Назад
Company hidden
6 часов назад

Cybersecurity Engineer (Vulnerability Management)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Engineer (Vulnerability Management): Leading vulnerability management for a large-scale financial-sector service across infrastructure, applications, cloud, and container environments with an accent on risk-based prioritization, remediation, and technical coordination. Focus on analyzing critical and actively exploited vulnerabilities, defining compensating controls, monitoring SLAs and KPIs, and improving automation with supervised AI use.

Location: Hybrid in Tres Cantos, Madrid, Spain; includes up to 8 weeks per year of teleworking outside the usual geographical area.

Company

hirify.global provides a large-scale Vulnerability Management service for an organization in the financial sector.

What you will do

  • Act as the technical reference for Vulnerability Management operations and resolve technical escalations.
  • Perform advanced vulnerability analysis and risk-based prioritization using CVSS, EPSS, CISA KEV, exposure, criticality, and Threat Intelligence.
  • Define and monitor remediation activities, mitigations, and compensating controls.
  • Coordinate with Hacking, Cloud, Hardening/Compliance, Threat Intelligence, and Automation teams.
  • Supervise critical and actively exploited vulnerabilities, including technical verification and closure.
  • Monitor SLAs, KPIs, and reporting while identifying automation and service improvement opportunities, including the safe use of AI.

Requirements

  • At least 5 years of cybersecurity experience, including significant Vulnerability Management experience.
  • Technical university degree or equivalent qualification.
  • Strong knowledge of the vulnerability lifecycle, risk-based prioritization, CVSS, EPSS, CISA KEV, and Threat Intelligence.
  • Experience with vulnerability scanning and management tools, preferably Qualys, plus knowledge of Windows, Linux, networking, applications, cloud, and container environments.
  • Experience with exploitation analysis, mitigations, compensating controls, SLA/KPI management, reporting, scripting, REST APIs, JSON, and automation.
  • Technical English at B2 level is recommended.

Nice to have

  • Security, Hardening/Compliance, or Pentesting experience.
  • Experience with Prisma Cloud, Qualys WAAS, or Burp Suite.
  • Knowledge of cybersecurity governance and risk.

Culture & Benefits

  • Hybrid work with flexible start and finish times.
  • Intensive working hours on Fridays and during the summer.
  • Personalized career development, training, and language learning support.
  • National and international mobility, with a relocation package available for candidates from other countries.
  • Flexible compensation, brand discounts, health, dental, and accident insurance, plus wellbeing programs.

Hiring process

  • Recruitment includes telephone and personal contact with the talent acquisition team, either face-to-face or online.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →