Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector

Devoteam | Cyber Trust

Porto

Presencial

EUR 42 000 - 70 000

Tempo integral

Há 9 dias
Gerador de candidaturas

Uma candidatura feita para esta oferta — um currículo e uma carta de apresentação personalizados que vão ao encontro do anúncio.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Career development
Diversity & inclusion
Open to disabilities

Resumo da oferta

Devoteam Cyber Trust is seeking a Vulnerability Management Specialist to join our Threat Operations team. You will lead the vulnerability lifecycle across infrastructure and endpoints, prioritizing findings by CVE, CVSS, and business impact.

You will define remediation SLAs, monitor progress, and coordinate with AppSec, Cloud Security, and development teams to reduce risk. Strong analytical skills and clear communication are essential.

Qualificações

  • Fundamental knowledge of Vulnerability Management concepts (CVE, CVSS, KEV) and remediation.
  • Experience defining SLAs, monitoring remediation activities, conducting follow-ups, and escalating issues.
  • Knowledge of technology obsolescence (EOL/EOS) and associated risk assessment.
  • Experience creating dashboards and reports, with the ability to define and interpret KPIs.
  • Knowledge of cloud security and cloud resources, including security findings analysis.
  • Knowledge of container and container image vulnerabilities.
  • Familiarity with the SSDLC and SCA/SAST concepts.
  • Critical approach to security tool results, validating findings rather than accepting them at face value.

Responsabilidades

  • Manage the vulnerability lifecycle across infrastructure and endpoints, including analysis, prioritization (CVE, CVSS, KEV, exploitability, business context), and remediation SLAs.
  • Monitor and validate remediation or mitigation processes, identify SLA breaches, and elevate issues as needed.
  • Identify and monitor vulnerabilities within development pipelines (SSDLC), in coordination with AppSec.
  • Assess risk from technology obsolescence (EOL/EOS) across systems and components.
  • Identify and analyze security findings across cloud environments, containers, and images with AppSec and Cloud Security teams.
  • Critically validate security tool results, investigate false positives, and confirm true vulnerabilities.
  • Ensure coverage of the vulnerability management platform across the asset estate in coordination with Infrastructure.
  • Produce vulnerability dashboards, KPIs, and weekly status updates for management.
  • Automate, document, and standardize operational procedures within the Vulnerability Management Program.

Conhecimentos

Vulnerability Management
SLAs & remediation
KPI dashboards
Cloud security
SSDLC / SCA/SAST
Container security
Windows & Linux
Networking basics
Communication
Prioritization

Ferramentas

Tenable One
CrowdStrike FEM
Azure
Google Cloud
SCA/SAST tools
IaC scanning tools

Descrição da oferta de emprego

Devoteam Cyber Trust is the specialized cybersecurity unit of the Devoteam Group. With over 800 experts across the EMEA region, our mission is to position cybersecurity as a business enabler, not a barrier. We take a comprehensive approach to Cyber Resilience, Applied Security, and Security Service Management to safeguard the digital journey of large and mid-sized enterprises across all sectors and industries. Since 2009, previously known as INTEGRITY, our Portugal-based team has specialized in delivering cutting-edge Managed Security Services. By combining expertise with proprietary technology, we consistently and effectively reduce our clients' cyber risk. Our wide range of services includes Persistent Penetration Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. Certified in ISO 27001 (Information Security) and ISO 9001 (Quality), PCI-QSA, and members of CREST and CIS (Center for Internet Security), we serve a significant number of clients in over 20 countries.

Job Description

Integration into a Threat Operations team, with responsibilities within the organization's Vulnerability Management Program, including vulnerability identification, prioritization, remediation SLA definition and tracking, and reporting.

