VIPR & VMDR Expert

Armis

Italia

Ibrido

EUR 120.000 - 160.000

Tempo pieno

14 giorni+

Ricevi più risposte dai datori di lavoro

Invia un CV specifico per questa offerta in pochi minuti.

Descrizione del lavoro

Armis is seeking a VIPR & VMDR Expert to architect, analyze and operate vulnerability lifecycle management with threat intel, detection automation, and cross-functional coordination. You will lead how Armis detects, prioritizes, and responds to vulnerabilities across customer environments, infrastructure, SaaS ecosystems, and the Armis platform.

You’ll partner with Product Security, Threat Intelligence, and Customer Success to track remediation SLAs, publish risk dashboards, and deliver

Competenze

  • Deep knowledge of CVSS, CWE/CVE, NVD, KEV, and EPSS frameworks.
  • Experience operating vulnerability and detection management platforms.
  • Ability to develop automation scripts and data pipelines (Python, PowerShell, Bash, REST APIs).
  • Strong understanding of RBVM and prioritization scoring models.
  • Experience with cloud-native security and hybrid infrastructure.

Mansioni

  • Own the end-to-end vulnerability and detection lifecycle from discovery to reporting.
  • Lead VIPR/VMDR function integrating threat intel, exploit data, and asset context.
  • Correlate internal telemetry with external feeds to assess exploitability.
  • Tune tools across hybrid customer environments (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud).
  • Automate scoring, detection correlation, and reporting pipelines.
  • Track remediation SLAs and exposure metrics with cross-functional teams.
  • Publish risk dashboards and executive briefings using Splunk/Power BI/Elastic.
  • Develop and maintain vulnerability prioritization models and risk scoring.
  • Support penetration testing remediation and security audits.
  • Deliver training and enablement on vulnerability trends and tooling.

Conoscenze

Vulnerability Management
Threat Intelligence
Security Detection Engineering
Automation scripting
RBVM
Cloud-native security

Formazione

Bachelor’s or Master’s degree in Information Security or Computer Science

Strumenti

Tenable
Qualys
Rapid7
Wiz
Prisma Cloud
ServiceNow VR
Centrix for VMDR

Descrizione del lavoro

The VIPR & VMDR Expert serves as an architect,, strategic analyst and technical operator — combining vulnerability lifecycle management with exploit intelligence, detection automation, and cross-functional coordination (ITSM).

You’ll lead how Armis detects, prioritizes, and responds to vulnerabilities across customer environments, infrastructure, SaaS ecosystems, and the Armis platform — ensuring our customers stay ahead of emerging exploits, threats, and exposures.

Key Responsibilities
  • Own the end-to-end vulnerability and detection lifecycle — from discovery, triage, and prioritization through remediation and reporting.
  • Lead the Vulnerability Intelligence, Prioritization & Detection Response (VIPR/VMDR) function, integrating threat intel, exploit data, and asset context to drive data-backed decisions.
  • Correlate internal vulnerability telemetry with external feeds (NVD, CISA KEV, EPSS, Mandiant, Shodan, VulnDB, Centrix for Early Warning) to assess exploitability and exposure.
  • Operate and tune vulnerability and detection tools (e.g., Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR) across hybrid customer environments.
  • Automate vulnerability scoring, detection correlation, and reporting pipelines using Python, PowerShell, REST APIs, or automation rules within AMS/VIPR.
  • Partner with Customer Success, Security Engineering, and Cloud Infrastructure teams to track remediation SLAs, exposure metrics, and MTTR improvements.
  • Build and publish risk dashboards, customer-facing reports, and executive briefings using Splunk, Power BI, Elastic, or AMS/VIPR.
  • Develop and maintain the Armis Vulnerability Prioritization Model (VPM) — aligning exploit intelligence, CVSS/EPSS scoring, Armis Proprietary Risk Scoring, and business criticality to guide customer risk posture.
  • Support penetration test remediation, red team findings, and customer security audits.
  • Author weekly vulnerability intelligence reports, zero-day summaries, and leadership briefings for APJ/APAC stakeholders.
  • Collaborate with Product Security and Threat Intelligence teams to integrate vulnerability and detection data into Armis platform insights.
  • Deliver training sessions and enablement workshops for customers, engineers, and analysts on vulnerability trends, tools, and operational best practices.
Qualifications
  • 6–10+ years of experience in Vulnerability Management, Threat Intelligence, or Security Detection Engineering.
  • Deep expertise in CVSS, CWE/CVE, NVD, KEV, and exploit prediction (EPSS) frameworks.
  • Hands-on experience with vulnerability and detection management platforms (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR, Centrix for VMDR).
  • Proven ability to develop automation scripts and data pipelines (Python, PowerShell, Bash, REST APIs, JSON).
  • Familiarity with risk-based vulnerability management (RBVM) and prioritization scoring models.
  • Strong understanding of cloud-native security, container scanning, and hybrid infrastructure (AWS, Azure, GCP).
  • Exceptional data storytelling skills — turning technical findings into actionable executive insights.
  • Demonstrated ability to work independently and as part of a team.
  • Exceptional communication skills across all levels of technical, middle management, and executive leadership personnel.
  • Bachelor’s or Master’s degree in Information Security, Computer Science, or related discipline.
  • Previous experience operating in a "Voice of the Customer" (VoC) technical role directly embedded with Product Engineering pods.
  • A track record of mentoring senior technical staff (TCMs, TAMs, or Solutions Engineers) and developing scalable knowledge-sharing frameworks.
Preferred Experience
  • Prior experience in enterprise SaaS, cybersecurity, or customer-facing technical programs.
  • Familiarity with Armis Centrix™ or similar asset intelligence and exposure management tools.
  • Certifications such as CISSP, GCCC, GCTI, CEH, or CySA+.
  • Experience supporting compliance frameworks (SOC 2, ISO 27001, FedRAMP) in enterprise environments.
  • Strong cross-cultural communication and collaboration skills across global and regional teams (APJ/APAC).
Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

VIPR/VMDR Architect & Threat Intelligence Lead
VIPR/VMDR Architect & Threat Intelligence Lead

Armis • Italia

Ibrido
EUR 120.000 - 160.000
Senior Cyber Incident Response Analyst
Senior Cyber Incident Response Analyst

Integrity360 • Italia

In loco
EUR 65.000 - 90.000
Network Security Specialist
Network Security Specialist

Jobtailor • Veneto

In loco
EUR 45.000 - 65.000
Vulnerability Governance Analyst, Italy
Vulnerability Governance Analyst, Italy

ION Group • Lombardia

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
International environment
Vulnerability Governance Analyst, Italy
Vulnerability Governance Analyst, Italy

ION Group • Milano

In loco
EUR 40.000 - 50.000
CCNL Metalmeccanico
Senior Incident Response Engineer
Senior Incident Response Engineer

Cacheflow • Milano

Ibrido
EUR 60.000 - 85.000
Staff Product Manager - AI SIEM, Detection and Response
Staff Product Manager - AI SIEM, Detection and Response

SentinelOne • Italia

In loco
EUR 90.000 - 130.000
RSUs
ESPP
Competitive leave
+6
Azure Cloud Infrastructure Lead — Security & DevOps
Azure Cloud Infrastructure Lead — Security & DevOps

Avanade Spain SL • Milano

In loco
Microsoft Technology Account Lead (MTAL)
Microsoft Technology Account Lead (MTAL)

Avanade Spain SL • Milano

In loco
Cyber Security Specialist
Cyber Security Specialist

Avvale • Turbigo

Ibrido
EUR 40.000 - 70.000
Flexibility in remote working
Training & development budget
Commitment to gender equality & inclusion