- 68 years of relevant experience in Cybersecurity / Information Security.
- Solid experience in enterprise Vulnerability Management.
- Experience managing vulnerability programmes across large and complex technology environments.
- Good understanding of infrastructure, network, application, endpoint and cloud vulnerabilities.
- Experience working with technology teams to drive remediation and risk reduction.
- Experience with security governance, reporting, audit and risk management.
- Insurance, banking, financial services or other highly regulated-industry experience would be preferred.
Preferred Technical Knowledge
- CVE / CVSS and vulnerability scoring
- OWASP Top 10 | CWE Top 25 | OWASP Mobile Top 10 | SANS Top 25
- Network and infrastructure security
- Web and API security
- Cloud security AWS/Azure/GCP
- Container and DevSecOps security
- Patch management
- Penetration testing
- Threat intelligence
- Security Information and Event Management (SIEM)
- Vulnerability Management tools – Tenable / Qualys / Rapid7/Microsoft Defender