Назад
Company hidden
обновлено 6 дней назад

Vulnerability Management Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Management Analyst (Cybersecurity): Identifying, assessing, and coordinating remediation of vulnerabilities across a global, multi-product environment with an accent on vulnerability tooling, secure configuration benchmarks, and risk-based prioritisation. Focus on tuning SAST, DAST, SCA, CSPM, and IVS programmes, coordinating penetration testing, and designing remediation metrics and reporting.

Location: Hybrid in Birmingham, England, United Kingdom

Company

hirify.global operates a global, multi-product business with an information security and data protection function supporting product security and risk management.

What you will do

  • Configure, tune, maintain, and integrate vulnerability scanning tools with ticketing systems and CI/CD pipelines.
  • Triage vulnerability findings, confirm genuine issues, assess risk, and prioritise remediation based on severity, exploitability, and business impact.
  • Develop secure configuration benchmarks and hardening guidance aligned with recognised industry frameworks.
  • Work with developers and engineers to explain findings, provide remediation guidance, track overdue actions, and escalate where necessary.
  • Coordinate internal vulnerability scanning, web application testing, and penetration testing programmes with external providers.
  • Design remediation SLAs, produce regular vulnerability reports, and improve vulnerability management processes and tooling.

Requirements

  • At least 2 years of experience in vulnerability management, security operations, development, or a related security or IT role.
  • Hands-on experience with vulnerability management tooling such as SAST, DAST, SCA, CSPM, or IVS.
  • Knowledge of common vulnerability types and remediation approaches, including the Mitre ATT&CK Framework and OWASP Top 10.
  • Experience triaging and risk-assessing findings and coordinating penetration testing or other third-party security engagements.
  • Ability to explain technical findings to developers and non-technical stakeholders, manage parallel workstreams, and operate autonomously in an agile enterprise environment.
  • Ability to read common programming languages is essential; scripting or coding experience is preferred.

Nice to have

  • CompTIA Security+, CompTIA CySA+, GIAC GFACT, GIAC GPEN, or CEH certification.
  • Experience developing scripts or code for automation.

Culture & Benefits

  • Fully funded training pathway and mentoring support.
  • 25 days of holiday plus bank holidays, a paid Wellbeing Day, flexible bank holidays, and the option to buy or carry over up to 5 additional days.
  • Enhanced family-friendly leave, wedding or honeymoon leave, and an Employee Assistance Programme.
  • Pension scheme, Corporate Medical Cash Plan, electric car salary sacrifice scheme, and payroll giving.
  • Professional qualification funding, wellbeing workshops, a paid Volunteer Day, community groups, and employee discounts.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →