Cyber Security Specialist
- Full-time
Company Description
Since opening our first self-storage facility in 1972, Public Storage has grown to become the largest owner and operator of self-storage facilities in the world. With thousands of locations across the U.S. and Europe, and more than 170 million net rentable square feet of real estate, we're also one of the largest landlords.
We've been recognized as A Great Place to Work by the Great Place to Work Institute. And, our employees have also voted us as having Best Career Growth, ranked us in the Top 5% for Work Culture, and in the Top 10% for Diversity and Inclusion.
We're a member of the S&P 500 and FT Global 500. Our common and preferred stocks trade on the New York Stock Exchange.
Public Storage is the nation’s leading self-storage provider, recognized for its iconic orange doors and commitment to delivering simple, reliable solutions to millions of customers across the country. We are expanding our creative team to enhance our consistent and engaging visual brand presence.
Job Description
The Cyber Security Specialist is responsible for supporting and operating the organization's Vulnerability Management Program. This role focuses on identifying, assessing, prioritizing, tracking, and validating remediation of vulnerabilities across endpoints, servers, cloud environments, network devices, applications, and other enterprise technology assets. The Cyber Security Specialist works closely with Security, Infrastructure, Network, Cloud, Application, IT Operations, and Compliance teams to reduce risk, improve remediation performance, maintain audit-ready evidence, and strengthen the organization's overall security posture.
Vulnerability Management - Primary Focus
- Administer and support enterprise vulnerability management tools.
- Perform scheduled and ad hoc vulnerability scans across endpoints, servers, cloud resources, databases,
- network devices, and externally exposed assets.
- Review scan results, validate findings, identify duplicates or false positives, and ensure vulnerabilities are
- accurately categorized.
- Prioritize vulnerabilities using CVSS, CISA Known Exploited Vulnerabilities (KEV), exploitability, asset criticality, internet exposure, business impact, and threat intelligence.
- Create and track remediation tickets with appropriate technology owners and support teams.
- Monitor remediation service-level targets for Critical, High, Medium, and Low vulnerabilities.
- Validate remediation through re-scans, patch verification, configuration checks, and closure evidence.
- Maintain vulnerability exception records, risk acceptance documentation, false positive decisions, and compensating control evidence.
- Identify recurring vulnerabilities and assist with root cause analysis to reduce repeat findings.
Reporting, Metrics, and Documentation
- Prepare vulnerability reports, dashboards, scorecards, and remediation status updates for security leadership
- and technical teams.
- Track vulnerability aging, backlog, SLA compliance, overdue remediation, recurrence trends, and risk reduction
- progress.
- Maintain vulnerability management procedures, runbooks, standards, remediation guidance, and evidence
- repositories.
- Support audit and compliance requests by providing scan records, remediation evidence, exception approvals,
- and control performance documentation.
Security Administration and Operational Support
- Support security tool administration activities related to asset coverage, scan configuration, tagging, grouping, and reporting accuracy.
- Assist with security investigations were vulnerabilities, missing patches, weak configurations, or exposed services may contribute to risk.
- Review hardening standards, configuration baselines, and patch compliance information to help reduce exposure.
- Monitor emerging vulnerabilities, vendor advisories, zero-day activity, and threat intelligence to help determine organizational impact.
Collaboration and Remediation Coordination
- Partner with Infrastructure, Network, Cloud, Application, Endpoint, and third-party support teams to drive timely remediation.
- Communicate vulnerability risk and remediation expectations clearly to technical and non-technical stakeholders.
- Participate in change management, patch planning, and remediation meetings as needed.
- Escalate overdue, high-risk, or repeatedly recurring vulnerabilities to management for visibility and action.
Qualifications
- Bachelor’s degree in information security, Information Technology, Computer Science, or related field, or equivalent combination of education and experience.
- 2+3 years of experience in cybersecurity, information security, vulnerability management, systems administration, or related IT roles.
- Hands-on experience with vulnerability scanning, vulnerability validation, remediation tracking, or patch management processes.
- Experience with vulnerability management tools similar. Working knowledge of CVSS, CISA KEV, vulnerability exploitation concepts, patch management, system
- hardening, and remediation prioritization.
- Working knowledge of Windows, Linux, Active Directory / Entra ID, TCP/IP, DNS, VPNs, endpoints, firewalls, and cloud security fundamentals.
Preferred Qualifications
- Professional certifications such as Security+, CySA+, CISSP Associate, GIAC, CEH, Microsoft Security, cloud security, or vulnerability assessment certifications.
- Experience supporting PCI DSS, SOX, NIST Cybersecurity Framework, CIS Controls, ISO 27001, or similar compliance requirements.
- Experience using ticketing workflows, SIEM, endpoint protection, or reporting platforms.
- Experience with PowerShell, Python, Bash, REST APIs, or automation for reporting and security operations.
- Familiarity with cloud platforms such as Azure, GCP, or AWS.
Additional Information
Workplace
- One of our values pillars is to work as One Team and we believe that there is no replacement for in-person collaboration but understand the value of some flexibility. Public Storage teammates are expected to work in the office five days each week with the option to take up to three flexible remote days per month.
Public Storage is an equal opportunity employer and embraces diversity. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or any other protected status. All qualified candidates are encouraged to apply.
**Sponsorship for Work Authorization is not available for this posting. Candidates must be authorized to work in the U.S. without restrictions or requiring sponsorship now or in the future. We do not provide training plans or support for F-1 OPT, STEM OPT extensions, or future visa sponsorship.**
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply