Vulnerability Management Analyst

Salt Digital Recruitment

Dubai

On-site

AED 167,400 - 279,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Salt Digital Recruitment is seeking a Vulnerability Management Analyst in Dubai. This role involves managing the end-to-end vulnerability lifecycle across a complex enterprise environment, working closely with security tooling and infrastructure teams. Candidates should have a strong technical background in vulnerability management and excellent communication skills.

The ideal applicant will have a minimum of 3 years' experience and be familiar with tools like Tenable.sc and Rapid7. This position offers an opportunity to lead governance sessions and improve vulnerability management processes.

Qualifications

  • Minimum 3+ years of hands-on vulnerability management experience.
  • Strong understanding of vulnerability prioritisation methodologies.
  • Familiarity with NIST CSF 2.0, ISO 27001, and UAE IA Regulation.

Responsibilities

  • Consolidate vulnerability findings into a prioritised backlog.
  • Produce weekly and monthly vulnerability management reports.
  • Host remediation and governance sessions with technical stakeholders.

Skills

Vulnerability management
Scripting (Python, Bash, PowerShell)
Communication skills
Stakeholder management

Education

Relevant industry certifications (CISSP, GCIH, OSCP, CCSP)

Tools

Tenable.sc
Rapid7
GitLab Secure
Jira
ServiceNow

Job description

Overview

Cybersecurity | Vulnerability Management We are currently supporting a major enterprise client in Abu Dhabi that is looking to hire an experienced Vulnerability Management Analyst to take ownership of the end-to-end vulnerability management lifecycle across a complex enterprise environment. This is a highly operational and business-critical role focused on transforming raw vulnerability data into measurable risk reduction. The successful candidate will act as the central coordination point between security tooling, infrastructure teams, cloud teams, application owners, and remediation stakeholders to ensure vulnerabilities are prioritised, tracked, governed, and resolved effectively.

Key Responsibilities
  • Consolidate vulnerability findings from multiple security platforms into a single prioritised remediation backlog
  • Prioritise vulnerabilities using CVSS, EPSS, KEV catalog data, threat intelligence, exploitability, and asset criticality
  • Assign findings to infrastructure, application, and cloud owners and track remediation activities through to closure
  • Escalate overdue remediation items and ensure SLA adherence across teams
  • Host weekly remediation and governance sessions with technical stakeholders
  • Produce weekly and monthly vulnerability management reports including: Open vs closed findings, Vulnerability aging analysis, SLA adherence metrics, Trend analysis, Top recurring issues and offenders
  • Manage exception workflows for vulnerabilities that cannot be remediated within agreed timelines
  • Ensure all approved exceptions are documented, time-bound, and audit-ready
  • Feed residual risks and unresolved findings into the enterprise Risk Register
  • Support continuous improvement initiatives across vulnerability management processes and reporting
What We're Looking For
Technical Experience
  • Minimum 3+ years of hands-on vulnerability management experience
  • Strong experience with: Tenable.sc, Rapid7, GitLab Secure, Jira and/or ServiceNow
  • Strong understanding of: Vulnerability prioritisation methodologies, CVSS scoring, EPSS, CISA KEV catalog, threat intelligence-driven remediation
  • Experience working across infrastructure, cloud, and application security environments
  • Strong scripting and automation skills using Python, Bash, or PowerShell
Security & Governance Knowledge
  • Familiarity with: NIST CSF 2.0, ISO 27001, MITRE ATT&CK, UAE IA Regulation
  • Understanding of remediation governance, exception handling, and audit readiness
  • Experience managing security metrics, reporting, and SLA tracking
Certifications
  • Relevant industry certifications are highly desirable, including: CISSP, GCIH, OSCP, CCSP
Soft Skills
  • Excellent written and verbal communication skills
  • Ability to engage effectively with both technical teams and senior leadership
  • Strong organisational and stakeholder management capability
  • High attention to detail with a proactive and accountable mindset
Key Objectives
  • Achieve and maintain remediation SLA targets across all severity levels
  • Eliminate vulnerability backlog growth through effective remediation governance
  • Provide leadership with a single, accurate source of truth for enterprise vulnerability posture
  • Ensure all critical vulnerabilities are either remediated or formally exception-approved within defined timelines
  • Build sustainable vulnerability management processes with measurable operational improvement

Salt is acting as an Employment Business in relation to this vacancy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Lead: Risk & Remediation Governance
Vulnerability Management Lead: Risk & Remediation Governance

Salt Digital Recruitment • Dubai

On-site
AED 167,400 - 279,000
Rapid7 Vulnerability Management Engineer
Rapid7 Vulnerability Management Engineer

VaporVM • United Arab Emirates

On-site
AED 200,000 - 360,000
Cybersecurity Specialist
Cybersecurity Specialist

Hamdan Bin Mohammed Smart University • Dubai

On-site
AED 250,000 - 380,000
Senior Manager - Cyber Security Engineers (Ref: 197823)
Senior Manager - Cyber Security Engineers (Ref: 197823)

Forsyth Barnes • Abu Dhabi

On-site
AED 520,000 - 860,000
Competitive compensation
Career growth opportunities
Exposure to AI risk and security tools
Senior Security Engineer – Vulnerability Management
Senior Security Engineer – Vulnerability Management

Deriv • Dubai

On-site
AED 164,000 - 328,000
Information Security Consultant
Information Security Consultant

United Al Saqer Group • Abu Dhabi

On-site
AED 180,000 - 260,000
Cyber Security Specialist
Cyber Security Specialist

Hamdan Bin Mohammed Smart University • Dubai

On-site
AED 180,000 - 320,000
Network & Systems Engineer (Vulnerability Management)
Network & Systems Engineer (Vulnerability Management)

gruve • Dubai

On-site
AED 240,000 - 360,000
Cyber Security Specialist
Cyber Security Specialist

جامعة حمدان بن محمد الذكية • Dubai

On-site
AED 180,000 - 240,000
Information Security Specialist
Information Security Specialist

Client of AIQU • Dubai

On-site
AED 180,000 - 240,000