6 часов назад
Cybersecurity Engineer (Vulnerability Management)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cybersecurity Engineer (Vulnerability Management): Leading vulnerability management for a large-scale financial-sector service across infrastructure, applications, cloud, and container environments with an accent on risk-based prioritization, remediation, and technical coordination. Focus on analyzing critical and actively exploited vulnerabilities, defining compensating controls, monitoring SLAs and KPIs, and improving automation with supervised AI use.
Location: Hybrid in Tres Cantos, Madrid, Spain; includes up to 8 weeks per year of teleworking outside the usual geographical area.
Company
provides a large-scale Vulnerability Management service for an organization in the financial sector.
What you will do
- Act as the technical reference for Vulnerability Management operations and resolve technical escalations.
- Perform advanced vulnerability analysis and risk-based prioritization using CVSS, EPSS, CISA KEV, exposure, criticality, and Threat Intelligence.
- Define and monitor remediation activities, mitigations, and compensating controls.
- Coordinate with Hacking, Cloud, Hardening/Compliance, Threat Intelligence, and Automation teams.
- Supervise critical and actively exploited vulnerabilities, including technical verification and closure.
- Monitor SLAs, KPIs, and reporting while identifying automation and service improvement opportunities, including the safe use of AI.
Requirements
- At least 5 years of cybersecurity experience, including significant Vulnerability Management experience.
- Technical university degree or equivalent qualification.
- Strong knowledge of the vulnerability lifecycle, risk-based prioritization, CVSS, EPSS, CISA KEV, and Threat Intelligence.
- Experience with vulnerability scanning and management tools, preferably Qualys, plus knowledge of Windows, Linux, networking, applications, cloud, and container environments.
- Experience with exploitation analysis, mitigations, compensating controls, SLA/KPI management, reporting, scripting, REST APIs, JSON, and automation.
- Technical English at B2 level is recommended.
Nice to have
- Security, Hardening/Compliance, or Pentesting experience.
- Experience with Prisma Cloud, Qualys WAAS, or Burp Suite.
- Knowledge of cybersecurity governance and risk.
Culture & Benefits
- Hybrid work with flexible start and finish times.
- Intensive working hours on Fridays and during the summer.
- Personalized career development, training, and language learning support.
- National and international mobility, with a relocation package available for candidates from other countries.
- Flexible compensation, brand discounts, health, dental, and accident insurance, plus wellbeing programs.
Hiring process
- Recruitment includes telephone and personal contact with the talent acquisition team, either face-to-face or online.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
1 день назад
Penetration Tester (Cybersecurity)
42 000 - 70 000€
4 дня назад
Infrastructure Security Engineer
42 800 - 77 000€
2 дня назад
Risk Technology Risk & Cybersecurity Specialist III (Cybersecurity)
4 дня назад
Senior Platform Security Engineer (AI)
1 день назад
Senior IT Risk Officer (Cybersecurity)
2 дня назад