Job Description
Planning, implementing, managing, monitoring, and upgrading security measures for the protection of DRC data, systems, and networks
· Responding to all system and/or network security breaches
· Design and maintain enterprise SCCM/MECM patching strategies for Windows endpoints and supported server environments.
· Create and manage SCCM device collections, deployment groups, maintenance windows, software update groups, and deployment schedules.
· Coordinate vulnerability information from Qualys with SCCM patching data to identify vulnerable systems requiring remediation.
· Perform vulnerability-first remediation by identifying affected assets and determining the appropriate patch, configuration change, software upgrade, or compensating control.
· Analyze patch compliance, deployment status, failed installations, pending reboots, missing updates, and non-reporting devices.
· Manage Software Update Points (SUP), WSUS synchronization, software update groups, deployment packages, and Automatic Deployment Rules (ADRs).
· Troubleshoot SCCM client installation, client health, policy retrieval, software update scanning, deployment evaluation, and content download failures.
· Develop procedures for emergency patch deployment when critical or actively exploited vulnerabilities require accelerated remediation.
· Package and deploy third-party application updates and security fixes where Microsoft updates do not provide remediation.
· Create and maintain SCCM operational runbooks, patching procedures, troubleshooting guides, deployment standards, and rollback procedures.
· Testing and identifying network and system vulnerabilities
· Evaluating the organization’s security needs and establishing best practices and standards accordingly
· Taking appropriate security measures to ensure that DRC’s infrastructure and existing data are kept safe
· Perform scheduled and ad-hoc vulnerability scans across networks, servers and endpoints.
· Work with server, endpoint, security, network, and application teams to resolve cross-platform remediation dependencies.
· Tune scans and reduce false positives to improve data accuracy
· Develop vulnerability metrics, dashboards, and executive-level reports
· Conducting testing and scans to identify any vulnerabilities in the network and system
Requirements
Skill | Required / Desired | Amount | of Experience |
Network Security and threat detection, incident response and vulnerability management
| Required
| 10
| Years
|
Hands-on experience administering Qualys, remediation documentation and patch management processes
| Required
| 10
| Years
|
Microsoft SCCM/MECM administration.
| Required
| 10
| Years
|
Experience with Vulnerability scan reports and remediation tracking, risk assessment and compliance documentation
| Highly desired
|
|
|
Requirements
Skill Required / Desired Amount of Experience Proven work experience with enterprise data governance Required 3 Years Proven work experience with the OneTrust platform (Data Mapping, Data Discovery, Data Catalog, Assessments) Required 2 Years Proven work experience creating documentation for internal and external audiences, technical and business audiences Required 3 Years Proven work experience supporting the creation and presentation of knowledge and training Required 3 Years