  • Manage the vulnerability lifecycle across infrastructure and endpoints, including analysis, prioritization (CVE, CVSS, KEV, exploitability, business context), and definition of remediation SLAs.
  • Monitor and validate remediation or mitigation processes, identify SLA breaches, perform follow‑ups, and elevate issues to the appropriate teams or management levels.
  • Identify and monitor vulnerabilities within development pipelines (SSDLC), in coordination with the AppSec team.
  • Assess and monitor the risk associated with technology obsolescence (End-of-Life / End-of-Support) across systems, applications, and components.
  • Identify and analyze security findings across cloud environments, containers, and images, in collaboration with AppSec and Cloud Security teams.
  • Critically validate the results generated by security tools, investigating false positives and confirming vulnerabilities.
  • Ensure adequate coverage of the vulnerability management platform across the asset estate, in coordination with Infrastructure and Workplace teams.
  • Produce vulnerability dashboards, KPIs, and reporting, including weekly status updates on critical vulnerabilities and remediation SLAs for management.
  • Automate, document, and standardize operational procedures within the Vulnerability Management Program.
Qualifications
Vulnerability Management
  • Fundamental knowledge of Vulnerability Management concepts, including CVE, CVSS, KEV, exploitability, severity, prioritization, and remediation.
  • Experience defining SLAs, monitoring remediation activities, conducting follow‑ups, and escalating issues.
  • Knowledge of technology obsolescence (EOL/EOS) and associated risk assessment.
  • Experience creating dashboards and reports, with the ability to define and interpret KPIs.
  • Knowledge of cloud security and cloud resources, including security findings analysis.
  • Knowledge of container and container image vulnerabilities.
  • Familiarity with the Secure Software Development Lifecycle (SSDLC) and SCA/SAST concepts.
  • A critical approach to security tool results, with the ability to validate findings rather than assuming they are automatically accurate.
Technical Knowledge
  • Windows and Linux operating systems.
  • Networking and protocols: TCP/IP, DNS, HTTP/HTTPS, ports, and services.
  • Vulnerability Management platforms: Tenable One, CrowdStrike FEM.
  • Cloud platforms, particularly Microsoft Azure and Google Cloud.
  • Security tools integrated into development pipelines, including SCA, SAST, and IaC scanning.
Soft Skills
  • Effective communication with technical and operational teams.
  • Ability to communicate with different levels of the organization, including management, translating technical information into business risk and impact.
  • Strong analytical and problem‑solving skills.
  • Autonomy, organization, and prioritization skills in a high‑volume vulnerability environment involving multiple teams.
Certifications

Certifications in cybersecurity and Vulnerability Management are considered an advantage, particularly:

  • GIAC Enterprise Vulnerability Assessor (GEVA) — SANS SEC460.
  • CompTIA CySA+ or CompTIA Security+.
  • Cloud security certifications, such as Microsoft AZ‑500 or Google Professional Cloud Security Engineer.
  • Vendor certifications related to vulnerability scanning and management tools.
Additional Information
  • Professional development and monitoring talent;
  • Commitment to our employees' development;
  • Collaboration in a company that is constantly growing and evolving;
  • Strong organizational culture: collaboration, sharing, flexibility, integrity and low ego.

The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.

Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector
Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector

Devoteam • Porto

Presencial
EUR 60 000 - 90 000
Professional development
Growth opportunities
Collaborative culture
Devoteam Cyber Trust | Vulnerability Analyst | Telecom Sector
Devoteam Cyber Trust | Vulnerability Analyst | Telecom Sector

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 40 000 - 60 000
Professional development
Growth opportunities
Collaborative culture
Devoteam Cyber Trust |Vulnerability Manager | Fintech Sector
Devoteam Cyber Trust |Vulnerability Manager | Fintech Sector

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 45 000 - 65 000
Professional development opportunities
Collaborative work environment
Strong organizational culture of integrity and flexibility
Devoteam Cyber Trust | Vulnerability Analyst | Telecom Sector
Devoteam Cyber Trust | Vulnerability Analyst | Telecom Sector

SmartRecruiters, Inc. • Lisboa

Presencial
EUR 55 000 - 75 000
Professional development
Employee development
Collaborative culture
Devoteam Cyber Trust | Product Engineer – Security Platform
Devoteam Cyber Trust | Product Engineer – Security Platform

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 48 000 - 72 000
Devoteam Cyber Trust | Cyber Security Engineer
Devoteam Cyber Trust | Cyber Security Engineer

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 35 000 - 60 000
Equal opportunity employer
Diversity-focused workplace
Vulnerability Management Specialist
Vulnerability Management Specialist

Decskill • Porto

Presencial
EUR 48 000 - 70 000
Devoteam Cyber Trust | Cybersecurity Analyst
Devoteam Cyber Trust | Cybersecurity Analyst

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 40 000 - 60 000
Professional development and monitoring talent
Commitment to employee development
Collaboration in a growing company
+1
Devoteam Cyber Trust | SOC Analyst | Financial Sector
Devoteam Cyber Trust | SOC Analyst | Financial Sector

Devoteam | Cyber Trust • Porto

Presencial
EUR 26 000 - 36 000
Devoteam Cyber Trust | Operation Resilient Analyst | Insurance Sector
Devoteam Cyber Trust | Operation Resilient Analyst | Insurance Sector

SmartRecruiters, Inc. • Lisboa

Presencial
EUR 42 000 - 60 000