Cybersecurity Vulnerability Analyst

Visa Visa · Fintech · London, United Kingdom, United Kingdom

Visa is seeking a Cybersecurity Vulnerability Analyst to manage and coordinate vulnerability processes across their infrastructure and products. The role involves reviewing and escalating vulnerabilities, supporting compliance activities like PCI DSS and ASV, managing exceptions, and providing training on security best practices. The analyst will also collaborate with various teams and requires practical coding skills and technical proficiency in at least one programming language.

What you'd actually do

  1. Coordinate Vulnerability Management: Work with asset owners and stakeholders to ensure prompt remediation, offering guidance as needed.
  2. Review and Escalation: Organize and lead regular vulnerability review calls, ensuring that appropriate stakeholders and asset owners are aware of open findings.
  3. Reporting: Prepare and present quarterly vulnerability reports, raising findings to appropriate stakeholders and leadership.
  4. Compliance Support: Support PCI evidencing and Approved Scanning Vendor (ASV) activities, ensuring compliance with regulatory requirements.
  5. Exception Management: Guide exception management processes, review submissions, and track unresolved vulnerabilities, facilitating approvals and risk acceptance.

Skills

Required

  • 2+ years of relevant work experience and a bachelor’s degree OR 5+ years of relevant work experience.
  • Demonstrable experience in vulnerability management, application security, or a related cybersecurity discipline.
  • Experience supporting compliance activities (e.g., PCI DSS, ASV).
  • Familiarity with security frameworks, risk management, and exception handling.
  • Technical proficiency in at least one programming language.
  • Ability to successfully complete a coding assessment.

Nice to have

  • 3 or more years of work experience with a bachelor’s degree or more than 2 years of work experience with an Advanced degree.
  • Bachelor’s degree in computer science, Information Security, or a related field, or equivalent professional experience.
  • Experience delivering training and collaborating with cross-functional teams.
  • Relevant certificates (e.g., CISSP, CISM, CEH, OSCP) are desirable.
  • Strong knowledge of vulnerability management tools and methods, application security experience is a plus.
  • Strong analytical and advisory capabilities, with meticulous attention to detail in exception and risk management.
  • Excellent interpersonal and communication skills, able to convey complex technical concepts to diverse audiences.
  • Ability to adapt as the role evolves and as new threats and technologies emerge.

What the JD emphasized

  • compliance activities
  • PCI evidencing
  • Approved Scanning Vendor (ASV) activities
  • exception management processes
  • practical coding skills
  • technical proficiency in at least one programming language