2 дня назад
Product Security Incident Response Team (PSIRT) Vulnerability Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Product Security Incident Response Team (PSIRT) Vulnerability Analyst (Cybersecurity): Analyzing, validating, and prioritizing vulnerabilities affecting client products and services with an accent on exploitability, severity, business impact, and remediation coordination. Focus on L2 vulnerability assessment, PSIRT investigations, technical advisories, coordinated disclosure, and improving vulnerability response processes and tooling.
Location: Hybrid work in Vila Nova de Gaia, Portugal
Company
Engineering provides engineering, research and development, digital, and software technology services to organizations across multiple industries.
What you will do
- Perform L2 analysis, validation, and technical assessment of vulnerabilities affecting client products and services.
- Assess exploitability, severity, business impact, and customer and operational risk.
- Triage vulnerability reports from internal teams, external researchers, automated tools, and security assessments.
- Collaborate with engineering, product, and operations teams to validate findings and drive remediation through closure.
- Support PSIRT investigations, vulnerability response coordination, SLA tracking, and escalation of critical risks.
- Prepare vulnerability advisories, technical reports, risk assessments, management updates, and coordinated disclosure materials.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Engineering, Information Security, or equivalent professional experience.
- Experience in vulnerability management, product security, incident response, security operations, application security, or a related cybersecurity field.
- Strong knowledge of vulnerability assessment, risk analysis, vulnerability triage, and remediation processes.
- Experience analyzing software, firmware, operating systems, network infrastructure, embedded systems, and/or OT/ICS environments.
- Knowledge of vulnerability classes, attack techniques, exploitation concepts, remediation approaches, CVSS, CWE, CAPEC, and MITRE ATT&CK.
- Experience with security testing and vulnerability management tools, including SCA, SAST, vulnerability management platforms, and network or infrastructure scanners.
Nice to have
- Knowledge of SSDLC, IEC 62443, the NIST Cybersecurity Framework, and ISO 27001.
- Cybersecurity certifications such as CISSP, GSEC, GCIH, GPEN, OSCP, Security+, or GIAC.
Culture & Benefits
- Multicultural and inclusive work environment.
- Supportive atmosphere focused on work-life balance.
- National and international projects.
- Career growth programs, training, and certification opportunities.
- Health and life insurance.
- Referral program with bonuses and access to office facilities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Application Security Engineer
6 дней назад
Application Security Engineer (Cybersecurity)
5 дней назад
Obsolescence and Vulnerability Security Risk Analyst (Banking)
5 дней назад
Cybersecurity Risk Analyst (Financial Services)
2 дня назад
Security Assurance Specialist - Associate (Information Security)
5 дней назад