Threat Governance - Engineer
Listed on 2025-12-31
-
IT/Tech
Cybersecurity, IT Consultant
FICO (NYSE: FICO) is a leading global analytics software company, helping businesses in 100+ countries make better decisions. Join our world-class team today and fulfill your career potential! The Opportunity
“This role will be working on Cloud security issues and the Vulnerability findings on FICO assets which includes user computers, data center systems and Cloud. This position will work with key stakeholders to understand threats unique to each business unit or application. This position will collaborate with technology, security, development and product management groups across the corporation to drive successful execution of the Threat governance Portifolio to ensure an appropriate proactive enterprise security posture.
A solid understanding of OS’s, IP networks, and database and application functionality are critical. This position should be able to participate in technical discussions with IT personnel and have the ability to quickly understand the FICO Technology environment, including network, OS and key applications.” – Software Engineering-Director.
- Collaborate with FICO Cyber Security Team, Business and IT partners, and clients.
- Act as an internal subject matter expert with respect to Vulnerability and Compliance scanning and reporting. Implement new and iterate on existing technology to help identify and mitigate security issues.
- Validate and triage identified Threats.
- Contribute to team strategy in managing threats and vulnerabilities.
- Develop, evangelize, and iterate on threat & vulnerability management practices.
- Conducting required tasks for the vulnerability scanning program and publishing reported vulnerabilities to impacted teams for remediation.
- Triage and risk rank vulnerabilities according to severity and exposure. Work with Product and IT teams to risk rank and patch vulnerabilities related to the technology stack. Develop remediation plans for vulnerabilities.
- Initiate improvement activity to reduce risk, ensure compliance, lower cost, and improve quality within IT processes.
- Conduct/support periodic risk assessments and develop appropriate mitigation plans in support of deliverables.
- Continuous review of configuration management and vulnerability management posture inside the company and knowledge of all external developments that could bring new risks, including vendor patches, zero-day exploits, end-of-life systems or deprecated services.
- Strong thought process to enhance the current capabilities of Cloud asset management , Cloud vulnerability management & cloud patch management
- Create reports to the stake holders for effective remediation and metrics for leadership.
- Security+, CEH or another similar info security/IT certification is desired.
- 2-4 years of Experience with Wiz, Qualys or other Cloud Security and Vulnerability scanning technology required.
- Demonstrates subject-matter expert level understanding in multiple IT, Security and Software disciplines.
- Ability to understand the cause and effect of application vulnerabilities with Operating System Vulnerabilities.
- Must be able to multi-task and keep track of large amounts of information across disparate systems.
- Ability to keep making progress and define future strategy/policy with regards to Vulnerability Management.
- Adherent to ‘continuous monitoring’ and ‘continuous improvement’ thought process.
- Demonstrated technical security expertise in a variety of cloud platforms (AWS is preferred).
- Comfortable interfacing with other internal or external organizations regarding problems that must be addressed to enhance security posture.
- knowledge on any scripting language is nice to have (python, Java, Shell, Bash)
- Moderate documentation and analytical skills; documenting processes, policies and standards
- knowledge of current threat landscape is a good to have.
- An inclusive culture strongly reflecting our core values:
Act Like an Owner, Delight Our Customers and Earn the Respect of Others. - The opportunity to make an impact and develop professionally by leveraging your unique strengths and participating in valuable learning experiences.
- Highly competitive compensation, benefits and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).