This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Vulnerability Assessment Specialist is a seasoned subject matter expert, responsible for conducting advanced vulnerability assessments, identifying vulnerabilities, and provides expert recommendations to mitigate security risks to ensure the security and integrity of the organization's systems and infrastructure. This role requires collaboration with cross-functional teams, and they lead/perform vulnerability assessments, analyze findings, and provide recommendations to mitigate security risks and contributes to the improvement of vulnerability management practices.
Job Responsibility:
Conducts vulnerability assessments using automated scanning tools and manual techniques to identify security vulnerabilities in systems, networks, applications, and infrastructure components
Analyzes scan results and prioritizes vulnerabilities based on severity, impact, and exploitability
Assesses the potential risks associated with identified vulnerabilities
Analyzes the business impact, likelihood of exploitation, and potential attack vectors to prioritize remediation efforts based on risk severity
Provides detailed remediation recommendations to system owners, administrators, and IT teams
Collaborates to develop practical mitigation strategies, configuration changes, and patch management processes to address identified vulnerabilities
Utilizes vulnerability scanning tools such as Nessus, OpenVAS, Qualys, or similar tools to conduct scans, configure scan policies, and fine-tune scan parameters for accurate and comprehensive assessments
Communicates assessment results to stakeholders, including technical and non-technical audiences, in a clear and concise manner
Collaborates with cross-functional teams, including IT operations, development teams, and security stakeholders, to ensure effective communication, coordination, and alignment on vulnerability management efforts. Communicates technical concepts and recommendations to non-technical stakeholders
Participates in security awareness programs and provides training to end-users and stakeholders on vulnerability management best practices, secure coding, and security hygiene
Promotes a culture of security awareness within the organization
Collaborates with incident response teams to identify and address vulnerabilities associated with security incidents
Provides support during incident response efforts and contribute to post-incident analysis and remediation
Stays updated with the latest security trends, emerging vulnerabilities, and industry best practices
Contributes to the enhancement of vulnerability assessment processes, methodologies, and tools
Shares knowledge and provides guidance to improve vulnerability management practices
Performs any other related task as required
Requirements:
Bachelor's degree or equivalent in Computer Science, Information Security, or a related field
Relevant certifications such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or GIAC Certified Vulnerability Assessor (GCVA) are beneficial
Seasoned demonstrated experience in information security or related roles, with a focus on conducting vulnerability assessments and providing remediation recommendations
Seasoned demonstrated experience in conducting advanced vulnerability assessments, including application security assessments, penetration testing, or code review
Seasoned understanding of vulnerability assessment methodologies, tools, and industry best practices
Seasoned understanding of networking concepts, operating systems, and common software vulnerabilities
Solid proficiency in using vulnerability assessment tools such as Nessus, OpenVAS, Qualys, or similar tools
Seasoned knowledge of risk analysis principles and the ability to assess the business impact of vulnerabilities
Solid knowledge of vulnerability management frameworks, such as CVE, CVSS, and common vulnerability databases
Strong analytical and problem-solving skills to analyze scan results, prioritize vulnerabilities, and recommend effective remediation actions
Excellent written and verbal communication skills to prepare vulnerability assessment reports and effectively communicate technical information to diverse stakeholders
Excellent collaboration and teamwork skills to work effectively with cross-functional teams and stakeholders
Seasoned familiarity with security frameworks, standards, and regulatory compliance requirements