Vulnerability Management Analyst
GMV · Tres Cantos, Spain
You apply off-site, with the employer or the job board. I never handle applications.
Vulnerability Management Analyst | Job Details
If you want to develop your career in cybersecurity, contributing to a large-scale Vulnerability Management service for a financial sector organization and working alongside specialized technical teams to reduce risk exposure, your place is with us.
We´ll get to the point; we'll tell you what's not on the web. If you want to know more about: GMV
WHAT CHALLENGE WILL YOU BE TAKING ON?
- You will join a specialized Vulnerability Management team, contributing to the continuous management of the vulnerability lifecycle across infrastructure, applications, Cloud and container environments.
Your main responsibilities will include:
- Analyzing, managing and tracking vulnerabilities from multiple sources, including the review of scanner results, false positives and duplicates.
- Correlating and enriching vulnerability information, prioritizing vulnerabilities based on risk and monitoring remediation activities.
- Monitoring SLA compliance, coordinating with the teams responsible for remediation and escalating critical or complex vulnerabilities.
- Verifying remediation, managing evidence and keeping operational information up to date.
- Preparing technical reporting and service indicators.
- Using and monitoring service automation, contributing to continuous improvement.
- You will work autonomously within a collaborative environment, coordinating with different technical teams and handling large volumes of information.
WHAT DO WE NEED IN OUR TEAM?
For this position, we are looking for a professional with at least 2 years of experience in cybersecurity, preferably in Vulnerability Management, and a Higher Vocational Training qualification or equivalent degree related to Computer Science or Cybersecurity.
You should have experience and knowledge of:
- Vulnerability Management, scanners and platforms such as Qualys or equivalent tools.
- CVSS and risk-based prioritization criteria.
- Windows, Linux, networking, web applications and IT infrastructure.
- Vulnerability interpretation, mitigations and vendor recommendations.
- Ticketing and tracking tools, as well as technical reporting and documentation.
Technical English is required, with a B2 level being recommended.
*
- We will value knowledge of CVSS v4.0, EPSS, CISA KEV, Prisma Cloud, Qualys WAAS, Burp Suite or equivalent tools, as well as experience in Cloud and container security, Hardening/Compliance, Threat Intelligence, Pentesting and technical vulnerability validation.
WHAT DO WE OFFER?
Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.
Flexible start and finish times, and intensive working hours Fridays and in summer.
Personalized career plan development, training and language learning support.
National and international mobility. Do you come from another country? We can offer you a relocation package.
Competitive compensation with ongoing reviews, flexible compensation and discount on brands.
Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!
- ️ In our recruitment processes you will always have telephone and personal contact, face-to-face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.
❤️ We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.
WHAT ARE YOU WAITING FOR? JOIN US
#LI-Hybrid