Senior Enterprise Vulnerability Analyst
Listed on 2025-12-01
-
Security
Cybersecurity
Title:
Senior Enterprise Vulnerability Analyst
At Graphic Packaging International, we produce the paper cup that held your coffee this morning, the basket that transported those bottles of craft beer you enjoyed last weekend, and the microwave tray that heated your gourmet meal last night. We’re one of the largest manufacturers of paperboard and paper-based packaging for some of the world’s most recognized brands of food, beverage, food service, household, personal care and pet products.
Headquartered in Atlanta, Georgia, we are collaborative, diverse, innovative individuals who create inspired packaging while giving back to our communities.
With over 25,000 employees working in more than 130 locations worldwide, we strive to be environmentally responsible in our industry and in the communities where we operate. We are committed to workplace diversity and offer compensation and benefits programs that are among the industry’s best to reward the talented people who make our company successful.
If this sounds like something you would like to be a part of, we’d love to hear from you.
A World of Difference. Made Possible.
MISSION / SUMMARYEnterprise Vulnerability Management covers server, cloud, workstations, applications, appliances, and mobile devices to ensure all risk mitigation activities are performed in a timely manner to de-risk and protect Graphic Packing International’s enterprise assets from cyber-threats.
The primary mission includes evaluating security vulnerabilities, assessing risk and impact, to protect GPI from internal and external threat vectors. Utilization of a host of GPI operational and cyber tools to discover, prioritize and automate methods towards vulnerability management tasks.
Primary ResponsibilitiesThe Enterprise Vulnerability Analyst will be responsible with assisting the continual development and growth of the Enterprise Vulnerability Management, or EVM, program. This role will be collaborating with cross-functional and technical teams in a global, matrixed environment with the goal to de-risk GPI. Additional activities will include revising existing documentation and process models as well as assisting in the implementation of new, innovative methodologies of vulnerability management as necessary.
The analyst must be technically competent being capable of identifying process, security, and general technical gaps could cause security events and follow defined procedures for mitigating threats.
- De-risk the GPI enterprise utilizing tools that make up the GPI Operational Stack including but not limited to Qualys, Service Now, SCCM, and Sentential One
- Detection and reporting of all vulnerabilities (including misconfigurations) in all environments such as production & non-production, including but not limited to network, servers, databases, application, and workstations)
- Collaborate with cross-functional, global organizations including IT Service Owners, managed service providers, shared services, and internal business partners
- Deep dives into vulnerability findings to determine EOL/EOS services and operating systems, following through to ensure service remediation or operational risk exceptions are documented and reported
- Triage vulnerabilities and application findings to determine required patching, remediation, and prioritization
- Driving process excellence in the enterprise vulnerability management space performing in a matrixed environment across governance teams
- Engage with department leaders, project managers, software development, and lines of business to acquire support and evaluate all changes
- Serve as change agent by leading successful process improvement practices, diagnosing barriers to Enterprise Vulnerability Management success, facilitating resolutions as appropriate
- Apply industry best practices to maximize efficiencies and achieve adherence to diverse program policy guidelines
- Drive a regular cadence with stakeholders to gain a holistic perspective of the current state of VM and Patch Management operations
- Assist with the determination and the scope of the program
- Provide technical knowledge to operations and various support teams
- Continually enrich the data quality of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).