Hardening Compliance Analyst

Role description

The Hardening Compliance Analyst will work with the team to help approve the process to measure hardening compliance across various US-based entities. This person will support the team to understand hardening compliance gaps by setting up the initial configurations of the compliance measurement tool, creating new compliance measurement profiles and setting up the reports templates needed. The ideal person is very comfortable assisting the Security teams in consolidating the way/tool used to measure hardening compliance.

Job Duties:

  • Assess hardening compliance gaps identified by the hardening compliance scans and evaluate, rate and perform risk assessments on assets by creating new report templates.
  • Prioritize remediation of gaps discovered along with remediation timeline(s) and work with associated teams to explain gaps and remediation steps as required.
  • Create reports and provide analysis on gaps for technical teams and leadership.
  • Collaborate with upper management and technical teams to help create strategy and technical design to configure and install Policy Compliance Qualys module.
  • Provide crucial insights into the most pressing issues and suggest how to prioritize security resources while monitoring for and detecting security events utilizing Qualys.
  • Evaluate, rate and perform risk assessments on assets in addition to reviewing alerts escalated by end users and perform initial triage of incoming issues.
  • Document, investigate and notify appropriate contact for security events and response while participating in the resolution of events, even after they are escalated.
  • Monitor health alerts and downstream dependencies in addition to providing limited response to end users for low complexity security events and reviewing false positive with the various Security teams to tune and provide feedback to improve accuracy of the alerts.


Required Qualifications & Experience:

  • Bachelor’s Degree is required
  • Bilingual in both English/Spanish (strong written & verbal skills) is a must
  • 2-3+ years’ experience of vulnerability management/hardening compliance is required
  • 2+ years’ experience using Vulnerability Management & analysis tools (Qualys and Compliance module and/or Nessus)
  • General network knowledge, TCP/IP, Internet Routing, UNIX / LINUX & Windows OS
  • Strong understanding of vulnerability scanning and reporting


Pluses (not required but preferred experience) include:

  • Previous experience as a Systems Admin hardening Windows/Linux systems


Latest jobs

The Cervantes Group

Data Quality Developer

January 17th, 2025
Onsite: Dallas, United States
Full-time

The Data Quality Developer will assist the Data Governance & Data Quality teams in the implementation and production of data quality rules. This person analyzes, and evaluates information technology systems operations to determine user needs and requirements and recommends ways to improve systems. Developer who comes from a development background and has experience meeting with users, business units and data modeling teams to craft and assemble technical designs for solutions to be implemented. This person will be interacting with both technical and non-technical audiences within an Informatica PowerCenter IDQ development environments while providing Production support and defining dataflows.  

The Cervantes Group

Data Remediation Analyst

January 17th, 2025
Remote
Full-time

The Data Remediation Analyst will be responsible for driving the data remediation efforts and identifying and correcting errors, inconsistencies, and inaccuracies in data. The ideal person has a strong background in data management, who is passionate about making a positive impact in the financial industry. Monitor and track progress of data remediation efforts, and provide regular updates to management while conducting risk assessments and implement risk mitigation strategies to ensure data integrity. Translate business problems into requirements, process changes, test cases, data mapping, etc., and serve as liaison between numerous cross-functional teams both technical and business units. 

C3 S.A. Inc

Business Intelligence Analyst

January 17th, 2025
San Juan
Full-time

Analyzes needs, designs, writes and tests new solutions, to fulfill business needs. This role will be an integral component of the organization's data governance, delivering valuable information through Intelligence and Analytics, providing direct support to the entire company. Applies judgment in devising program logic by selecting and adapting standard programming procedures, ultimately providing insights to help us make better decisions. 

The Cervantes Group

Hardening Compliance Analyst

January 17th, 2025
Remote
Full-time

The Hardening Compliance Analyst will work with the team to help approve the process to measure hardening compliance across various US-based entities. This person will support the team to understand hardening compliance gaps by setting up the initial configurations of the compliance measurement tool, creating new compliance measurement profiles and setting up the reports templates needed. The ideal person is very comfortable assisting the Security teams in consolidating the way/tool used to measure hardening compliance.