Supervisor, Vulnerability Management and Application Security

Supervisor, Vulnerability Management and Application Security

Vollzeit 121200 - 199200 € / Jahr (geschätzt) Homeoffice (teilweise)
P

Auf einen Blick

  • Aufgaben: Leite das Informationssicherheitsteams zur Bewertung von Risiken und Bedrohungen.
  • Unternehmen: PSEG Long Island, eines der größten Energieunternehmen in den USA.
  • Vorteile: Attraktives Gehalt, umfassende Gesundheitsleistungen und flexible Arbeitsoptionen.
  • Weitere Informationen: Dynamisches Arbeitsumfeld mit hervorragenden Karrieremöglichkeiten.
  • Warum dieser Job: Gestalte die Zukunft der Cybersicherheit und schütze unsere Gemeinschaften.
  • Qualifikationen: Erfahrung in Cybersecurity, Schwachstellenmanagement und Teamführung erforderlich.

Das prognostizierte Gehalt liegt zwischen 121200 - 199200 € pro Jahr.

  • PSEG Company : PSEG Long Island
  • Work Location Category : Hybrid Flexible

We're one of the country's largest energy companies, with a vision of powering a future where people use energy more efficiently and it's safer and delivered more reliably than ever.

We're also deeply connected to the communities we serve, with more than 13,000 employees working together to support our customers and make a difference every day.

Here, you'll have the stability and exciting opportunities that come with being a Fortune 500 company — along with a supportive, friendly work environment where your contributions are valued.

We know life isn't one-size-fits-all, and neither is work.

That's why we offer flexible work options depending on the role.

In support of this model, roles have been categorized into one of three work location categories:

  • Onsite - roles where employees are expected to be onsite daily.
  • Hybrid fixed - roles that are a mix of remote work and onsite work fixed days each week.
  • Hybrid flexible - roles that are a mix of remote work and onsite work, but the onsite requirements have greater flexibility. (i. e. 5-8 days a month vs. set days each week).

As an employee, if you are regularly scheduled to work 20 or more hours per week, you will have access to a wide range of comprehensive benefits designed to support your total well-being:

  • medical
  • dental
  • vision
  • paternal leave and family leave programs
  • behavioral health programs
  • 401(k) with company match
  • life insurance
  • tuition reimbursement
  • generous paid time off

More than 13,000 people already call PSEG their work home, taking pride in providing safe, reliable service to millions of customers.

If you're looking for a place where you can build a meaningful career and help power and support our communities, we'd love to welcome you to the team.

PSEG is not offering visa sponsorship for this position.

Job Summary

This position leads Information Security staff in the evaluation of risks and threats, development, implementation, communication, operation, monitoring and maintenance of the IT security policies and procedures to promote secure and uninterrupted operation of all IT systems, applications and infrastructure.

In this role, you will be responsible for proactively identifying, prioritizing, and tracking security vulnerabilities across the PSEG's network and systems.

You will also be responsible for conducting security assessments, running penetration tests, review Cyber threat intelligence and providing relevant data to parties to action upon.

This role will perform red team exercises mimicking adversary practices while leveraging similar tools and techniques.

To be successful in this role you must have a broad understanding of information security and experience in application security, Dev Sec Ops (Development, Security, and Operations) vulnerability management, and cyber exploitation techniques in an evolving artificial intelligence driven world.

You must also possess excellent problem-solving and communication skills and proven people management experience.

  • Job Responsibilities
  • Cyber Assessment & Vulnerability Management lead is responsible for the overall lifecycle of the Cyber Assessment & Vulnerability Management program.
  • Inform, advise, and partner with IT, Security, and other business units to help better secure their operations.

Identify gaps in current processes, workflows, and design and recommend changes or enhancements as needed.

  • Participate in Change Management Process, from early Assessment of proposed changes/enhancements, through Vulnerability scanning and recommended remediation before go-live.
  • Participate in incident response activities as needed.

Ensure cross-company processes around threat & vulnerability management are adhered to.

This includes tracking SLAs, discovery, and handling of any finding.

Maintain situational awareness, identification, tracking, and ensuring action on industry news related to software vulnerabilities, including zero-day vulnerabilities and emergency patching.

  • Implement and operationalize advanced Vulnerability Management reporting tools.

Design, develop and operationalize Vulnerability Management metrics.

Design and Implement advanced Vulnerability dashboards.

Evaluate performance, perform career development, coaching and counseling and manage compensation for Cyber assessment staff.

  • Responsible for conducting security assessments & penetration tests.

Review Cyber threat intelligence and ensures and provide relevant data to parties within the Cyber Assessment & Vulnerability management teams to action upon.

Oversee regular red team exercises to proactively emulate attackers TTP and report back findings so security engineering and operations can improve their defenses.

  • Create, perform tabletop exercises exercising mimicking adversary practices testing PSEG LI's ability to respond to cyber incidents.
  • Job Specific Qualifications
  • Bachelor's degree and 8 years of relevant cyber security experience
  • Candidates without a degree, will need 12 years of cyber experience
  • Experience within vulnerability/compliance management, penetration testing, and/or threat hunting
  • Ability to present to all levels of management and executive leadership
  • Excellent teamwork, facilitation, relationship building, and negotiation skills
  • Able to maintain positive working relationships both leading and as part of a team
  • Effective time management skills and able to multi-task effectively
  • Able to communicate effectively with both technical and non-technical individuals
  • Compliance with the Department of Energy's regulation 10 CFR 810 is required
  • Desired
  • Certified Information Systems Security Professional (CISSP), or equivalent

Some positions at PSEG require access to information covered by the Department of Energy's regulation 10 CFR 810 (Part 810).

If applicable, the successful applicant must prove they are: (1) a citizen or national of the USA; OR (2) a lawful permanent resident of the United States (Non-Conditional Permanent I-551 / Green Card / Permanent Resident Card holder); OR (3) a citizen, national, or permanent resident of a \"Generally Authorized\" destination on the attached list and not also a citizen, national, permanent resident of any country not listed; OR (4) a \"Protected Individual\" under the Immigration and Naturalization Act (8 U.

As an employee of PSEG Long Island, you should be aware that during storm/outage restoration efforts, you may be required to perform functions different from normal operations and work extended hours beyond your regular work schedule.

You may also be required to work on premise or in an alternate location as directed by the company.

For all roles, PSEGLI's drug and alcohol testing program includes pre-employment testing, testing for cause, and post-incident/accident testing.

Employees who are hired or transfer into a federally regulated role (including positions covered by USDOT, PHMSA, or NRC regulations) are subject to random drug and alcohol testing, inclusive of marijuana.

Although numerous states throughout the country have legalized marijuana/cannabis products recreationally and medically, the use of these products are prohibited for employees in federally regulated roles.

Please note that the use of CBD products may result in a positive drug test for THC/Marijuana and such use is not a legitimate medical explanation for a positive result.

If you are a current PSEG employee and offered an opportunity with PSEG Long Island, you will be treated as a new hire.

Please note that as a new hire to the Long Island subsidiary, your benefits will change and generally will be consistent with other similarly situated PSEG Long Island new hires.

Similarly, for PSEG Long Island employees who accept job opportunities with PSEG or any of its subsidiaries (other than PSEG Long Island), their benefits will change and generally be consistent with other similarly situated new hires of that company.

PSEGLI is an equal opportunity employer, dedicated to a policy of non-discrimination in employment, based on any legally protected characteristic.

Legally protected characteristics include race, color, religion, national origin, sex, age, marital status, sexual orientation, disability or veteran status or any other characteristic protected by federal, state, or local law in locations where PSEG employs individuals.

PSEGLI is committed to providing reasonable accommodations to individuals with disabilities.

If you have a disability and need assistance applying for a position, please call 973-430-3845 or email accommodations@pseg. com.

If you need to request a reasonable accommodation to perform the essential functions of the job, email accommodations@pseg. com.

Any information provided regarding a disability will be kept strictly confidential and will not be shared with anyone involved in making a hiring decision.

ADDITIONAL EEO INFORMATION (Click link below) Know your Rights: Workplace Discrimination is Illegal

#J-18808-Ljbffr

Supervisor, Vulnerability Management and Application Security Arbeitgeber: PSEG

PSEG Long Island ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern nicht nur Stabilität und Sicherheit bietet, sondern auch ein unterstützendes und freundliches Arbeitsumfeld, in dem ihre Beiträge geschätzt werden. Mit flexiblen Arbeitsoptionen und einem umfassenden Leistungspaket, das medizinische Versorgung, Altersvorsorge und Weiterbildung umfasst, fördert PSEG die persönliche und berufliche Entwicklung seiner Mitarbeiter. Hier haben Sie die Möglichkeit, eine sinnvolle Karriere aufzubauen und aktiv zur Verbesserung der Gemeinschaft beizutragen.

P

Kontaktdaten:

PSEG Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Supervisor, Vulnerability Management and Application Security erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie PSEG kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von PSEG zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei PSEG.

Wir glauben, dass du diese Fähigkeiten brauchst, um Supervisor, Vulnerability Management and Application Security mit Bravour zu bestehen

Cybersecurity
Vulnerability Management
Penetration Testing
Threat Hunting
Information Security
DevSecOps
Problem-Solving Skills

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei PSEG vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei PSEG könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. PSEG sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird PSEG auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!