Vulnerability Response Senior SME

ALTEN

Kraków

On-site

PLN 180,000 - 260,000

Full time

21 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medicover medical care
Medicover Benefits platform
Medicover Sport card
Referral Program
Group life insurance
Layette for a newborn employee’s child

Job summary

ALTEN Polska is seeking an experienced IT Security professional to lead vulnerability management across our technology estate in Kraków. You will review critical and high-severity advisories, validate findings, map affected assets to owners, and coordinate remediation with cross-functional teams to ensure closure.

You will produce detailed technical write-ups, support governance submissions, and contribute to regulators and audits.

Qualifications

  • Proven experience reviewing and assessing critical/high-severity vulnerabilities from NIST/NVD and vendor advisories.
  • Translate technical findings into clear business impact for governance stakeholders.
  • Knowledge of vulnerability identification approaches and tooling (Tenable, SAST, DAST).

Responsibilities

  • Review critical/high-severity vulnerabilities and determine business impact.
  • Validate findings with evidence (versions, configs, logs, scan outputs).
  • Map vulnerabilities to assets with CMDB and service owners; maintain accurate risk lists.
  • Recommend remediation and mitigations with patches, upgrades, and hardening.
  • Produce technical write-ups with root cause, attack paths, and remediation steps.
  • Coordinate remediation with infrastructure, platform, and application teams to drive closure.
  • Track progress and escalate risks as needed.
  • Verify remediation effectiveness via re-scan or validation testing.

Skills

Vulnerability assessment
NIST/NVD advisories
Impact translation
SAST/DAST tooling
Tenable
CI/CD security
Networking fundamentals
Cloud and on-prem security
Stakeholder management
Technical writing
Governance reporting

Education

Bachelor’s degree in IT Security or related field

Tools

Tenable
SAST
DAST

Job description

  • Review critical and high-severity vulnerabilities published by sources such as NIST/NVD and vendor advisories, determine whether they affect our technology estate, and provide a clear impact summary to the business (what’s affected, how it could be exploited, and the likely risk/exposure).
  • Validate findings and confirm exposure by gathering technical evidence (versions, configurations, logs, scan output) to confirm true/false positives and refine the list of affected assets.
  • Map vulnerabilities to assets and ownership by working with CMDB / inventory sources and service owners to identify accountable teams and complete, accurate impacted-asset lists.
  • Recommend remediation and mitigations by proposing fixes and practical workarounds (patching, upgrades, configuration hardening, compensating controls) and outlining prerequisites, risks, and dependencies.
  • Produce high-quality technical write-ups including root cause, affected components, attack paths, business impact, and step-by-step remediation guidance suitable for technical teams and governance stakeholders.
  • Coordinate remediation execution by partnering with infrastructure, platform, and application teams to plan remediation activities, resolve blockers, and support delivery through to closure.
  • Track remediation progress and outcomes by maintaining status updates, timelines, and evidence of fix, and escalating delays or risks where required.
  • Verify remediation effectiveness by confirming closure via re-scan, validation testing, or evidence review, and documenting residual risk where full remediation isn’t immediately possible.
  • Contribute to and inform requests from Regulators, Internal/ External Audit, and 2LOD challenges/ Papers.
  • Supporting the commentary for routine governance submissions e.g. Cybersecurity Executive Committee Monthly Update, Risk Map, KCIs, KRIs.
  • Adhoc tasks as required; including support to CSAT operational activities, handling escalations and requests from any team or angle.
What you will bring to the role:
  • Proven experience reviewing and assessing critical/high-severity vulnerabilities from sources such as NIST/NVD and vendor advisories, translating technical findings into clear business impact.
  • Strong understanding of common vulnerability types and attack techniques (e.g., remote code execution, privilege escalation, authentication bypass) and how they apply across enterprise environments.
  • Understanding of vulnerability identification approaches and tooling, including Tenable and application security testing (SAST, DAST) and similar scanning solutions.
  • Good understanding of the CI/CD lifecycle and how security testing and remediation are integrated into build and release pipelines.
  • Solid technical foundation across networking and application delivery, including WAFs, load balancers, certificates/TLS, and how vulnerabilities manifest at different layers.
  • Experience working across on-prem and cloud environments, understanding typical architecture patterns and exposure points in each.
  • Practical knowledge of remediation approaches across infrastructure and applications, including patching, upgrades, configuration hardening, and compensating controls.
  • Strong stakeholder management skills, partnering with service owners, platform teams, application teams, and operations to confirm ownership and drive actions to closure.
  • Excellent written communication skills, producing structured technical write-ups and remediation guidance for both technical teams and governance audiences.
  • Organised and delivery focused.
  • Experience of working in roles within Cyber Security Operations, Risk Management, and Governance, within a mid to large enterprise or equivalent organization.
  • Minimum of 5 years of experience in IT Security or similar role.
We offer a full-time employment contract
  • Stable and long-term cooperation
  • Well-defined career path at the European leader in engineering & IT consulting
  • Opportunity to relocate and work in different ALTEN Polska branches
  • After completion of the project, opportunity to engage in a subsequent one within the company
  • Introduction and cooperation with dedicated Competences Manager
  • Medicover medical care
  • Medicover Benefits platform
  • Medicover Sport card
  • Referral Program
  • Layette for a newborn employee’s child
  • Group life insurance
We also guarantee:
  • Access to professional certifications with our technology partners (e.g. Google, ISTQB)
  • Access to relevant industry events
  • Access to the Knowledge Sharing Program
  • Access to Referral program
We also offer cooperation based on a B2B or Contract of mandate (UZ).

