Назад
Company hidden
14 часов назад

Lead Engineer, Vulnerability & Exposure Management (f/m/d)

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Engineer, Vulnerability & Exposure Management (Cybersecurity): Engineering vulnerability and exposure management pipelines for scanning, data ingestion, normalization, prioritization, ticketing, reporting, and automation with an accent on Python, SQL, REST APIs, and risk-based prioritization. Focus on integrating vulnerability, ticketing, cloud, and endpoint data sources, applying threat intelligence such as EPSS and CISA KEV, and maintaining data quality and service ownership.

Location: On-site in Krakow, Poland

Company

hirify.global is a science and technology company operating across life sciences, diagnostics, and biotechnology.

What you will do

  • Engineer scan coverage, vulnerability data ingestion and normalization, prioritization logic, ticketing, and reporting pipelines.
  • Build Python, SQL, and REST API automation for prioritization, SLA logic, exception processes, and validation.
  • Implement and refine the CTEM operating model in collaboration with the Global Lead.
  • Create pipeline runbooks, data-quality checks, and service-ownership mappings to support ongoing operations.
  • Integrate vulnerability and exposure workflows with cloud, endpoint, application, remediation, and ticketing systems.

Requirements

  • 5+ years of experience in vulnerability management or security engineering.
  • Hands-on experience engineering vulnerability and exposure tooling such as Tenable, Qualys, Rapid7, CrowdStrike FEM, or Defender, including scan coverage, authenticated scanning, and data normalization.
  • Experience building integrations across vulnerability, ticketing, cloud, and endpoint data sources using Python, SQL, and REST APIs.
  • Experience applying risk-based prioritization beyond CVSS using EPSS, CISA KEV, threat intelligence, and asset context.
  • One of the following certifications: CrowdStrike CCFA, Tenable VM Specialist, Qualys VMDR, GIAC GSEC/GMON, or a cloud security certification.

Nice to have

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • Experience with attack surface management, cloud posture, or container/Kubernetes exposure.
  • Experience with patch and remediation orchestration tools such as BigFix, SCCM/MECM, or Red Hat Satellite.

Culture & Benefits

  • Corporate information security role hosted by the Cytiva operating company.
  • Work in a continuous-improvement culture focused on science, technology, and real-world impact.
  • Opportunity to develop within a global organization with internal career growth opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →