12 sep
|
Gmv Spain
|
Madrid
Application Security and Secure Development
If you want to takethe next step in your cybersecurity career,becoming a technical reference in
VulnerabilityManagement
within a large-scale service for a financial sectororganization, your place is with us We´ll get to the point; we'll tell you what's not on the web.If you want to know more about deGMV WHAT CHALLENGE WILL YOU BE TAKING ON? You will act as the technical reference for a
Vulnerability Management service, leading advanced analysis, risk-based prioritization andvulnerability treatment across infrastructure,applications, Cloud and container environments. Your mainresponsibilities will include: Acting as the technicalreference for Vulnerability Management operations and resolving technical escalations. Performing advanced analysisand risk-based prioritization, considering factors such as
CVSS, EPSS,CISA KEV , exposure, criticality and
Threat Intelligence . Defining and monitoring remediationactivities, mitigations and compensating controls. Coordinating with specialized Hacking,Cloud, Hardening/Compliance, Threat Intelligence and Automation
teams. Supervising critical oractively exploited vulnerabilities, including technicalverification and closure. Monitoring
SLAs, KPIs and reporting,identifying opportunities for automation and service improvement. Contributing to the evolutionof the service and the safe and supervised use of AI in
Vulnerability Management . WHAT DO WE NEED IN OUR TEAM? We are looking for aprofessional with at least 5 years of experiencein cybersecurity, with significant experience in Vulnerability Management, and a technicaluniversity degree or equivalent qualification. You should have: Strong knowledge of the vulnerabilitylifecycle and risk-based prioritization, including
CVSS, EPSS,
CISA KEV
and
ThreatIntelligence. Experience with vulnerabilityscanning and management tools, preferably
Qualys . Solid knowledge of
Windows,Linux, networking, applications, Cloud
and container environments. Experience in exploitationanalysis, defining mitigations and compensating controls, as well as
SLA, KPI
andreporting management. Knowledge of scripting, REST APIs, JSON
and automation. Strong technicalleadership, autonomy and multidisciplinary coordination skills. Security, Hardening/Compliance, Pentesting and tools such as
Prisma Cloud, Qualys WAAS or Burp Suite , willbe valued. Knowledge of cybersecurity governance and risk. Technical English is required, with a B2 level being recommended. WHAT DO WE OFFER? Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area. Adaptable start and finish times, and intensive working hours Fridays and in summer. Personalizedcareer
plan development , training and language learning support. National and international mobility. Do you come from another country?We can offer you a relocation package. Competitivecompensation with ongoing reviews, flexible compensation anddiscount on brands. Wellbeingprogram : Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more! In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition, bank transfers and bank cards will neverbe requested. If you are contacted through another process, please get in touch with the person responsible for the selection process. We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity.
#J-18808-Ljbffr
📌 Application Security and Secure Development (Madrid)
🏢 Gmv Spain
📍 Madrid