VIPR & VMDR Expert

Armis

France

Hybride

EUR 90 000 - 130 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Armis seeks a VIPR & VMDR Expert to architect, analyze, and operate vulnerability management and exploit intelligence across customer environments, infrastructure, SaaS ecosystems, and the Armis platform. You will lead how Armis detects, prioritizes, and responds to vulnerabilities, integrating threat intel with asset context to drive data-backed decisions and publish executive-ready insights.

Collaborate with Customer Success, Security Engineering, and Cloud Infrastructure teams to track

Qualifications

  • 6–10+ years of experience in Vulnerability Management, Threat Intelligence, or Security Detection Engineering.
  • Deep expertise in CVSS, CWE/CVE, NVD, KEV, and EPSS frameworks.
  • Hands-on experience with VM/detection platforms (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR, Centrix for VMDR).
  • Proven ability to develop automation scripts and data pipelines (Python, PowerShell, Bash, REST APIs, JSON).
  • Familiarity with RBVM and prioritization scoring models.
  • Strong cloud-native security knowledge (AWS, Azure, GCP).
  • Excellent communication across technical, management, and executive levels.

Responsabilités

  • Own the end-to-end vulnerability and detection lifecycle—from discovery to remediation and reporting.
  • Lead VIPR/VMDR function, integrating threat intel, exploit data, and asset context for decisions.
  • Correlate internal telemetry with external feeds to assess exploitability and exposure.
  • Operate and tune vulnerability and detection tools across hybrid environments.
  • Automate scoring, detection correlation, and reporting pipelines.

Connaissances

Vulnerability Management
Threat Intelligence
Security Detection Engineering
RBVM
Automation scripting
Data storytelling
Executive communication

Formation

Bachelor’s or Master’s degree in Information Security or Computer Science

Outils

Tenable
Qualys
Rapid7
Wiz
Prisma Cloud
ServiceNow VR
Centrix for VMDR

Description du poste

The VIPR & VMDR Expert serves as an architect,, strategic analyst and technical operator — combining vulnerability lifecycle management with exploit intelligence, detection automation, and cross-functional coordination (ITSM).

You’ll lead how Armis detects, prioritizes, and responds to vulnerabilities across customer environments, infrastructure, SaaS ecosystems, and the Armis platform — ensuring our customers stay ahead of emerging exploits, threats, and exposures.

Key Responsibilities
  • Own the end-to-end vulnerability and detection lifecycle — from discovery, triage, and prioritization through remediation and reporting.
  • Lead the Vulnerability Intelligence, Prioritization & Detection Response (VIPR/VMDR) function, integrating threat intel, exploit data, and asset context to drive data-backed decisions.
  • Correlate internal vulnerability telemetry with external feeds (NVD, CISA KEV, EPSS, Mandiant, Shodan, VulnDB, Centrix for Early Warning) to assess exploitability and exposure.
  • Operate and tune vulnerability and detection tools (e.g., Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR) across hybrid customer environments.
  • Automate vulnerability scoring, detection correlation, and reporting pipelines using Python, PowerShell, REST APIs, or automation rules within AMS/VIPR.
  • Partner with Customer Success, Security Engineering, and Cloud Infrastructure teams to track remediation SLAs, exposure metrics, and MTTR improvements.
  • Build and publish risk dashboards, customer-facing reports, and executive briefings using Splunk, Power BI, Elastic, or AMS/VIPR.
  • Develop and maintain the Armis Vulnerability Prioritization Model (VPM) — aligning exploit intelligence, CVSS/EPSS scoring, Armis Proprietary Risk Scoring, and business criticality to guide customer risk posture.
  • Support penetration test remediation, red team findings, and customer security audits.
  • Author weekly vulnerability intelligence reports, zero-day summaries, and leadership briefings for APJ/APAC stakeholders.
  • Collaborate with Product Security and Threat Intelligence teams to integrate vulnerability and detection data into Armis platform insights.
  • Deliver training sessions and enablement workshops for customers, engineers, and analysts on vulnerability trends, tools, and operational best practices.
Qualifications
  • 6–10+ years of experience in Vulnerability Management, Threat Intelligence, or Security Detection Engineering.
  • Deep expertise in CVSS, CWE/CVE, NVD, KEV, and exploit prediction (EPSS) frameworks.
  • Hands-on experience with vulnerability and detection management platforms (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR, Centrix for VMDR).
  • Proven ability to develop automation scripts and data pipelines (Python, PowerShell, Bash, REST APIs, JSON).
  • Familiarity with risk-based vulnerability management (RBVM) and prioritization scoring models.
  • Strong understanding of cloud-native security, container scanning, and hybrid infrastructure (AWS, Azure, GCP).
  • Exceptional data storytelling skills — turning technical findings into actionable executive insights.
  • Demonstrated ability to work independently and as part of a team.
  • Exceptional communication skills across all levels of technical, middle management, and executive leadership personnel.
  • Bachelor’s or Master’s degree in Information Security, Computer Science, or related discipline.
  • Previous experience operating in a "Voice of the Customer" (VoC) technical role directly embedded with Product Engineering pods.
  • A track record of mentoring senior technical staff (TCMs, TAMs, or Solutions Engineers) and developing scalable knowledge-sharing frameworks.
Preferred Experience
  • Prior experience in enterprise SaaS, cybersecurity, or customer-facing technical programs.
  • Familiarity with Armis Centrix™ or similar asset intelligence and exposure management tools.
  • Certifications such as CISSP, GCCC, GCTI, CEH, or CySA+.
  • Experience supporting compliance frameworks (SOC 2, ISO 27001, FedRAMP) in enterprise environments.
  • Strong cross-cultural communication and collaboration skills across global and regional teams (APJ/APAC).
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Application Security & VIPR Expert
Application Security & VIPR Expert

Armis • France

Sur place
EUR 110 000 - 160 000
Vulnerability Lifecycle & Detection Expert
Vulnerability Lifecycle & Detection Expert

Armis • France

Hybride
EUR 90 000 - 130 000
AppSec & VIPR Lead: Architect, Automate, Remediate
AppSec & VIPR Lead: Architect, Automate, Remediate

Armis • France

Sur place
EUR 110 000 - 160 000
Lead Vulnerability Expert (F/M)
Lead Vulnerability Expert (F/M)

Equans France • Courbevoie

Sur place
EUR 70 000 - 90 000
Vulnerability Operations Engineer (Cloud and Infrastructure) - Up to 700€ per day - Hybrid
Vulnerability Operations Engineer (Cloud and Infrastructure) - Up to 700€ per day - Hybrid

Hunter Bond • Auvergne-Rhône-Alpes

Sur place
EUR 77 000 - 129 000
Information Security Analyst
Information Security Analyst

RemoteLeads • France

Sur place
EUR 60 000 - 90 000
Prinicipal (L3) SOC Analyst
Prinicipal (L3) SOC Analyst

Integrity360 • Paris

Hybride
EUR 65 000 - 95 000
DevSecOps Engineer
DevSecOps Engineer

London Stock Exchange Group • France

Sur place
EUR 65 000 - 85 000
Cybersecurity Engineer
Cybersecurity Engineer

Jobtailor • Paris

Sur place
EUR 60 000 - 90 000
Senior Security Engineer
Senior Security Engineer

Xpandium Coberon Ltd • Eu

Hybride
EUR 70 000 - 90 000