We are seeking a Junior Vulnerability Management Analyst to support vulnerability management operations within a complex enterprise IT environment. The successful candidate will be responsible for identifying, assessing, prioritizing, and tracking security vulnerabilities across infrastructure, endpoints, networks, and cloud environments. The role requires close collaboration with infrastructure, network, cloud, and application teams to ensure timely remediation and continuous improvement of security posture.
Your daily tasks:
- Support vulnerability management operations within a complex enterprise IT environment.
- Analyze, assess, and prioritize security vulnerabilities based on technical severity and business impact.
- Manage vulnerability tickets and ensure timely resolution and tracking.
- Coordinate remediation activities with infrastructure, server, endpoint, network, and cloud teams.
- Monitor patching activities and follow up on remediation progress.
- Maintain vulnerability management dashboards, reports, and operational metrics.
- Support KPI and SLA monitoring related to vulnerability management processes.
- Ensure asset inventory and vulnerability data are accurate and up to date.
- Assist with regulatory and compliance requirements, including DORA, NIS2, and ISO 27001 audits.
- Contribute to the continuous improvement of vulnerability management processes and procedures
Our requirements:
- Minimum 2 years of experience in Cyber Security, IT Operations, or Vulnerability Management.
- Good understanding of vulnerability management processes and best practices.
- Knowledge of CVE, CVSS, and vulnerability assessment methodologies.
- Experience working with Windows and Linux environments.
- Experience with ticketing systems and IT Service Management (ITSM) processes.
- Strong analytical and problem-solving skills.
- English at B2 level or higher.
Nice to have:
- German language skills (A1/A2 or higher) are considered an advantage
- Experience with vulnerability management tools such as Tenable, Qualys, Rapid7, Microsoft Defender, Raynet, or Versio.io.
- ITIL knowledge or certification.
- Experience in patch management.
- Understanding of CMDB and IT asset management principles.
- Previous experience in highly regulated industries such as banking, insurance, or financial services.
- Knowledge of Microsoft Azure and virtualization environments.
What we offer:
- Hybrid working model (2 days in the office from our Warsaw office, 3 days remote per week)
- Competitive salary with annual salary reviews
- Opportunity to use foreign languages and the newest technologies on a daily basis
- Access to MyBenefit platform where you can choose from a variety of benefits (Sport, Tourism, Culture, Recreation etc.)
- Sport's card (Multisport)
- Private medical care for you and your family
- Access to wide range of learning & development platforms