Vulnerability Management Specialist
Summary
The Vulnerability Management Specialist ensures Cardif’s IT assets are regularly scanned for vulnerabilities, monitors patch deployments, and coordinates remediation efforts across global teams. Core focus: vulnerability scanning, penetration testing, and cybersecurity compliance in a fintech environment.
Location: Porto,Porto District,Portugal
Overview:
The Vulnerability Management Specialist will actively participate on the continuous improvement of the client's Cybersecurity performance device. Within this area, the candidate will have a transversal knowledge of the client's environment and departments as the candidate will work daily with different counterparts.
What will you do?
- Ensure that all the client's assets are subject to regular vulnerability scans and that identified vulnerabilities are remediated.
- Monitor the deployment of critical patches.
- Ensure that all eligible assets are subject to regular code reviews and that identified vulnerabilities are remedied.
- Vulnerability scans.
- Monitor that all assets are covered by the vulnerability scanning tools.
- Monitor that all assets are regularly and successfully scanned.
- Examine scan tests results, prioritize and propose remediation plans and follow-up to the concerned Entities.
- Analyze critical patches information and identify impacted perimeters.
- Alert Entities impacted by critical patches.
- Follow the progress of the deployment of critical patches.
- Formalize and communicate a progress report Analyze critical patches information and identify impacted perimeters.
- Alert Entities impacted by critical patches.
- Follow the progress of the deployment of critical patches.
- Formalize and communicate a progress report.
- Monitor and request penetration tests on behalf of entities.
- Analyze test results, prioritize and propose remediation plans, monitor remediation.
- Control the quality and alignment with the requirements of the group of the services provided by the penetration test providers.
- Monitor that eligible assets (internal and external) are covered by the code review tools.
- Monitor that all assets are regularly and successfully scanned.
What are we looking for?
- Minimum 5 years’ experience in IT field.
- Wide vision on IT field.
- Cybersecurity knowledge/experience is a plus.
- Very good oral and written English.
- Produce regular and on demand reports about all topics.
- MS Excel advanced knowledge.
- Ability to travel within and outside Portugal.
What can you expect from us?
- A permanent job contract for a long term project;
- Tech equipment + SIM Card + personal smartphone;
- Health and Life Insurance;
- Social events and team buildings;
- The commitment of letting you grow with us, and be rewarded accordingly;
- A dynamic and young team that will be always there to support you;
- Training in the latest technologies;
- Coffee, fruits, snacks and a warm welcoming when you pass by the office.