Manager, Vulnerability Management - Enterprise Security
Johns Creek, GA
Employer: | Macy's |
Category: | Legal |
Job Type: | Full Time |
Description | |
Bring Your Amazing Self to Work At Macy's, Inc. we're on a mission to create a brighter future with bold representation for all. This is our Mission Every One. We know that each person here is unique. So we respect and invest in each individual to create growth, pride, and satisfaction. If we are able to bring our whole selves to work, it translates into a more abundant and wider array of ideas and energy for all to benefit from. Our success will be built on amazing colleagues, working together. Job Overview The Manager, Vulnerability Management provides strategic direction and collaborates across enterprise teams to develop, coordinate, elevate, and streamline the vulnerability management program. They draw on extensive experience in vulnerability management and penetration testing to ensure the program's continuous improvement. This role oversees the enhancement of vulnerability platforms, works closely with security and business teams to create innovative risk mitigation strategies, and ensures compliance with established policies. The Manager also communicates key metrics to senior leaders and remediation teams across the enterprise. They possess expertise in a variety of security testing tools, including BurpSuite, HP WebInspect, Core Impact, Tenable, MetaSploit, and Qualys. Additionally, they are well-versed in penetration testing, vulnerability scanning, and red teaming methodologies. The Manager is capable of explaining vulnerabilities and weaknesses in the CISA KEV, OWASP Top 10, and CWE 25 to diverse audiences and discussing effective defensive techniques. What You Will Do
Regulatory Compliance: Strong knowledge of regulatory compliance requirements, including PCI-DSS, SOX, and GLBA. Security Infrastructure: Advanced knowledge in security infrastructure design and architecture for both new implementations and existing infrastructure. Enterprise Security: Experience in designing and implementing enterprise-wide security strategies, policies, and standards. Threat Protection: Experience protecting large enterprise environments from internal and external attacks. Vulnerability Management: Strong understanding of network, physical, application, and web security as it relates to vulnerability management. Advanced knowledge of common vulnerabilities, testing approaches, and remediation strategies. Security Technologies: Expert understanding of current and emerging security technologies, defense strategies, and industry standards. Ability to determine and recommend security-related products and activities, influencing decision-making processes. Interpersonal Skills: Advanced leadership, facilitation, and interpersonal skills to work across functional lines and at various levels. Communication: Excellent written and verbal communication skills, with the ability to read, write, and interpret instructional documents. Certifications: One or more certifications such as CISSP, CEH, Secure+, OCSP, GPEN, CISA, CISM, GWAPT, GXPN etc. preferred. Who You Are
Now is an exciting time for a Macy's career as we continue to focus on creating exciting and memorable experiences for every Macy's customer, whether their journey starts online or in the store. Our opportunities in Sales, Merchandise, Operations, Customer Service, Warehouse, Marketing, and other areas let you express your creativity and commitment to excellence, grow your career and make a difference to your Macy's colleagues and customers. Bring your creativity, energy, and ideas to the Macy's team - Apply Today! This job description is not all-inclusive. Macy's, Inc. reserves the right to amend this job description at any time. Macy's, Inc. is an Equal Opportunity Employer, committed to a diverse and inclusive work environment. TECH00 LEGALRE00 |