Vulnerability Response Senior SME – Cybersecurity & Risk Management
~18.2k - 22k PLN18 200 - 22 000 PLN/ mies.B2B
Brak informacji o wynagrodzeniu
SeniorFull-time·B2B·Umowa o pracę
#402195·Dodano 3 dni temu·0
Źródło: ITDSTech Stack / Keywords
cloud environmentsDASTload balancersNISTNVDSASTTenableTLSWAF
Firma i stanowisko
This role is within a Cybersecurity team safeguarding global financial services through vulnerability management, threat assessment, and security testing.
Wymagania
- Minimum 5 years of experience in IT Security or related fields.
- Expertise in reviewing and assessing high-severity vulnerabilities from NIST/NVD and vendor sources.
- Strong understanding of vulnerability types and attack techniques such as remote code execution, privilege escalation, and authentication bypass.
- Hands-on experience with vulnerability identification tools like Tenable, SAST, and DAST testing methodologies.
- Solid understanding of CI/CD pipelines including security testing and remediation integration.
- Experience in both on-premises and cloud environments.
- Technical skills across networking, application delivery, and security controls such as WAFs, load balancers, and TLS certificates.
- Excellent stakeholder management and strong written communication skills in English.
Nice to have:
- Certifications like CISSP, OSCP.
- Experience with regulatory or audit engagements in cybersecurity compliance.
Obowiązki
- Review critical and high-severity vulnerabilities from sources such as NIST/NVD and vendor advisories, providing clear impact summaries to stakeholders.
- Validate vulnerabilities by gathering technical evidence and confirm whether they pose true threats.
- Map vulnerabilities to assets and collaborate with service owners to identify impacted components.
- Recommend practical remediation measures including patches, configurations, and compensating controls.
- Produce technical reports detailing root causes, attack pathways, and mitigation strategies.
- Coordinate remediation efforts with infrastructure, platform, and application teams, tracking progress.
- Verify remediation effectiveness through re-scanning and validation testing.
- Support regulatory, audit, and governance requests with documentation and analysis.
- Assist operational teams with escalations and ad hoc cybersecurity activities as needed.
Benefity
- Hybrid work model: 4 days remote, 1 day office.
- Opportunity to work in global financial services cybersecurity.
- Career advancement in cybersecurity risk management and threat mitigation.
Inne informacje
Only candidates with an existing legal right to work in the European Union will be considered for this role.
ITDS
283 aktywne oferty