Hardening Compliance Analyst

Role description

The Hardening Compliance Analyst will work with the team to help approve the process to measure hardening compliance across various US-based entities. This person will support the team to understand hardening compliance gaps by setting up the initial configurations of the compliance measurement tool, creating new compliance measurement profiles and setting up the reports templates needed. The ideal person is very comfortable assisting the Security teams in consolidating the way/tool used to measure hardening compliance.

Job Duties:

  • Assess hardening compliance gaps identified by the hardening compliance scans and evaluate, rate and perform risk assessments on assets by creating new report templates.
  • Prioritize remediation of gaps discovered along with remediation timeline(s) and work with associated teams to explain gaps and remediation steps as required.
  • Create reports and provide analysis on gaps for technical teams and leadership.
  • Collaborate with upper management and technical teams to help create strategy and technical design to configure and install Policy Compliance Qualys module.
  • Provide crucial insights into the most pressing issues and suggest how to prioritize security resources while monitoring for and detecting security events utilizing Qualys.
  • Evaluate, rate and perform risk assessments on assets in addition to reviewing alerts escalated by end users and perform initial triage of incoming issues.
  • Document, investigate and notify appropriate contact for security events and response while participating in the resolution of events, even after they are escalated.
  • Monitor health alerts and downstream dependencies in addition to providing limited response to end users for low complexity security events and reviewing false positive with the various Security teams to tune and provide feedback to improve accuracy of the alerts.


Required Qualifications & Experience:

  • Bachelor’s Degree is required
  • Bilingual in both English/Spanish (strong written & verbal skills) is a must
  • 2-3+ years’ experience of vulnerability management/hardening compliance is required
  • 2+ years’ experience using Vulnerability Management & analysis tools (Qualys and Compliance module and/or Nessus)
  • General network knowledge, TCP/IP, Internet Routing, UNIX / LINUX & Windows OS
  • Strong understanding of vulnerability scanning and reporting


Pluses (not required but preferred experience) include:

  • Previous experience as a Systems Admin hardening Windows/Linux systems


Latest jobs

The Cervantes Group

Sr. Business Systems Analyst: GRC Implementation

February 27th, 2025
Remote
Full-time

The Sr. GRC Business Systems Analyst will be working within the Operational Risk Management area to implement new GRC solutions to support use cases. This person will actively contribute to determining an overall GRC solution strategy, as well as use case definition, requirements gathering, system design, configuration, data migrations, integrations, testing, release readiness, and documentation. Track and report operational risks identified according to industry standards, regulations and frameworks.


Job Duties:

  • Collaborate with upper management to determine overall GRC solution strategy and guide decisioning on system design, configuration, etc., while leading meetings with clearly stated objectives that drive desired outcomes
  • Participate in several activities to improve Operational Risk Management program, such as use case definition, requirements gathering, system design, configuration, data migrations, integrations, testing, release readiness, and documentation.
  • Work with stakeholders on the creation of business processes and deployment of technology to align strategic objectives and regulatory compliance while effectively managing operational risks.
  • Identify areas for implementations, create GRC strategic roadmaps to present to stakeholders, select GRC solutions, and carry out GRC implementation. 
  • Assess current Governance of operational areas and identify most critical areas of risk in organization and where the enterprise client is most impacted by regulatory requirements.
  • Define objectives and scope of GRC implementation roadmap, including risk management strategies centered around compliance driven activities according to industry regulations.
  • Help to establish KPIs and ensure smooth integration of GRC practices within business and operational processes.
  • Analyze workflow automation capabilities of GRC software, integration options, and cost analysis.
  • Monitor and identify improvement areas defining metrics and KPIs for measuring performance.


Education & Requirements:

  • Bachelor’s Degree required
  • 5+ years’ experience with enterprise-scale Governance, Risk, and Compliance (GRC) solution implementations for financial institutions
  • 5+ years’ experience use case definition, requirements gathering, system design, configuration, data migrations, integrations, testing, release readiness, and documentation
  • Previous experience integrating SAP GRC is a required
  • Must have experience with Microsoft Power Apps, SharePoint, Snowflake,
  • Must have proven success advising and guiding decisioning on system design, configuration, etc.



Plus:

  • Bilingual in Spanish/English (verbal, written) is desired 


The Cervantes Group

Software Engineer: Core Banking

February 27th, 2025
Remote
Full-time

**REMOTE from Mexico**


As the SW Engineer, you will be responsible for reviewing, analyzing, and evaluating business systems incidents in efforts to provide ad-hoc support within the production areas of various core banking platforms and applications within the global client. Due to the international nature of this client, this person will be coordinating, collaborating and communicating daily with teams throughout Mexico and Spain regarding technology solutions within application, software, database, and operating system environments. The ideal person can participate in the full SW development life cycle from technical design preparation, development, maintenance and production support serving as the on-site technical point of contact and cultural liaison for assigned functional and technical areas.

