Cybersecurity Specialist
Caterpillar
- Location
- Irving Texas
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 106 approvals (FY2023)
- Posted
- 20h ago
Skills
About this role
Career Area: Technology, Digital and Data Job Description: Your Work Shapes the World at Caterpillar Inc. When you join Caterpillar, you're joining a global team who cares not just about the work we do – but also about each other. We are the makers, problem solvers, and future world builders who are creating stronger, more sustainable communities. We don't just talk about progress and innovation here – we make it happen, with our customers, where we work and live. Together, we are building a better world, so we can all enjoy living in it. The Qualys Platform Lead owns the administration, operation, governance, and continuous improvement of Caterpillar’s enterprise Qualys platform. This role provides technical leadership for vulnerability scanning, scanner appliances, Cloud Agents, platform configuration, asset data quality, reporting, integrations, and roadmap delivery across a global environment. The role serves as the primary Qualys subject matter expert and works closely with Cybersecurity, Infrastructure, Cloud, Application, ServiceNow, Governance and Compliance, and leadership teams to support effective vulnerability identification, prioritization, routing, and remediation coordination.
What You Will Do
Platform Ownership & Administration Manage platform configurations, scan profiles, scanner appliances, schedules, authentication records, asset tags, user access, and permissions, subscription usage, and operational health. Ensure high availability, accuracy, and scalability of vulnerability scanning across enterprise-wide infrastructure and coordinate rescanning and validation activities as needed. Maintain integrations between Qualys, ServiceNow, CMDB, cloud platforms, reporting systems, and approved security technologies. Oversee host discovery, authenticated infrastructure scanning, scanner appliance operations, and Cloud Agent deployments. Analyze vulnerability data to identify trends, coverage gaps, systemic issues, and areas requiring attention. Support risk-based prioritization using Qualys Detection Scores, ETM and TruRisk capabilities, threat intelligence, exploitability, and asset context. Lead prioritization efforts using Caterpillar’s risk criteria and Qualys capabilities (e.g., TruRisk, Threat Protection, Patch Management modules if applicable). Leverage AI-assisted security analytics and risk-scoring capabilities to improve vulnerability prioritization and remediation decision-making. Evaluate and validate AI-generated insights from Qualys TruRisk, threat intelligence platforms, and security analytics tools to reduce false positives and focus remediation efforts on exploitable risks. Utilize predictive analytics to identify emerging vulnerability trends, attack paths, and areas of heightened exposure. Evaluate AI use cases and emerging technologies to improve operational efficiency, asset discovery, threat exposure analysis, and remediation effectiveness. Governance, Reporting & Metrics Work closely with Governance and Compliance teams to support audits, controls, and regulatory requirements. Create, update, and maintain operational documentation, standards, and processes for vulnerability lifecycle management. Assess and mitigate risks associated with AI-generated recommendations and automated remediation activities. Cross-Functional Collaboration Partner with Infrastructure, Cloud, Application, and DevOps teams to drive remediation plans and support secure system configurations. Serve as a trusted advisor to IT partners, educating them on vulnerability risks, remediation techniques, and Qualys usage best practices. Provide escalation support and root cause analysis for scan failures, agent issues, or false positives. Continuous Improvement Evaluate and implement new Qualys modules, features, or scanning techniques aligned with Caterpillar’s security roadmap. ETM/TruRisk, CSAM (Asset Management), QPM (Patch Management) and QPA (Policy Control/Audit, EASM (Attack Surface Management). Drive