Oct. 3, 2022, 2:22 p.m. | /u/Jonathan-Todd

cybersecurity www.reddit.com

I’m normally very forensics-obsessed but recently [expanded my focus](https://www.reddit.com/r/cybersecurity/comments/xiayvl/heres_why_business_operations_communication_and/?utm_source=share&utm_medium=ios_app&utm_name=iossmf) to the Risk Management world. Particularly in the realm of compliance with government regulations, a central point of focus in RM is vulnerability scan results. The problem is that an organization can, after one of these automated scans, have many thousands of CVEs to deal with.

Some of the qualities I’ve heard repeated:

- Not all of the returned vulnerabilities are exploitable.

- Not all of them are accurate.

And I’m …

compliance cybersecurity scanners vuln work

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Consultant

@ Auckland Council | Central Auckland, NZ, 1010

Security Engineer, Threat Detection

@ Stripe | Remote, US

DevSecOps Engineer (Remote in Europe)

@ CloudTalk | Prague, Prague, Czechia - Remote

Security Architect

@ Valeo Foods | Dublin, Ireland

Security Specialist - IoT & OT

@ Wallbox | Barcelona, Catalonia, Spain