Analyst, IT Security Threat Vulnerability
Overall Job Summary
Analyst, IT Security Threat & Vulnerability | PCI | Ethical Hacker (Hybrid - 2 Days Onsite)
Tractor Supply Company benefits include: Bonus, Flexible PTO, Fertility, 401k, ESPP, Relocation & more
This position supports Tractor Supply Company’s (TSC) Threat and Vulnerability Management program. This includes analyzing threats and vulnerabilities within TSC’s network, developing threat intelligence and metrics, supporting incident response, advancing the data loss prevention (DLP) program, and assisting in developing and maintaining the identity and access management (IAM) program.
Essential Duties and Responsibilities (Min 5%)
- Review, investigate, and document security events identified by the Security Operations Center.
- Perform continuous monitoring and development of operational functions and tools to support Information Security.
- Participate in on-call rotation.
- Work with other Information Technology (IT) teams in order to identify and create action plans for vulnerabilities.
- Develop and distribute regular reporting on current threats and threat intelligence.
- Coordinate testing and execution of incident response plan with TSC.
- Compile recurring security metrics for Executive Management review.
Qualifications
High Demand IT Specialized Skills
- Experience with the following security standards, controls, and frameworks:
- Payment Card Industry (PCI)
- Sarbanes Oxley Act (SOX)
- National Institute of Standards and Technology (NIST)
- Control Objectives for Information and Related Technologies (COBIT)
- Information Technology Infrastructure Library (ITIL) is preferred.
- Experience with a Security Operations Center is preferred.
- Experience with Vulnerability Management preferred.
Preferred knowledge, skills or abilities
- General knowledge of firewalls, intrusion detection systems, anti-virus software, vulnerability systems, and other industry standard techniques and practices is required.
- General knowledge of network, PC, and platform operating systems, including Microsoft and Linus is required.
- Ability to work with a Security Information and Event Management (SIEM), as well as working knowledge of QRadar.
- Ability to create key performance indicators (KPIs), dashboards, metrics, and reporting.
- General knowledge of incident response.
- Proficiency in Microsoft Office is required.
Disclaimer
This job description represents an overview of the responsibilities for the above referenced position. It is not intended to represent a comprehensive list of responsibilities. A team member should perform all duties as assigned by his/ her supervisor.
Nearest Major Market: Nashville