We are looking for an experienced Senior Application Vulnerability Management Analyst to join the team responsible for developing and operationally managing the application vulnerability management process in a modern enterprise environment. You will be responsible for designing and maintaining vulnerability management processes, collaborating with development teams, DevOps, and security operations to improve vulnerability visibility and increase SLA compliance. If you are passionate about application security and want to make an impact on improving security within the organization, this opportunity is for you.
Your tasks
- Designing and maintaining application vulnerability management processes and remediation processes
- Analyzing and prioritizing vulnerabilities based on risk criteria such as CVSS, EPSS, exploitability, application criticality, data sensitivity, and production exposure
- Monitoring and classifying results from SAST, DAST, and Software Composition Analysis (SCA) tools
- Coordinating remediation efforts with development and DevOps teams, ensuring clear accountability
- Creating and managing workflows in Jira, tickets, deadlines, and escalation paths for security findings
- Tracking remediation SLAs, following up on overdue vulnerabilities, and coordinating risk acceptance or exception processes as needed
- Verifying remediation through re-scanning and validation actions before closure
- Developing operational dashboards, KPIs, and management reports regarding risk exposure, aging vulnerabilities, and remediation performance
- Automating security processes, including ticket generation, assigning responsibilities, notifications, SLA tracking, reporting, and re-scanning
- Driving continuous improvements in vulnerability management processes, automation capabilities, scanning coverage, and developer engagement
Requirements
- Minimum of 5 years of experience in Cyber Security, Application Security, or Vulnerability Management
- Practical knowledge of application vulnerability management and remediation processes
- Previous work with SAST, DAST, SCA tools, and Snyk-class platforms
- Strong knowledge of DevSecOps, SDLC, and CI/CD processes
- Ability to assess risk using CVSS, EPSS metrics, and business criteria
- Experience working with Jira and coordinating efforts between technical teams
- Knowledge of security process automation and reporting
- Very good command of English - minimum B2 level
- Knowledge of Polish and residing in Poland
Job no. JOB-2YB6R
Sii ensures that all hiring decisions are made solely on the basis of qualifications and competence. We are committed to equal and fair treatment of all, regardless of legally protected characteristics. At Sii, we promote a diverse and inclusive work environment, in full compliance with applicable anti-discrimination laws.
Benefits For You
- Great Place to Work
- Solid financial situation
- Contracts with the biggest brands
- Centre of internal trainings
- Many experts you can learn from
- Open and accessible management team
- Profit sharing
- Passion Sponsorship program
- Regular integration events and trips
- Comfortable and well-equipped offices
- MySii app
- Medical care