Discover Financial Services - Deerfield, IL

posted 3 months ago

Full-time - Mid Level
Remote - Deerfield, IL
Credit Intermediation and Related Activities

About the position

At Discover, be part of a culture where diversity, teamwork, and collaboration reign. Join a company that is just as employee-focused as it is on its customers and is consistently awarded for both. We're all about people, and our employees are why Discover is a great place to work. Be the reason we help millions of consumers build a brighter financial future and achieve yours along the way with a rewarding career. As a Vulnerability Analyst, you will play a critical role in enhancing the security posture of our organization. Your primary responsibility will be to write comprehensive cybersecurity risk assessments that identify threats and vulnerabilities, while also recommending effective remediation strategies. You will conduct formal, systematic threat modeling of IT systems using the STRIDE methodology, ensuring that our cybersecurity measures are robust and effective. In this position, you will apply your deep knowledge of procedure-based controls within a cybersecurity program, which includes qualitative risk analysis steps, vulnerability and patch management, threat modeling, and Identity and Access Management (IAM). Familiarity with cybersecurity frameworks such as NIST CSF, PCI-DSS, and CIS will be essential. You will also practice expert-level assessment skills using technology-based controls, including cloud security, Artificial Intelligence/GenAI risks, penetration testing results, cryptography, network security fundamentals, malware defense, data loss prevention, and endpoint security. Your role will involve compiling professional security assessment reports and leading discussions to effectively communicate risks and remediation options to partners. You will demonstrate sound knowledge of Incident Management Respond and Recover functions from a cyber resiliency perspective, ensuring that our organization is prepared to respond to incidents effectively. This position requires you to work independently to identify vulnerabilities in the deployment of technologies, assess their severity and impact, and recommend risk-based options for remediation. You will actively collaborate with business partners, application architects, and partner security teams to research and build security solutions that align with business goals. Additionally, you will be expected to learn advanced cybersecurity concepts, including new and modern threat exploitation techniques used by threat actors. As a Vulnerability Analyst, you will also be responsible for achieving team commitments and influencing others to do the same by utilizing informal leadership and advanced communication skills. You will actively manage and escalate risk and customer-impacting issues within your day-to-day role to management, demonstrating excellent technical writing skills. Furthermore, you will have the opportunity to mentor novices by providing learning tasks and guiding them in their professional growth, while also leading cybersecurity discussions at Discover and providing oversight on security programs that impact decision-making.

Responsibilities

  • Write comprehensive cybersecurity risk assessments identifying threats & vulnerabilities and recommend remediation.
  • Conduct formal, systematic threat modeling of IT systems using STRIDE methodology.
  • Apply deep knowledge of procedure-based controls of a cybersecurity program including qualitative risk analysis steps, vulnerability and patch management, threat modeling, Identity and Access Management (IAM), cybersecurity frameworks (NIST CSF, PCI-DSS and CIS).
  • Practice expert level assessment skills using technology-based controls of a cybersecurity program including cloud security, Artificial Intelligence / GenAI risks, penetration testing results, cryptography & network security fundamentals, malware defense, data loss prevention and endpoint security.
  • Compile professional security assessment reports, slides, and lead discussions to effectively communicate the risks and remediation options to partners.
  • Demonstrate sound knowledge of Incident Management Respond and Recover functions from a cyber resiliency perspective.
  • Work independently to identify vulnerabilities in deployment of technologies, severity, and impact, and recommend risk-based options for remediation.
  • Actively collaborate with business partners, application architects and partner security teams to research and build security solutions aligned to business goals.
  • Learn advanced cybersecurity concepts including new and modern threat exploitation techniques of threat actors.
  • Achieve team commitments (and influence others to do the same) by using informal leadership & advanced communication skills.
  • Actively manage and escalate risk and customer-impacting issues within the day-to-day role to management.
  • Demonstrate excellent technical writing skills.
  • Mentor novices by providing learning tasks as well as work related tasks, direct the work of advanced beginners, and help them continue to grow.
  • Communicate effectively and promptly every day and lead cybersecurity discussions at Discover. Provide oversight on security programs impacting decisions. Guide team to achieve key results for the assigned security assessment tasks.

Requirements

  • Currently authorized to work in the United States on a full-time basis.
  • Deep knowledge of procedure-based controls of a cybersecurity program.
  • Experience with qualitative risk analysis, vulnerability and patch management, threat modeling, and Identity and Access Management (IAM).
  • Familiarity with cybersecurity frameworks such as NIST CSF, PCI-DSS, and CIS.
  • Expert level assessment skills using technology-based controls of a cybersecurity program.
  • Knowledge of cloud security, Artificial Intelligence / GenAI risks, penetration testing results, cryptography, network security fundamentals, malware defense, data loss prevention, and endpoint security.
  • Excellent technical writing skills.
  • Ability to work independently and collaboratively with various teams.

Nice-to-haves

  • Experience in mentoring and guiding less experienced team members.
  • Familiarity with modern threat exploitation techniques used by threat actors.

Benefits

  • Paid Parental Leave
  • Paid Time Off
  • 401(k) Plan
  • Medical, Dental, Vision, & Health Savings Account
  • STD, Life, LTD and AD&D
  • Recognition Program
  • Education Assistance
  • Commuter Benefits
  • Family Support Programs
  • Employee Stock Purchase Plan
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service