VULNERABILITY MANAGEMENT SPECIALIST (HYBRID PORTO)
Portuguese company hires for hybrid position
Location: Porto, Portugal
Only candidates already based in Portugal will be considered
Work Model: Hybrid
Language Requirements: Very good written and spoken English — mandatory
Seniority: Senior (5+ years) minimum five years of experience in IT
Sector: Banking
Rate Between €3600 - 3900 RV / €2400 - 2700 CTI
About The Opportunity
We are looking for a Vulnerability Management Specialist to strengthen a Corporate Cybersecurity team within an international financial-services environment.
In this role, you will help ensure that IT assets are regularly assessed, vulnerabilities are correctly prioritised and remediation activities are effectively monitored. You will work across different business and technology areas, collaborating daily with IT teams, cybersecurity specialists, internal entities and external security providers around the world.
This opportunity is ideal for someone with a broad understanding of IT, strong analytical skills and an interest in improving vulnerability management processes within a complex and regulated organisation.
Main Responsibilities
- Ensure that all eligible IT assets are covered by regular vulnerability scans.
- Confirm that vulnerability scans are completed successfully and according to the required schedule.
- Analyse scan results, assess severity and prioritise identified vulnerabilities.
- Propose remediation plans and monitor their implementation with the responsible teams.
- Monitor the deployment of critical security patches.
- Identify systems and business areas affected by critical vulnerabilities and patches.
- Alert the relevant teams and entities regarding urgent remediation requirements.
- Track patch deployment progress and communicate status reports.
- Coordinate and request penetration tests on behalf of internal entities.
- Analyse penetration-testing results and propose appropriate remediation plans.
- Monitor the remediation of vulnerabilities identified through penetration tests.
- Assess the quality of services provided by external penetration-testing suppliers.
- Ensure that penetration-testing activities comply with internal security standards and requirements.
- Confirm that eligible internal and external assets are covered by code-review tools.
- Monitor the execution and results of security code reviews.
- Produce regular and ad hoc reports covering vulnerability scans, patches, penetration tests, code reviews and remediation progress.
- Lead meetings with technical teams, business stakeholders and security providers.
- Contribute to the continuous improvement of vulnerability management processes and cybersecurity performance.
Vulnerability Scanning
- Monitor asset coverage across vulnerability-scanning tools.
- Ensure that assets are scanned regularly and successfully.
- Review scan results and identify the most critical security exposures.
- Prioritise vulnerabilities based on risk and business impact.
- Define and follow up on remediation plans with the responsible teams.
- Identify coverage gaps and unsuccessful scans.
Critical Patch Management
- Analyse information related to critical patches and security advisories.
- Determine which systems, applications and teams are affected.
- Notify the relevant entities of urgent patching requirements.
- Track the progress of critical patch deployment.
- Produce and communicate clear progress reports.
Penetration Testing
- Coordinate and request penetration tests for internal entities.
- Analyse findings and prioritise vulnerabilities.
- Define and monitor remediation actions.
- Review the quality of penetration-testing deliverables.
- Ensure that external providers comply with organisational security standards.
Secure Code Review
- Ensure that eligible internal and external applications are covered by code-review tools.
- Monitor the regular and successful execution of security code scans.
- Analyse identified issues and follow up on remediation activities.
- Support teams in improving secure development and code-review coverage.
Mandatory Requirements
- Minimum of five years of professional experience in the IT field.
- Broad understanding of IT systems, applications, infrastructure and security processes.
- Experience analysing technical information and coordinating remediation activities.
- Ability to produce regular and on-demand reports.
- Advanced knowledge of Microsoft Excel.
- Very good written and spoken English.
- Strong analytical and organisational skills.
- Ability to lead meetings with technical and non-technical stakeholders.
- Availability to travel within and outside Portugal.
Valued Experience
- Professional experience in cybersecurity or information security.
- Hands-on experience with vulnerability management platforms or scanning tools.
- Knowledge of CVE, CVSS and risk-based vulnerability prioritisation.
- Experience coordinating penetration tests and following remediation plans.
- Familiarity with Static Application Security Testing and secure code-review tools.
- Experience managing critical patching campaigns.
- Previous experience in insurance, banking or another regulated sector.
- Knowledge of cybersecurity governance, risk and compliance processes.
Soft Skills
- Rigorous and detail-oriented approach.
- Dynamic and proactive attitude.
- Strong focus on deliverables and results.
- Client-oriented mindset.
- Effective collaboration across international teams.
- Adaptability within complex environments.
- Resilience and persistence.
- Strong analytical and problem-solving abilities.
- Clear written and verbal communication.
- Confidence leading meetings and following up on action plans.
The Ideal Profile
The ideal candidate has at least five years of experience in IT and a broad understanding of infrastructure, applications and cybersecurity processes. You can analyse vulnerability data, identify priorities and translate technical findings into structured remediation plans and clear management reports.
You are comfortable coordinating activities across multiple teams, challenging remediation progress and leading meetings with technical stakeholders, business representatives and external providers.
You are rigorous, collaborative and deliverable-oriented, with advanced Excel skills and very good English communication. Experience in vulnerability scanning, penetration testing, patch management, secure code review or regulated financial environments will be a strong advantage.
CV Keywords
Vulnerability Management Specialist, Vulnerability Management, Cybersecurity, Information Security, Vulnerability Assessment, Vulnerability Scanning, Security Scanning, Vulnerability Scanner, Asset Coverage, Asset Management, CVE, CVSS, Risk-Based Vulnerability Management, RBVM, Vulnerability Prioritisation, Remediation Plans, Remediation Tracking, Critical Patches, Critical Patch Management, Patch Management, Security Advisories, Penetration Testing, Pentest, Penetration Test Coordination, Security Testing, External Security Providers, Code Review, Secure Code Review, Static Application Security Testing, SAST, Code Scanning, Application Security, AppSec, Secure Development, Security Findings, Risk Analysis, Cybersecurity Reporting, Security Metrics, Cybersecurity Governance, Risk Management, Compliance, IT Security, Financial Services, Insurance, Banking, Regulated Environment, Microsoft Excel, Advanced Excel, Reporting, Stakeholder Management, Meeting Facilitation, English