1 час назад
Operational Security Engineer (Vulnerability Management)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Operational Security Engineer (Vulnerability Management) (Qualys/Tanium): Managing end-to-end vulnerability and security compliance lifecycles across enterprise Windows, Linux, on-premises, DMZ, and cloud environments with an accent on vulnerability analysis, remediation coordination, and operational reporting. Focus on maintaining scanning platforms, tracking SLA-based remediation, assessing security controls, and improving automation and compliance coverage.
Location: Bucharest, Romania; Workplace: Hybrid
Company
is a software engineering and IT consulting company delivering team augmentation, dedicated teams, custom software development, enterprise systems, automation frameworks, and digital transformation platforms.
What you will do
- Manage the end-to-end vulnerability and security compliance lifecycle, including scan preparation, execution, analysis, remediation tracking, and reporting.
- Perform vulnerability and compliance scans across Windows, Linux, on-premises, DMZ, and cloud environments using Qualys, Tanium, PingCastle, and related tools.
- Coordinate remediation with infrastructure, security, application, and business teams, including SLA tracking, ownership assignment, risk escalation, and exception management.
- Maintain security KPIs, dashboards, operational indicators, technical documentation, procedures, guidelines, and contingency plans.
- Manage the availability and lifecycle of vulnerability management platforms, including upgrades, patching, incident resolution, and maintenance.
- Perform technical assessments and PoCs while continuously improving scanning coverage, automation, reporting, and security controls.
Requirements
- Strong experience in vulnerability management, security compliance, and operational security in complex enterprise environments.
- Hands-on experience with Qualys and Tanium, including vulnerability, compliance, SelfAssessment, API, and Comply capabilities.
- Experience with PingCastle and knowledge of ELK Stack, Power BI, and Power Query for security analysis and reporting.
- Strong understanding of NIST, CIS Benchmarks, OWASP, ISO 27001, PTES, ISSAF, and OSSTMM.
- Technical knowledge of Windows, Linux, cloud, networking, infrastructure security, patch management, system hardening, and network protocols.
- Automation skills with Python, PowerShell, and Regular Expressions, plus experience coordinating remediation and communicating findings to technical stakeholders.
- Fluent French, written and spoken, and good command of English required.
Culture & Benefits
- Premium medical package, lunch tickets, Pluxee Card, Bookster subscription, and a 13th salary or yearly bonuses.
- Flexible working program with openness to remote work alongside a hybrid workplace.
- Enterprise job security with a startup mentality, flat hierarchy, international exposure, and a supportive work-life balance culture.
- Access to learning platforms, courses, certifications, mentorship, and professional development opportunities.
- Opportunities to choose projects aligned with career goals and participate in team events and internal practices.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →