Vulnerability Management Specialist
Full-time Mid-Senior LevelJob Overview
As part of the Corporate Cybersecurity team, the Vulnerability Management Specialist will play a key role in strengthening and continuously improving the organization's cybersecurity posture.
This position offers a broad and transversal view of the IT landscape, working closely with IT teams, Cybersecurity teams, business stakeholders, and external security partners. The successful candidate will contribute to identifying, assessing, prioritizing, and driving the remediation of vulnerabilities across the organization, ensuring compliance with security standards and reducing cyber risk.
Key Responsibilities
Vulnerability Management
- Ensure all eligible assets are covered by vulnerability management tools and processes.
- Monitor the execution and success of vulnerability scans across the infrastructure.
- Analyze vulnerability assessment results, evaluate associated risks, and prioritize remediation activities.
- Collaborate with IT and infrastructure teams to define remediation plans and track implementation.
- Monitor compliance with vulnerability remediation targets and escalation procedures.
- Produce regular reports and dashboards on vulnerability exposure, remediation progress, and risk trends.
Patch Management Oversight
- Analyze security advisories and critical patch announcements to identify impacted systems and environments.
- Coordinate with relevant stakeholders to ensure the timely deployment of critical security patches.
- Monitor patch deployment progress and follow up on delayed remediation actions.
- Escalate high-risk situations where critical vulnerabilities remain unresolved.
- Prepare and communicate status reports to management and key stakeholders.
Penetration Testing Coordination
- Coordinate and oversee penetration testing activities.
- Ensure penetration tests are planned, executed, and documented according to internal security standards.
- Review penetration testing findings and support risk-based prioritization of remediation actions.
- Monitor remediation progress and validate the closure of identified vulnerabilities.
- Ensure the quality and effectiveness of services delivered by external penetration testing providers.
Secure Code Review Monitoring
- Ensure eligible applications are covered by approved code review and application security testing tools.
- Monitor the execution and effectiveness of automated and manual code reviews.
- Review identified vulnerabilities and coordinate remediation efforts with development teams.
- Contribute to the continuous improvement of Secure Development Lifecycle (SDLC) practices.
Reporting & Stakeholder Management
- Produce regular and ad hoc reports related to vulnerability management, penetration testing, patch management, and application security activities.
- Present findings, risks, and remediation progress to both technical and non-technical stakeholders.
- Facilitate discussions and meetings with internal teams, security specialists, and external providers.
- Support cybersecurity governance initiatives and continuous improvement programs.
Make Your Resume Now