Назад
Company hidden
12 часов назад

Vulnerability Management (VM) Specialist (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Netherlands
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Management (VM) Specialist (Cybersecurity): Managing the end-to-end vulnerability lifecycle for Finance & Risk, from validation and risk scoring through remediation tracking and verification, with an accent on CVSS-based prioritization, threat intelligence, asset criticality, and regulated IT risk governance. Focus on coordinating DevOps remediation, reducing scan noise, improving vulnerability coverage and automation, and keeping risk metrics within the approved risk appetite.

Location: HBP, Amsterdam, Netherlands; hybrid working.

Company

hirify.global supports ING’s banking operations through technology, IT risk, security, and resilience expertise.

What you will do

  • Manage the end-to-end vulnerability management lifecycle, including validation, triage, risk scoring, remediation tracking, and verification.
  • Prioritize vulnerabilities using CVSS, threat intelligence, exploitation activity, asset criticality, exposure, and compensating controls.
  • Coordinate remediation sessions with owners and validate fixes through patches, configuration changes, version upgrades, or mitigations.
  • Advise DevOps teams on vulnerability management issues and translate complex security risks into actionable guidance.
  • Improve scanning quality by reducing false positives and duplicates, tuning scans, expanding coverage, and driving automation.
  • Monitor Finance & Risk vulnerability metrics, support risk appetite compliance, and contribute to Risk Opinion and First Line Monitoring activities.

Requirements

  • Strong knowledge of the end-to-end vulnerability management process.
  • Expertise in vulnerability identification, analysis, prioritization, and remediation.
  • Experience with vulnerability scanning and management tools such as Nessus, Qualys, Tenable, Rapid7, GSOC, ServiceNow, Checkmarx, Cloud Atlas, or APF.
  • Knowledge of CVSS classification, vulnerability risk metrics, and risk governance frameworks.
  • Experience with vulnerability management in complex, regulated environments.
  • Strong stakeholder management, communication, ownership, and consultancy skills.

Nice to have

  • Certifications such as CISSP, OSCP, GCIH, or similar.

Culture & Benefits

  • Full-time employment with a 36-hour working week.
  • 25–28 vacation days depending on the contract.
  • Pension scheme, 13th-month salary, and 8% holiday payment.
  • Hybrid working and an informal environment with innovative colleagues.
  • Personal growth opportunities and challenging work in IT risk and security.

Hiring process

  • Submit a CV and motivation letter through the application process.
  • Contact the recruiter attached to the advertisement for questions.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →