(Cybersecurity) Vulnerability Response Senior SME
Brak informacji o wynagrodzeniu
SeniorFull-time
#444564·Dodano wczoraj·0
Źródło: nofluffjobs.comTech Stack / Keywords
SecurityCybersecurityVulnerability ManagementCI/CDSASTDASTWAFsLoad balancersStakeholder managementCommunication skillsOrganizational skills
Firma i stanowisko
This role is within a cybersecurity team at Antal in Kraków, Poland, focusing on vulnerability management in a large-scale technology environment.
Wymagania
- 5+ years of experience in IT Security, Cybersecurity, Vulnerability Management, or related area.
- Proven experience assessing and responding to critical and high-severity vulnerabilities.
- Strong understanding of common vulnerability types and attack techniques including remote code execution, privilege escalation, authentication bypass.
- Experience with vulnerability identification and assessment tools, ideally including Tenable.
- Understanding of application security testing approaches such as SAST and DAST.
- Good understanding of CI/CD processes and integration of security testing in software development pipelines.
- Solid technical knowledge of networking and application delivery technologies including WAFs, load balancers, certificates, and TLS.
- Understanding of security risks across on-premises and cloud environments.
- Practical knowledge of vulnerability remediation including patching, upgrades, configuration hardening, and compensating controls.
- Strong stakeholder management and communication skills, able to explain technical topics to diverse audiences.
- Strong organizational skills and delivery-focused approach.
- Experience in cybersecurity operations, risk management, or security governance in medium or large enterprise.
- Ability to work effectively in hybrid and remote environments.
Obowiązki
- Review critical and high-severity vulnerabilities identified through sources such as NIST/NVD, vendor advisories, and security scanning tools.
- Assess whether vulnerabilities affect the technology environment and communicate their potential impact, exploitability, and risk clearly.
- Validate vulnerability findings using software versions, configurations, logs, and scan results.
- Identify affected assets and coordinate with technical teams to establish ownership and scope.
- Recommend remediation and mitigation approaches including patching, upgrades, configuration changes, and compensating controls.
- Prepare technical documentation covering root cause, affected components, attack paths, business impact, and remediation.
- Coordinate remediation activities with infrastructure, cloud, platform, and application teams.
- Track remediation progress, identify blockers, and escalate risks or delays.
- Verify successful remediation via rescanning, validation testing, or evidence review.
- Assess and document residual risk if full remediation is not immediately possible.
- Support cybersecurity governance including risk reporting, management updates, and security metrics.
- Contribute to audit and regulatory request responses.
- Support cybersecurity operational activities, escalations, and vulnerability-related ad-hoc requests.
Benefity
- B2B contract.
- Hybrid working model with 6 days per month from Kraków office.
- Lux Med private medical care.
- MyBenefit cafeteria.
- Support from dedicated Contractor Care specialist.
- Opportunity to work on complex cybersecurity and vulnerability management challenges in a large-scale environment.
Opieka zdrowotna
Inne informacje
Location requirement: Kraków, Poland, hybrid role with office presence 6 days per month.
Antal
944 aktywne oferty