 

Responsibilities:

  • Participate in the software development lifecycle to design, code, configure, test, debug, and document corporate and core banking system and application programs.
  • Lead internal escalations communicating with Engineering and business units/teams while ensuring technical incidents are identified, tracked, reported and resolved in timely manner.
  • Prepare technical design specifications based on functional requirements and analysis documents and review functional requirements, analysis and design documents.
  • Conduct technical evaluation and analysis of various software issues, ranging from basic login trouble to complex software behaviors, redirecting and escalating requests when necessary.
  • Assess urgency of incident and communicate with various cross-functional business units and IT staff to verify bandwidth of problem resolution teams located in Spain, Boston, Mexico.
  • Prepare requirements, specifications, business processes and recommendations.
  • Develop existing process diagrams and communicates needed changes to development team across various global regions in addition to participating in sessions of prototyping new systems for the purpose of enhancing business process operations and information process flows.
  • Design technical solutions to resolve technical issues at hand and automate job tasks/schedules.
  • Participate in the testing process through test review and analysis, test witnessing and certification of software to ensure QA standards.


Requirements:

  • Bachelor’s Degree is required
  • Bilingual (read, write, speak, etc.) in English and Spanish is required
  • Flexibility with an understanding that production support is not always normal hours
  • Advanced experience with databases (Oracle, SQL Server) and complex tables
  • Minimum of 3 years of experience in SW development, back end development and database structures/architectures
  • Strong experience and knowledge of SQL queries
  • Previous experience supporting and/or developing applications with Java, Python, and/or C#
  • Prior experience working with ServiceNow


Plus:

  • Previous experience in the banking/financial industries is a plus


The Cervantes Group

Sr. Software Engineer: Core Banking

February 27th, 2025
Remote
Full-time

**REMOTE from Mexico**



As the Sr. SW Engineer, you will be responsible for leading various phases of the software development lifecycle and working with stakeholders to create release schedules and architectural designs for applications, platforms and programs. Lead the technical incident and production support efforts working directly with SW Engineering teams to provide ad-hoc support within the production areas of various core banking platforms and applications within the global client. This person will be producing technical specification documents (DDR) and communicating daily with teams located internationally. The ideal person for this role is able to adapt to cross functional and cross-cultural environments.

 

Responsibilities:

  • Lead in the software development lifecycle to design, code, configure, test, debug, and document corporate and core banking system and application programs.
  • Work with executives and stakeholders to create release schedules and architectural designs for applications, platforms and programs while managing technical incident life cycles ensuring technical incidents are identified, tracked, reported and resolved in timely manner.
  • Prepare technical design specifications based on functional requirements and analysis documents and review functional requirements, analysis and design documents.
  • Conduct technical evaluation and analysis of various software issues, ranging from basic login trouble to complex software behaviors, redirecting and escalating requests when necessary.
  • Assess urgency of incident and communicate with various cross-functional business units and IT staff to verify bandwidth of problem resolution teams located in Spain, Boston, Mexico.
  • Prepare requirements, specifications, business processes and recommendations.
  • Develop existing process diagrams and communicates needed changes to development team across various global regions in addition to participating in sessions of prototyping new systems for the purpose of enhancing business process operations and information process flows.
  • Design technical solutions to resolve technical issues at hand and automate job tasks/schedules.
  • Participate in the testing process through test review and analysis, test witnessing and certification of software to ensure QA standards.


Requirements:

  • Bachelor’s Degree is required
  • Bilingual (read, write, speak, etc.) in English and Spanish is a must
  • Advanced experience with databases (Oracle, SQL Server) and complex tables
  • Minimum of 5 years of experience in SW development, back end development and database structures/architectures
  • Previous experience in technical and architecture design preparation and producing technical specification documents (DDR)
  • Must have prior experience participating in creating and executing release schedules
  • Strong experience and knowledge of SQL queries
  • Previous experience supporting and/or developing applications with Java, Python, and/or C#
  • Prior experience working with ServiceNow


Plus:

  • Previous experience in the banking/financial industries is a plus


The Cervantes Group

Network Security Engineer, Cisco ISE

February 26th, 2025
Remote
Full-time

This person will be reconfiguring and installing Cisco switches in efforts toward implementing a new Cisco ISE infrastructure to optimize network access management throughout the organization. Conduct testing to ensure that switches are working as expected during and after the changes while working with the design engineers on tasks to accomplish the project goals. Analyze virtual and physical network IT infrastructures (IPS, network access controls, and security infrastructure). The ideal person can prepare technical procedures, standards & network schematics interfacing with stakeholders and technical audiences in an international environment.