Vulnerability Management Consultant

Andersen Lab

Polska

On-site

PLN 140,000 - 210,000

Full time

4 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Private health insurance
Sports compensation
Mentoring programs

Job summary

Andersen Lab is seeking a Vulnerability Management Consultant to strengthen cybersecurity in a complex, multi-tenant environment. You will manage end-to-end vulnerability processes, coordinate remediation across multiple client teams, and advise on patching and hardening baselines.

The role requires 5+ years in cybersecurity with 3+ years in vulnerability management, hands-on experience with enterprise scanners, and strong risk-based prioritization skills.

Qualifications

  • 5+ years in cybersecurity with a focus on vulnerability management
  • Hands-on with enterprise scanning platforms (Nessus, Qualys, Rapid7, MD VM)
  • Ability to prioritize vulnerabilities using CVSS/EPSS and asset criticality
  • Experience coordinating remediation across multiple teams and SLAs

Responsibilities

  • Run and improve end-to-end vulnerability management lifecycle: discovery, scan, prioritize, remediate, verify
  • Configure and operate vulnerability scanning tools across infrastructure, cloud, and web apps
  • Prioritize based on risk using CVSS/EPSS and asset criticality
  • Coordinate remediation with IT, app, and infra owners across client organizations
  • Manage exceptions and track SLA compliance
  • Produce KPI/KRI reports for technical and management audiences
  • Advise on patch management, CIS benchmarks, and attack surface reduction

Skills

Vulnerability management
Threat intelligence
Risk-based prioritization
Patch management
Coordination across teams
English communication

Tools

Nessus/Tenable.io/Tenable.sc
Qualys VMDR
Rapid7 InsightVM
Microsoft Defender Vulnerability Management

Job description

Andersen is hiring a Vulnerability Management Consultant for a project strengthening cybersecurity, managing vulnerabilities, and protecting critical systems in an international environment.


The customer is a large international organization that relies on modern technology and digital solutions to support its operations. Its activities involve secure IT infrastructure, data management, digital services, and the adoption of emerging technologies to improve operational efficiency and reliability.


The project is focused on providing cybersecurity and digital services for international organizations within a complex multi-tenant environment. It includes cyber defense operations, security incident management, and continuous protection of critical systems and services to ensure secure and reliable operations worldwide.


Responsibilities:


  • Running and improving the end-to-end vulnerability management process: discovery, scanning, prioritization, remediation tracking and verification.
  • Configuring and operating vulnerability scanning tools for infrastructure, cloud and web applications.
  • Prioritizing vulnerabilities by risk, using CVSS, EPSS, exploitability, threat intelligence and asset criticality.
  • Coordinating remediation with IT, application and infrastructure owners across multiple client organizations.
  • Managing exceptions and risk acceptance, and track SLA compliance.
  • Producing KPI/KRI reports and dashboards for technical and management audiences.
  • Advising on patch management, hardening baselines (e.g. CIS Benchmarks) and attack surface reduction.

Must-haves:


  • Experience in cybersecurity for 5+ years, including 3+ years in vulnerability management.
  • Hands-on experience with at least one enterprise scanning platform (Tenable Nessus/Tenable.io/Tenable.sc, Qualys VMDR, Rapid7 InsightVM or Microsoft Defender Vulnerability Management).
  • Risk-based prioritization (CVSS, EPSS, CISA KEV, asset criticality).
  • Experience coordinating remediation across multiple teams and tracking SLAs.
  • Knowledge of patch management for Windows, Linux and network devices, and of hardening standards (CIS).
  • Clean record, ready for background verification.
  • Level of English – from Upper-Intermediate and above.

Nice to haves:


  • Cloud security posture management (e.g. Defender for Cloud, Wiz, Prisma Cloud).
  • Web application and container scanning.
  • Attack surface management tools.
  • Knowledge of ISO 27001 or NIST CSF.
  • Scripting (Python, PowerShell) for reporting automation and API integrations.
  • Certifications: CISSP, CompTIA Security+ or CySA+, vendor certifications (Tenable, Qualys).

Reasons why this job would be interesting to you:


  • Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
  • The opportunity to change the project and/or develop expertise in an interesting business domain.
  • Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
  • The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
  • Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
  • Referral program.
  • Private health insurance and sports compensation, depending on the type of employment.

Your personal data is protected in accordance with GDPR regulations. Learn more: https://andersenlab.com/privacy-policy/pl

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Tester
Penetration Tester

Andersen Lab • Polska

Hybrid
PLN 120,000 - 190,000
Private health insurance
Sports compensation
Remote/hybrid work options
DevSecOps Architect / Technical Lead
DevSecOps Architect / Technical Lead

DOU Polska • Warszawa

Hybrid
PLN 180,000 - 280,000
Private health insurance and sports
Certification compensation
Referral program
+2
SSIEM Administrator / Engineer
SSIEM Administrator / Engineer

Andersen Lab • Kraków

On-site
PLN 180,000 - 240,000
Private health insurance
Sports compensation
Mentoring program
+2
Senior Vulnerability Management Consultant
Senior Vulnerability Management Consultant

Andersen Lab • Polska

On-site
PLN 140,000 - 210,000
Private health insurance
Sports compensation
Mentoring programs
Cyber Security Consultant
Cyber Security Consultant

DCG • Gdynia

On-site
PLN 90,000 - 130,000
Private medical care
Sports card co-financing
Dedicated consultant support
Junior Vulnerability Management Analyst
Junior Vulnerability Management Analyst

Tata Consultancy Services • Warszawa

Hybrid
PLN 70,000 - 90,000
Hybrid working model (2 days in-office
3 days remote per week
Competitive salary with annual reviews
+3
Senior Vulnerability Management Specialist
Senior Vulnerability Management Specialist

Antal Poland • Kraków

Hybrid
PLN 180,000 - 280,000
Hybrid working model
Lux Med private medical care
Contractor Care specialist
+1
Vulnerability Management Analyst & Automation specialist
Vulnerability Management Analyst & Automation specialist

Euroclear • Poland

On-site
PLN 120,000 - 170,000
Vulnerability Management Analyst & Automation specialist
Vulnerability Management Analyst & Automation specialist

Euroclear • Polska

Hybrid
PLN 180,000 - 240,000
Vulnerability Management Analyst & Automation specialist
Vulnerability Management Analyst & Automation specialist

Euroclear • Województwo małopolskie

On-site
PLN 60,000 - 80,000