Description
**Vulnerability Management Manager**
**Mission:**
Lead and evolve vulnerability management, ensuring continuous identification, risk-based prioritization, and timely remediation, while guaranteeing remediation compliance by responsible teams through automated and efficient processes.
**Key Job Responsibilities:**
* Vulnerability Identification and Assessment: Lead continuous identification of vulnerabilities across infrastructure, cloud, applications, and endpoints, leveraging specialized tools and vendors to ensure coverage, quality, and scanning frequency. Analyze and prioritize vulnerabilities based on criticality, exposure, and context. Implement, integrate, and maintain vulnerability management and continuous scanning tools, ensuring their operation, data quality, and evolution.
* Mitigation and Remediation: Ensure timely remediation of vulnerabilities by responsible teams, coordinating and tracking progress with IT, development, and vendors. Define and enforce remediation SLAs based on criticality. Manage the backlog, escalate non-compliance until closure, and administer risk exceptions in a controlled manner, with traceability and visibility.
* Automation and Operational Efficiency: Design and implement automation of the vulnerability management lifecycle, leveraging vendor tools and capabilities. Integrate processes and platforms (scanning, ITSM, CMDB) to ensure end\-to\-end traceability. Optimize operations by reducing manual effort and improving response and remediation times.
* Program Evolution: Define and execute the evolution of vulnerability management toward a continuous exposure management model, incorporating capabilities such as EASM, continuous control validation, and advanced prioritization. Evaluate and lead adoption of new technologies and specialized services to enhance visibility, coverage, and program effectiveness.
* Compliance and Continuous Improvement: Define, maintain, and evolve vulnerability management policies, standards, and processes, ensuring consistent execution with vendor support. Meet regulatory and audit requirements. Identify and implement continuous improvements to the operational model, ensuring efficiency and scalability.
* Education and Awareness: Ensure responsible teams understand and fulfill their roles in vulnerability remediation. Coordinate with vendors and internal teams to disseminate best practices, and maintain ongoing updates on threats, exploitation techniques, and relevant trends.
**Profile Requirements:**
*Education*
* Bachelor's degree or engineering in computer science.
* Desired certifications: CISSP, ISO 27001, CRISC, ISO27005, CEH, CompTIA Security\+, or similar.
*Experience*
* Minimum 5 years of cybersecurity experience, including at least 3 years focused on vulnerability management.
*Knowledge*
* Extensive knowledge of networks and/or telecommunications
* Extensive knowledge of operating systems and technology platforms
* Experience with vulnerability management tools (e.g., Qualys, Nessus, Rapid7\), operating systems, networks, and application security.
*Skills / Technical Competencies*
* Advanced English
* Frustration tolerance
* Strong collaboration and project development skills within teams.
* Agile mindset with a service-oriented attitude.
* Business acumen and focus on the end user.
* Strong analytical and problem-solving skills, project management capability, and excellent written and verbal communication skills.