Назад
Company hidden
1 день назад

Vulnerability Management Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Management Analyst (Cybersecurity): Managing the vulnerability lifecycle across infrastructure, applications, cloud, and container environments with an accent on risk-based prioritization, remediation coordination, and technical reporting. Focus on analyzing scanner results, validating remediation evidence, monitoring SLAs, and improving vulnerability management automation.

Location: Hybrid in Tres Cantos, Madrid, Spain; includes up to 8 weeks per year of teleworking outside the usual geographical area.

Company

hirify.global is building a specialized cybersecurity vulnerability management service for a financial-sector organization.

What you will do

  • Manage and track vulnerabilities across infrastructure, applications, cloud, and container environments.
  • Review scanner results, identify false positives and duplicates, and enrich vulnerability information.
  • Prioritize vulnerabilities using risk criteria and coordinate remediation with technical teams.
  • Monitor SLA compliance, escalate critical issues, and verify remediation evidence.
  • Prepare technical reports and service indicators while keeping operational documentation current.
  • Monitor automation and contribute to continuous improvement of the service.

Requirements

  • At least 2 years of cybersecurity experience, preferably in vulnerability management.
  • Higher Vocational Training or an equivalent degree in Computer Science or Cybersecurity.
  • Experience with vulnerability management scanners and platforms such as Qualys or equivalent tools.
  • Knowledge of CVSS, risk-based prioritization, Windows, Linux, networking, web applications, and IT infrastructure.
  • Experience interpreting vulnerabilities, defining mitigations, using ticketing and tracking tools, and preparing technical documentation.
  • Technical English is required; B2 level is recommended.

Nice to have

  • Knowledge of CVSS v4.0, EPSS, CISA KEV, Prisma Cloud, Qualys WAAS, Burp Suite, or equivalent tools.
  • Experience with cloud and container security, hardening and compliance, threat intelligence, pentesting, or technical vulnerability validation.

Culture & Benefits

  • Hybrid work with flexible start and finish times.
  • Intensive working hours on Fridays and during summer.
  • Personalized career development, training, and language-learning support.
  • National and international mobility, with a relocation package for candidates from other countries.
  • Flexible compensation, brand discounts, health, dental, and accident insurance.
  • Wellbeing support including physical, mental, and financial health training, free fruit, and coffee.

Hiring process

  • Recruitment includes telephone and personal contact with the talent acquisition team, either face-to-face or online.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →