Job Description :

Job Description Summary

Senior vulnerability analyst that will drive change within vulnerability management. Ability to lead in defining processes and tool recommendations needed to identify vulnerabilities, tests Chevron's digital security defenses, analyzes malicious code, and leverages all authorized resources and analytic techniques to secure Chevron's environment.

Job Description

This position supports the Information Risk Strategy Management (IRSM) Vulnerability Management (VM) program reporting to the Vulnerability Management Team Lead. Responsibilities include managing the vulnerability remediation process to ensure weaknesses identified through vulnerability scanning and assessments / penetration tests along with any emergency concerns are assigned to owners and tracked to resolution.

Responsible for analyzing information/data collected from vulnerability assessments and scans; and in conjunction with the IRSM risk managers, helps recommend mitigations in the form of policies, standards, and controls as they apply to the major risk domains. This person will also support project initiatives to assess vulnerability of Chevron's IT assets.

Support project initiatives to assess vulnerabilities in Chevron's IT assets and perform validation testing of remediated vulnerabilities from business vulnerability assessments, as needed.

Foundational knowledge in cybersecurity and apply that knowledge toward remediation initiatives.

Foundational skills in cybersecurity toolsets including infrastructure and application scanning, phishing campaigns, cloud access security broker, and other cross functional security tools.

Engage technical resources and leaders across the enterprise to share results and gain commitment.


- Demonstrated ability in vulnerability management or related field such as penetration testing, SOC, or threat intelligence.

-Understanding of attacker mindset, exploitation, and how vulnerabilities are leveraged.

- Knowledge of Cybersecurity principles and various information security technologies (i.e., IDS/IPS, HIPS, DLP, firewalls, network engineering, database, etc.).

- In-depth experience with cybersecurity concepts, vulnerability scanning tools, and other security techniques such as active/passive reconnaissance, vulnerability identification, exploitation, phishing, social engineering, and command and control techniques.

- Broad understanding in one of the following information technology areas used to support and manage the business (i.e., web, networking, database, cloud, telephony, mobile, applications, etc.).

Domain Knowledge

- Must understand IT systems (Operating Systems, databases, and applications).

- Experience in one of the following areas: a system administrator, application developer, programmer familiarity with MS Windows or UNIX/Linux operating systems.

- Strong desire to learn new tools and technologies highly motivated to apply that knowledge toward understanding and communicating the sources of vulnerabilities.


- Candidates should demonstrate strong verbal, written and presentation skills, as well as an ability to communicate technical information to different audiences (management, non-technical, IT Professionals, PCN Professionals). Able to engage and interview stakeholders requesting vulnerability management services to capture key information needed to effectively understand, clearly articulate, and document remediation plans.

Required Skills : Word
Basic Qualification :
Additional Skills :
Background Check :Yes
Drug Screen :Yes
Notes :
Selling points for candidate :
Project Verification Info :
Candidate must be your W2 Employee :Yes
Exclusive to Apex :No
Face to face interview required :No
Candidate must be local :No
Candidate must be authorized to work without sponsorship :Yes
Interview times set : :No
Type of project :Assessment/Analysis
Master Job Title :Security Analyst
Branch Code :Houston

Similar Jobs you may be interested in ..