Talent.com
Associate Director, Security Patching (ISC SecOps Vulnerability Services)

Associate Director, Security Patching (ISC SecOps Vulnerability Services)

NovartisBarcelona, Cataluña, España
Hace más de 30 días
Descripción del trabajo

Overview

Location : Barcelona, Spain; Hyderabad, India; (12 days / month in office). Internal job title : Assoc. Dir. DDIT ISC SecOps VulnSvcs. The role is based in Barcelona or Hyderabad. Novartis is unable to offer relocation support for this role : please only apply if this location is accessible for you.

About The Role

The Associate Director, Security Patching will join the DDIT ISC Security Operations Vulnerability Services team. The role will focus on reducing risk exposure from security vulnerabilities with major focus on enabling, enforcing and operating scalable remediation through Security Patching process.

Among the responsibilities, the role includes analyzing ongoing security vulnerabilities risk posture, aligning patch-based remediations, collaborating with service lines and finding owners for managing resolutions for patch success, acting as SME to assess discovered vulnerabilities, providing pragmatic solutions and flexibly supporting emergency security patching. Collaboration with cross-functional teams for patch infrastructure health, threat intel, security architecture, remediation and security operations are key.

Please note this position may require flexibility with work schedules (including support outside standard business days / hours) to coordinate emergency response for high-risk vulnerability remediation with relevant stakeholders.

Key Responsibilities

  • Govern and operate the Security Patch Management process for technologies such as Windows servers, Unix servers, Windows clients, Mac clients, databases, and middleware.
  • Assess daily risk exposure from security vulnerabilities, assess patch applicability and enable scalable remediations through centralized or decentralized patching.
  • Monitor patching coverage and compliance using tools such as SNOW, INPAT, SCCM, Intune, JamF, Ansible.
  • Generate regular reports on patching status, coverage, and risk metrics; continuously engage with service lines and stakeholders to maintain the process and tools health.
  • Assess, initiate and lead emergency patching activities to ensure timely responses to critical vulnerabilities; perform root cause analysis for patching failures and implement corrective actions.
  • Create and maintain documentation, including SOPs, work instructions knowledge articles, and training material. Ensure cross-functional relevant documents are maintained / updated from time to time or upon changes to related working.
  • Take accountability to ensure adherence with Security and Compliance policies and procedures; implement security policies, procedures, and standards to ensure confidentiality, integrity, and availability of resources from technical vulnerabilities.
  • Stay up to date with the latest security threats and vulnerabilities, proactively recommending mitigation strategies.
  • Provide security awareness and training to teams and stakeholders.
  • Collaborate with various stakeholders from cross-functional service lines, security operations, architecture, cyber, SOC, and application / infra teams to achieve technical risk reduction goals.

Essential Requirements

  • University working and thinking level, degree in technical computer science or information security area or comparable education / experience.
  • 8+ years of overall working experience in information security, preferably in Security patch management, vulnerability management and / or Infrastructure patching domain.
  • 3+ years in handling security vulnerability analysis, remediation and response coordinating with relevant stakeholders, and implementing corrective actions.
  • Experience with vulnerability management, scanning and patching tools : Qualys, ServiceNow, Wiz, MS Defender, SCCM, Intune, JamF, Ansible.
  • Excellent hands-on analytical skills for vulnerability exposure analysis, remediation analysis, mitigations and RCA. Strong understanding of metrics, KPI / KRI, SLAs, and dashboards for vulnerability management and providing executive reporting.
  • Strong knowledge of automation / orchestration implementation in patch management, top security vulnerabilities, threat correlation, control mitigations, vulnerability scoring standards and ability to translate vulnerability severity as security risk.
  • Knowledge of operating systems and platforms : Windows servers, Unix servers, Windows clients, Mac clients, databases, middleware technologies for patch analysis.
  • Know how on handling shadow IT asset scenarios, sensitizing teams for security patching, technical debt, SW patching, maintenance windows, scalable remediations, and relevant domains.
  • Demonstrated stakeholder management skills and leadership skills through engagement with large security / development program stakeholders.
  • Excellent communication and cross-functional collaboration skills, ability to effectively convey security risks and vulnerabilities to both technical and non-technical stakeholders.
  • Strong problem-solving skills and the ability to work independently and ensuring external team deliverables and day to day outcomes; strong curiosity, staying up to date with the latest security updates, vulnerability disclosures, and industry best practices.
  • Desirable

  • Working experience in security patching domain, vulnerability patch analysis and automation / orchestration implementation in patch management.
  • Relevant certifications : CISSP, CCSP, or equivalent.
  • Product certified knowledge like Microsoft or RHCE.
  • Commitment To Diversity & Inclusion

    We are committed to building an outstanding, inclusive work environment and diverse teams representative of the patients and communities we serve.

    Why Novartis

    Our purpose is to reimagine medicine to improve and extend people’s lives and our vision is to become the most valued and trusted medicines company in the world. How can we achieve this? With our people. It is our associates that drive us each day to reach our ambitions. Be a part of this mission and join us!

