status, age, citizenship status, membership of the Traveler community, sexual orientation, disability, genetic information, familial status, marital or registered civil partnership status, pregnancy or parental status, gender identity, gender reassignment, military or veteran status, or any other protected characteristic in accordance with applicable laws and regulations. The Company will also provide reasonable accommodation to the known disabilities or chronic illnesses of an otherwise qualified applicant for employment, unless the accommodation would impose undue hardship on the operation of the Company's business.

For roles in which the hired candidate will be working in the U.S., the salary ranges provided are shown in accordance with U.S. law and apply to U.S.-based positions. For roles which will be based in Japan and/or Canada, the salary ranges are shown in accordance with the applicable local law and currency. If you are outside the U.S, Japan or Canada, please speak with your recruiter about salaries and benefits in your location.

Please note that certain background checks will form part of the recruitment process. Background checks will be conducted in accordance with the law of the country where the position is based, including the type of background checks conducted. The purpose of carrying out such checks is for Regeneron to verify certain information regarding a candidate prior to the commencement of employment such as identity, right to work, educational qualifications etc.

Salary Range (annually)

$80,300.00 - $131,100.00

Total Views

0

Apply Clicks

0

Mock Applicants

0

Scraps

0

About Regeneron

Regeneron

Regeneron

Public

Focused on neurotrophic factors and their regenerative capabilities, giving rise to its present name; the company has since expanded operations int...

10,001+

Employees

Westchester County

Headquarters

Reviews

3.2

5 reviews

Work Life Balance

2.0

Compensation

4.3

Culture

2.5

Career

3.5

Management

2.0

Pros

Good pay and benefits

Company events and perks

Great coworkers

Cons

Toxic management

Poor work-life balance

Micromanagement and lack of autonomy

Salary Ranges

1,037 data points

Junior/L3

Junior/L3 · Data Analyst

0 reports

$108,540

total / year

Base

-

Stock

-

Bonus

-

$92,259

$124,821

Interview Experience

5 interviews

Difficulty

2.2

/ 5

Duration

14-28 weeks

Offer Rate

60%

Experience

Positive 80%

Neutral 20%

Negative 0%

Interview Process

1

Application Review

2

Phone/Video Screen

3

Hiring Manager Interview

4

Panel Interview

5

Stakeholder Interview

6

Offer

Common Questions

Technical Knowledge

Behavioral/STAR

Past Experience

Presentation Skills

Culture Fit