Works with third parties (such as Protexxa and ITMI) and respective departments to enable vulnerability scanning, identification of required mitigations, and implementation of agreed mitigating actions.
CAREEROPPORTUNITY
Title:Technical Analyst – Remediation Program
Work type:Contract – 3 months
Work Location: Barbados (remote work possible)
Position Description:
The Technical Analyst - Remediation Program works with third parties (such as Protexxa and ITMI) and respective departments to enable vulnerability scanning, identification of required mitigations, and implementation of agreed mitigating actions.
Main responsibilities of the role:
Vulnerability Scanning Coordination
Coordinate with third-party scanning vendors (Protexxa, ITMI, etc.)
Ensure proper access and configuration for scanning tools
Troubleshoot scanning issues and challenges
Maintain scanning schedules and documentation
Vulnerability Analysis
Review and analyze vulnerability scan results
Research vulnerability details and exploitation methods
Identify vulnerability patterns and root causes
Remediation Planning
Prioritize vulnerabilities based on risk and criticality
Determine appropriate remediation approaches
Develop remediation roadmaps and timelines
Assess resource requirements and constraints
Remediation Support
Work with department IT teams on remediation implementation
Assist with patch deployment and configuration changes
Validation and Verification
Conduct validation scanning after remediation
Test effectiveness of compensating controls
Document residual risks
Maintain remediation tracking database
The ideal candidate will possess the following qualifications & experience:
Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related field; OR
Associate degree with relevant certifications and equivalent experience
Minimum 5 years' experience in vulnerability management, systems administration, or security operations
Hands-on experience with vulnerability scanning tools (Nessus, Qualys, Rapid7, OpenVAS, etc.)
Experience working across multiple organizations or departments
Experience with both Windows and Linux environments
GIAC Certified Vulnerability Assessor (GCVA)
Certified Ethical Hacker (CEH)
CompTIA Security+
CompTIA CySA+
Core Competencies:
Technical Knowledge and Skills
Strong understanding of common vulnerabilities (OWASP Top 10, CVE, CWE)
Knowledge of Windows, Linux, and network device security
Understanding of security configuration standards (CIS Benchmarks, STIGs)
Familiarity with patch management processes and tools
Knowledge of security frameworks (NIST, ISO 27001)
Understanding of network protocols and services
Strong troubleshooting and analytical abilities
Only shortlisted candidates will be contacted