Role & responsibilities
DevSecOps,DAST, SAST, Vulnerability Management, OWASP
Job title
Sr Security Analyst
About the Role
(Role purpose / objective)
The Opportunity
Are you looking for a patient-focused company that will inspire you and support your career? If so, be empowered to take charge of your future at Takeda.
we are creating a future-ready organization, one that evolves at the speed of science and technology using data and digital to meet the needs of patients, our people, and the planet.
OBJECTIVES/PURPOSE
As a Sr. Security Analyst, you'll be the escalation point for threat management in which junior analysts do not have skills to handle appropriately. You will perform program functions within a high-performance dynamic environment and required to adjust priorities of work based on changing operational needs and the evolving threat horizon.
How you will contribute:
(Key accountabilities and responsibilities)
Responsibilities
Apply documented methodology to deliver consistent vulnerability management services to minimize business impact
Provide subject matter expertise for the delivery of threat management, technology controls, & incident response
Develop and maintain information security standards, processes, and guidelines
Lead collection and management of information security operations metrics and measures
Produce high quality outcomes and timely service delivery
Mentor less senior information security and risk resources (e.g., Junior Analysts)
Perform administration, testing, and remediation (including RCA) of security controls
Collaborate with business teams to effectively predict, protect, and respond to security threats
Conduct research and evaluation of new security technologies, processes, and methodologies
Skills and Qualifications
Essential
Bachelors degree in computer science, information systems, engineering or the equivalent combination of formal education, training, and experience
Strong analytical skills and understanding of vulnerability detection methods
Industry certifications from SANS, ISC2, ISACA or equivalent
3+ years of work experience directly supporting information security operations
Experience working on a team to effectively respond to large scale / complex requests
Strong analytical abilities, interpersonal skills, and verbal / written communication
In-depth knowledge of system operations, networking, and devices
Quickly adapts to changing events, reprioritizing efforts, and realign resources as needed
Willingness to be on-call, work non-standard hours, and travel (up to 15%) when required
Comfortable working in high stress and ambiguous environments
Fluent in the English language
Desired
Masters degree
Programming experience in any of the following: PostgreSQL, Python, Power BI, VB Script, or Power Shell
Experience using global industry leading security solutions, platforms, and technologies
Experience building out and maintaining cloud-based vulnerability management solutions
Experience working independently to manage and effectively respond to security requests
Experience developing and maintaining operations playbooks, run books, and performance measures
Good knowledge of industry standards regarding vulnerability management, including Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS) and Open Web Application Security Project (OWASP)
Good knowledge of information security leading practices and techniques
Good knowledge of networking protocols and log formats
Effective time, prioritization, and workload management skills
Experience working in validated environments (21 CFR Part 11)
Experience working within a global or multi-tiered organization
Preferred candidate profile
Perks and benefits
Keyskills: Sast Dast Burp Suite Penetration Testing Vulnerability Assessment