NOTICE: We kindly inform you that we will contact the selected people.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

(Cybersecurity) Information Protection Incident Manager
(Cybersecurity) Information Protection Incident Manager

ALTEN • Kraków

On-site
PLN 120,000 - 180,000
Medicover medical care
Medicover Benefits platform
Medicover Sport card
+3
Senior Penetration Tester
Senior Penetration Tester

ALTEN • Kraków

Hybrid
PLN 180,000 - 260,000
Medicover medical care
Medicover dental care
Medicover Benefits platform
+5
Principal Security Researcher
Principal Security Researcher

ALTEN • Kraków

On-site
PLN 180,000 - 240,000
Medicover medical care
Medicover dental care
Medicover Benefits platform
+5
Site Reliability Engineer
Site Reliability Engineer

ALTEN Polska • Kraków

On-site
PLN 180,000 - 250,000
Medicover medical care
Medicover Benefits platform
Medicover Sport card
+3
Scala Spark Developer
Scala Spark Developer

ALTEN Polska • Kraków

On-site
PLN 180,000 - 240,000
Medicover medical care
Medicover Benefits platform
Medicover Sport card
+3
Windows Expert - AI Defence Program
Windows Expert - AI Defence Program

ALTEN Polska • Warszawa

Hybrid
PLN 240,000 - 360,000
Medicover medical care
Medicover Benefits platform
Medicover Sport card
+3
Senior Cybersecurity Penetration Tester – Mobile, Web, Infrastructure
Senior Cybersecurity Penetration Tester – Mobile, Web, Infrastructure

ITDS Polska Sp. z o.o. • Kraków

Hybrid
PLN 180,000 - 260,000
Stable cooperation and good conditions
Developing expertise in financial行业
Social events and international环境
+4
Senior Solutions Architect
Senior Solutions Architect

ALTEN Polska • Poland

On-site
PLN 180,000 - 250,000
Medicover medical care
Medicover Benefits platform
Medicover Sport card
+4
Expert Application Security Specialist – Identity & Access Management
Expert Application Security Specialist – Identity & Access Management

ALTEN Polska • Warszawa

Hybrid
PLN 156,000 - 257,000
Full-time contract
Hybrid work model
Relocation opportunities
+1
Cybersecurity Operations Consultant
Cybersecurity Operations Consultant

EY (dawniej Ernst & Young) • Warszawa

Hybrid
PLN 180,000 - 320,000
Private healthcare
Life insurance
Work with enterprise-grade security
+3