IT Senior Vulnerability Management Specialist
About the project
We are looking for a senior Vulnerability Management Specialist who will take responsibility for designing and operating a scalable application vulnerability management program using the Snyk platform.
Your main task will be to connect the technical side of Application Security with risk management, effective remediation and automation of the entire process. You will work across Development, DevOps, Application Owners and Security teams and help establish processes so that vulnerabilities are correctly prioritized, assigned to responsible teams, resolved on time and subsequently verified.
The role will also include vulnerability management automation, reporting and continuous improvement of the entire process in line with company directives, standards, policies and procedures.
Mission
- Design and maintain an end-to-end vulnerability management and remediation process, including risk-based prioritization according to CVSS, EPSS, exploitability, application criticality and exposure, production status and data sensitivity.
- Monitor and triage findings from SAST, DAST and SCA, identify the correct application, repository and owner, and create actionable Jira tickets with priorities, deadlines and evidence.
- Coordinate remediation with developers, track SLAs, resolve blockers and escalate vulnerabilities that are overdue or have no owner.
- Coordinate risk acceptance and time-limited exceptions when a vulnerability cannot be remediated within the SLA, then verify remediation through automated rescanning and confirm closure.
- Prepare dashboards and management reporting covering risks, vulnerability age and SLAs, and automate ticketing, ownership, notifications, SLA tracking, escalations, rescanning and reporting.
- Continuously improve scan coverage, prioritization accuracy, remediation efficiency and developer experience, and develop governance in line with company standards, policies and procedures.
- Collaborate across Security, Development, DevOps and Application Owners, drive change without direct authority and build a scalable risk-driven remediation program aligned with DevSecOps principles.
Skills
- 5+ years of experience in vulnerability management, application security, DevSecOps or a related security role, including designing and operating enterprise VM/AppSec processes and coordinating remediation with Development and DevOps teams.
- Knowledge of SDLC, CI/CD, open-source dependencies, containers and application security; experience with Snyk or a similar platform and with designing or automating Jira workflows.
- Ability to translate technical findings into risk-based actions for both technical and business stakeholders; strong ownership, organizational and stakeholder management skills.
- Hands-on experience with GitLab SaaS or other CI/CD platforms (GitHub, GitLab, Bitbucket, Azure DevOps).
- Knowledge of OWASP Top 10, CVE, CVSS, CWE, EPSS and secure development principles.
- Experience with security in regulated environments (NIS2, ISO/IEC 27001) and automation in hyperscale cloud environments, for example AWS + Terraform.
Benefits
- Great colleagues and a fully flexible working policy
- Career coaching and professional development
- Flexible working hours
- Technical training and workshops
- Work equipment (Mac / Windows)
- Company events
- Company psychologist supporting mental wellbeing
- Multisport card
Take the next step in your career and get in touch.
Send us your CV and tell us a little about yourself. We'd love to learn about your experience, what you're looking for, and where you'd like to take your career next.