EU remote
Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector
About this role
Integration into a Threat Operations team, with responsibilities within the organization's Vulnerability Management Program, including vulnerability identification, prioritization, remediation SLA definition and tracking, and reporting. Manage the vulnerability lifecycle across infrastructure and endpoints, including analysis, prioritization (CVE, CVSS, KEV, exploitability, business context), and definition of remediation SLAs.
Monitor and validate remediation or mitigation processes, identify SLA breaches, perform follow-ups, and escalate issues to the appropriate teams or management levels. Identify and monitor vulnerabilities within development pipelines (SSDLC), in coordination with the AppSec team. Assess and monitor the risk associated with technology obsolescence (End-of-Life / End-of-Support) across systems, applications, and components.
Identify and analyze security findings across cloud environments, containers, and images, in collaboration with AppSec and Cloud Security teams. Critically validate the results generated by security tools, investigating false positives and confirming vulnerabilities. Ensure adequate coverage of the vulnerability management platform across the asset estate, in coordination with Infrastructure and Workplace teams. Produce vulnerability dashboards, KPIs, and reporting, including weekly status updates on critical vulnerabilities and remediation SLAs for management.
Automate, document, and standardize operational procedures within the Vulnerability Management Program. Vulnerability Management Fundamental knowledge of Vulnerability Management concepts, including CVE, CVSS, KEV, exploitability, severity, prioritization, and remediation. Experience defining SLAs, monitoring remediation activities, conducting follow-ups, and escalating issues. Knowledge of technology obsolescence (EOL/EOS) and associated risk assessment.
Experience creating dashboards and reports, with the ability to define and interpret KPIs. Knowledge of cloud security and cloud resources, including security findings analysis. Knowledge of container and container image vulnerabilities. Familiarity with the Secure Software Development Lifecycle (SSDLC) and SCA/SAST concepts. A critical approach to security tool results, with the ability to validate findings rather than assuming they are automatically accurate.