    #J-18808-Ljbffr

    Crear una alerta de empleo para esta búsqueda

    Associate Director • Barcelona, Cataluña, España

    Ofertas relacionadas
    • Oferta promocionada
    SAP Associate Architect (EHS)

    SAP Associate Architect (EHS)

    Merck GroupMollet del Vallès, Cataluña, España
    Join to apply for the SAP Associate Architect (EHS) role at Merck Group.The IT SAP Associate Architect (EHS) will be responsible for identifying and analyzing business needs, gathering and document...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Active Directory Specialist

    Active Directory Specialist

    JR SpainBarcelona, Catalonia, España
    Social network you want to login / join with : Key Responsibilities : Provide expert troubleshooting for multi-forest Active Directory service issues (DFS, DNS, WINS, LDAP etc)Promote and demote domain ...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Industrial Safety & Security Engineer

    Industrial Safety & Security Engineer

    Talent Solutions ManpowerGroup EspañaParets del Vallès, Catalonia, España
    Cuentas con 3 años de experiencia en la aplicación de la normativa de seguridad industrial en España para proyectos industriales para el sector farmacéutico o químico? ¿Tienes disponibilidad para d...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Coordinador / a de Medio Ambiente, Salud y Seguridad (EHS)

    Coordinador / a de Medio Ambiente, Salud y Seguridad (EHS)

    RandstadTordera, Catalonia, España
    Buscan un profesional con una sólida base técnica para unirse a su equipo y actuar como.Sistema EHS, asegurando la protección de las personas, el medio ambiente y la continuidad del negocio.Mostrar másÚltima actualización: hace 3 días
    • Oferta promocionada
    Internal Audit Manager – IT & Security

    Internal Audit Manager – IT & Security

    Giesecke+DevrientEl Prat de Llobregat, Catalonia, España
    At Giesecke+Devrient, a global leader in SmartCards and Secure Payment Elements, we are seeking a Internal Auditor to lead and enhance our 3rd Line audit program across IT operations, cybersecurity...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Associate Director, IT Solution Delivery

    Associate Director, IT Solution Delivery

    Jordan martorell s.l.Barcelona, Cataluña, España
    Summary Our Associate Director, IT Solution Delivery is our senior specialist for project delivery and / or operations in the given business sub-capability. In this role, you will partner with busines...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Senior Consultant SAP BW / BI

    Senior Consultant SAP BW / BI

    SiegfriedBarberà del Vallès, Catalonia, España
    At Siegfried, we offer more than just a job — we provide a platform for you to thrive, grow, and shape your future.With locations across the globe, we empower our employees to build meaningful, int...Mostrar másÚltima actualización: hace 26 días
    • Oferta promocionada
    Subdirector / a de hotel

    Subdirector / a de hotel

    ICSA Grupo®Pineda de Mar, Catalonia, España
    Importante hotel situado en Pineda de Mar necesita incorporar un / a : .En dependencia de Dirección se encargará de : .Supervisar y coordinar la operativa de todos los departamentos (Pisos, Cocina, Recep...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Director, Product Security.

    Director, Product Security.

    Games Jobs DirectBarcelona, Cataluña, España
    Scopely is looking for a Director of Product Security to join our IT / Ops team in Barcelona on a hybrid basis or remote in Spain or Portugal. At Scopely, we care deeply about what we do and want to...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Enterprise Security Architecture (AI)

    Enterprise Security Architecture (AI)

    LHHBarcelona, Cataluña, España
    El equipo de Arquitectura Empresarial de Seguridad busca un Director / a Asociado de Arquitectura de Seguridad Empresarial para IA. Este puesto contribuirá al desarrollo de estándares de arquitectur...Mostrar másÚltima actualización: hace 16 días
    • Oferta promocionada
    Associate Director, IT Service Operations

    Associate Director, IT Service Operations

    NovartisBarcelona, Cataluña, España
    Summary Our Associate Director, Service Operations will plan all aspects of the future operational model (DevOps) for our next generation Statistical Compute Environment (SCE).Upon go-live of the S...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Technical Delivery Lead, Associate Director

    Technical Delivery Lead, Associate Director

    NovartisBarcelona, Cataluña, España
    Technical Delivery Lead, Associate Director – Novartis.Primary Location : Prague, Czech Republic.Other Locations : Hyderabad, India. Barcelona, Spain; Ljubljana, Slovenia.Relocation Support : This rol...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Senior Manager Business Applications - SAP Data Migration

    Senior Manager Business Applications - SAP Data Migration

    SiegfriedBarberà del Vallès, Catalonia, España
    The Siegfried Group is a global life science company with a network of 13 sites in Europe, the USA and Asia.Siegfried offers contract development and manufacturing of active pharmaceutical ingredie...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Global CRM Manager

    Global CRM Manager

    OyshoTordera, SPAIN
    Te apasiona entender al cliente y conectar con él de manera inteligente, personalizada y creativa?.En Oysho buscamos un / a Global CRM Manager con visión estratégica, sensibilidad por la moda y pasió...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Process & Integrations Manager

    Process & Integrations Manager

    Multinacional alemanaGranollers, Catalonia, España
    We are looking for an experienced Enterprise Application Architect to design a secure, scalable IT architecture to support business capabilities. Key duties will include leading application rational...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Active Directory Specialist

    Active Directory Specialist

    InterEx GroupBarcelona, Catalonia, Spain
    Key Responsibilities : Provide expert troubleshooting for multi-forest Active Directory service issues (DFS, DNS, WINS, LDAP etc) Promote and demote domain controllers Support AD name resolution tec...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Associate Director, Cyber Defense Business Engagement

    Associate Director, Cyber Defense Business Engagement

    NovartisBarcelona, Cataluña, España
    Associate Director, Cyber Defense Business Engagement.Location : Prague, Czech Republic / Barcelona, Spain; (12 days / month in office). Internal job title : Associate Director, DDIT ISC Data Protection &...Mostrar másÚltima actualización: hace 20 días
    • Oferta promocionada
    INFORMATION SECURITY ASSOCIATE DIRECTOR

    INFORMATION SECURITY ASSOCIATE DIRECTOR

    Almirall Hermal GmbHBarcelona, Cataluña, España
    INFORMATION SECURITY ASSOCIATE DIRECTOR page is loaded## INFORMATION SECURITY ASSOCIATE DIRECTORlocations : BARCELONAtime type : Full timeposted on : Vor mehr als 30 Tagen ausgeschriebenjob requ...Mostrar másÚltima actualización: hace 11 días