We’re looking for motivated, engaged people to help make everyone’s journeys better.
Job summary:
Reporting to the Global Manager IT Security Operations, the IT Security Vulnerability Management Specialist is responsible for leading and managing the organization’s vulnerability management lifecycle. This includes identifying, classifying, prioritizing, remediating, and reporting vulnerabilities across IT and OT environments.
The role ensures continuous security improvement through collaboration with IT, development, operations, business and risk teams, aligning with the organization’s risk appetite and compliance mandates. The ideal candidate is both a strategic thinker and a hands-on executor with deep technical expertise and a strong understanding of business impact.
Main Duties and Responsibilities:
The IT Security Vulnerability Management Specialist will develop, maintain, or support an intelligence capability to anticipate and identify current and emerging security risks to the organization. The IT Vulnerability Management specialist will:
Vulnerability Management Operations
- Lead the end-to-end vulnerability management process, including scanning, identification, triage, and reporting.
- Coordinate with infrastructure, cloud, and application teams to remediate vulnerabilities in a timely and risk-informed manner.
- Maintain and tune vulnerability scanning tools to ensure accurate detection and comprehensive coverage.
- Establish SLAs for vulnerability remediation based on criticality, and track compliance.
Threat Intelligence Integration
- Work with threat intelligence teams to assess exploitability and real-world threat context of identified vulnerabilities.
- Integrate CVE and threat feeds (e.g., CISA KEV, NVD, vendor advisories) into the prioritization model.
Risk & Compliance Alignment
- Ensure vulnerability management processes align with security policies, ISO/IEC 27001, NIST 800-53, and regulatory requirements.
Core Competencies and Requirements:
- Bachelor's or master's degree in IT, engineering, business, management or a related field, or equivalent work experience
- Tertiary qualifications in information or security, or industry qualifications such as Offensive Security Certified Professional (OSCP), GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), CERT Incident Response Process Professional Certificate, or EC-Council Certified Incident Handler (ECIH)
- Minimum 3 years of experience in cybersecurity, with at least 1 year in vulnerability management or threat/risk analysis roles.
- Hands-on experience with enterprise vulnerability scanning tools and ticketing systems.
- Proven track record managing complex remediation across hybrid IT environments (on-prem, cloud, containers).