Vulnerability Management Cybersecurity Engineer
Current•Compiled, tracked vulnerabilities, and remediation results in a Power Bi dashboard to understand potential risks that may cause loss of confidentiality, integrity, or availability in IT resources and assets.•Developed risk-based remediation strategies for networks, operating systems, and applications to reduce the likelihood of a ransomware attack while ensuring business continuity for the different business units. •Leveraged Tanium discover module to identify routers, servers, workstations, domain controllers within Chevron’s internal network to perform vulnerability scanning using Nessus to identify Critical to High vulnerabilities and develop a remediation strategy to improve Chevron’s cyber posture. • Managed Chevron’s attack surface by routinely performing perimeter scanning every month using Masscan, Chomp, Spiderfoot, and Shodan to obtain a list of Chevron’s live public IP addresses, domains and subdomains, and Nessus to scan for vulnerable systems open to exploitation by an attacker.•Led and trained team of managed service providers (MSP) on vulnerability scanning of Chevron’s network by developing a Nessus playbook, detailing what configuration settings, CVE’s plugins, and hosts should be use depending on the type of systems that require a vulnerability scan