11 sep
|
Gmv Spain
|
Madrid
Application Security and Secure DevelopmentIf you want to takethe next step in your cybersecurity career,becoming a technical reference in VulnerabilityManagement within a large-scale service for a financial sectororganization, your place is with usWe´ll get to the point; we'll tell you what's not on the web.If you want to know more about deGMVWHAT CHALLENGE WILL YOU BE TAKING ON?You will act as the technical reference for a Vulnerability Managementservice, leading advanced analysis, risk-based prioritization andvulnerability treatment across infrastructure,applications, Cloud and container environments.Your mainresponsibilities will include:- Acting as the technicalreference for Vulnerability Management operations and resolving technical escalations.- Performing advanced analysisand risk-based prioritization, considering factors such as CVSS, EPSS,CISA KEV, exposure, criticality and Threat Intelligence.- Defining and monitoring remediationactivities, mitigations and compensating controls.- Coordinating with specializedHacking,Cloud, Hardening/Compliance, Threat Intelligence and Automation teams.- Supervising critical oractively exploited vulnerabilities, including technicalverification and closure.- Monitoring SLAs, KPIsand reporting,identifying opportunities for automation and service improvement.- Contributing to the evolutionof the service and the safe and supervised use of AI in Vulnerability Management.WHAT DO WE NEED IN OUR TEAM?We are looking for aprofessional with at least 5 years of experiencein cybersecurity, with significant experience in Vulnerability Management, and a technicaluniversity degree or equivalent qualification.You should have:- Strong knowledge of the vulnerabilitylifecycle and risk-based prioritization, including CVSS, EPSS,
CISA KEV and ThreatIntelligence.- Experience with vulnerabilityscanning and management tools, preferably Qualys.- Solid knowledge of Windows,Linux, networking, applications, Cloud and container environments.- Experience in exploitationanalysis, defining mitigations and compensating controls, as well as SLA, KPI andreporting management.- Knowledge of scripting,REST APIs, JSON and automation.- Strong technicalleadership, autonomy and multidisciplinary coordination skills.- Security, Hardening/Compliance, Pentesting and tools such as Prisma Cloud, Qualys WAAS or Burp Suite, willbe valued.- Knowledge of cybersecurity governance and risk.- Technical English is required, with a B2 level being recommended.WHAT DO WE OFFER?Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area.Flexible start and finish times, and intensive working hours Fridays and in summer.Personalizedcareer plan development, training and language learning support.National and international mobility. Do you come from another country?We can offer you a relocation package.Competitivecompensation with ongoing reviews, adaptable compensation anddiscount on brands.Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more!In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition, bank transfers and bank cards will neverbe requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity.#J-18808-Ljbffr
📌 Application Security And Secure Development (Madrid)
🏢 Gmv Spain
📍 Madrid