Description
###### **Required Experience**
###### **Vulnerability Management:** **Minimum of 3 to 5 years of experience leading triage, normalization, remediation, and prioritization of operational vulnerability backlogs.**
###### **Financial / Banking Sector:** **Proven experience working in regulated environments governed by CNBV regulations (especially regulatory indicator KRI0016\) and ISO 27001\.**
###### **Technical Risk Analysis:** **Experience filtering false positives, duplicates, and scanning tool collection errors from large-scale scans.**
###### **Collaboration and Testing:** **Experience coordinating with technical owners (infrastructure, networks, databases) and validating patch effectiveness in quality assurance (QA/SIT) environments.**
###### **IT Governance:** **Experience creating structured change controls, technical impact matrices, and contingency plans (Rollback).**
###### **Tools and Technical Knowledge**
###### **Key Tools**
###### **Tenable (Core):** **In-depth knowledge of interpreting Tenable reports (Vulnerability Management).**
###### **ServiceNow (Core):** **Proficiency in using the platform for creating change controls, assigning asset owners, and strictly tracking service-level agreements (SLA).**
###### **Penetration Test Reports:** **Ability to translate findings from manual penetration tests into actionable remediation plans.**
###### **Applied AI Tools:** **Desirable experience using AI assistants for automated data correlation and optimization of response times. (Must be open to learning them)**
###### **Theoretical Knowledge**
###### **Severity Metrics:** **Proficiency in CVSS and VPR scoring systems to correlate technical risk with actual business criticality.**
###### **Script and Playbook Development:** **Ability to review, validate, and propose suggested technical scripts or step-by-step remediation/mitigation guides.**
###### **Academic Background**
###### **Education:** **Bachelor’s degree or engineering degree in Cybersecurity, Computer Systems, Computer Science, Information Technology, or related IT fields.**
###### **Relevant Certifications**
###### **Desirable (Focus on CSA Role)**
###### **CompTIA CySA\+ (Cybersecurity Analyst):** **Perfectly aligns with the acronym and functions of vulnerability analysis, incident response, and compliance for this position.**
###### **Important: This is a hybrid role; you must attend the office two or three times per week.**
###### **Tenable Certified Vulnerability Management Specialist:** **Ensures technical mastery of the project’s primary ingestion tool.**
###### **Complementary Management and Cybersecurity Certifications**
**ITIL Foundation:** Fundamental to ensure the consultant understands the change management lifecycle operated in ServiceNow.
**CompTIA Security\+ or CEH (Certified Ethical Hacker):** To ensure a solid foundation in understanding how attack vectors and vulnerabilities identified in pentests operate.
**ISO 27001 Fundamentals:** To ensure internal alignment with the bank’s confidentiality policies.