Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector
Devoteam · Porto
Sobre a função
Integration into a Threat Operations team, with responsibilities within the organization's Vulnerability Management Program, including vulnerability identification, prioritization, remediation SLA definition and tracking, and reporting.
- Manage the vulnerability lifecycle across infrastructure and endpoints, including analysis, prioritization (CVE, CVSS, KEV, exploitability, business context), and definition of remediation SLAs.
- Monitor and validate remediation or mitigation processes, identify SLA breaches, perform follow-ups, and escalate issues to the appropriate teams or management levels.
- Identify and monitor vulnerabilities within development pipelines (SSDLC), in coordination with the AppSec team.
- Assess and monitor the risk associated with technology obsolescence (End-of-Life / End-of-Support) across systems, applications, and components.
- Identify and analyze security findings across cloud environments, containers, and images, in collaboration with AppSec and Cloud Security teams.
- Critically validate the results generated by security tools, investigating false positives and confirming vulnerabilities.
- Ensure adequate coverage of the vulnerability management platform across the asset estate, in coordination with Infrastructure and Workplace teams.
- Produce vulnerability dashboards, KPIs, and reporting, including weekly status updates on critical vulnerabilities and remediation SLAs for management.
- Automate, document, and standardize operational procedures within the Vulnerability Management Program.
Vulnerability Management
- Fundamental knowledge of Vulnerability Management concepts, including CVE, CVSS, KEV, exploitability, severity, prioritization, and remediation.
- Experience defining SLAs, monitoring remediation activities, conducting follow-ups, and escalating issues.
- Knowledge of technology obsolescence (EOL/EOS) and associated risk assessment.
- Experience creating dashboards and reports, with the ability to define and interpret KPIs.
- Knowledge of cloud security and cloud resources, including security findings analysis.
- Knowledge of container and container image vulnerabilities.
- Familiarity with the Secure Software Development Lifecycle (SSDLC) and SCA/SAST concepts.
- A critical approach to security tool results, with the ability to validate findings rather than assuming they are automatically accurate.
Technical Knowledge
- Windows and Linux operating systems.
- Networking and protocols: TCP/IP, DNS, HTTP/HTTPS, ports, and services.
- Vulnerability Management platforms: Tenable One, CrowdStrike FEM.
- Cloud platforms, particularly Microsoft Azure and Google Cloud.
- Security tools integrated into development pipelines, including SCA, SAST, and IaC scanning.
Soft Skills
- Effective communication with technical and operational teams.
- Ability to communicate with different levels of the organization, including management, translating technical information into business risk and impact.
- Strong analytical and problem-solving skills.
- Autonomy, organization, and prioritization skills in a high-volume vulnerability environment involving multiple teams.
Certifications
Certifications in cybersecurity and Vulnerability Management are considered an advantage, particularly:
- GIAC Enterprise Vulnerability Assessor (GEVA) — SANS SEC460.
- CompTIA CySA+ or CompTIA Security+.
- Cloud security certifications, such as Microsoft AZ-500 or Google Professional Cloud Security Engineer.
- Vendor certifications related to vulnerability scanning and management tools.
What we offer:
- Professional development and monitoring talent;
- Commitment to our employees' development;
- Collaboration in a company that is constantly growing and evolving;
- Strong organizational culture: collaboration, sharing, flexibility, integrity and low ego.
The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.