Overview In this role you will serve as the technical reference for Vulnerability Management within a large-scale financial services environment. You will lead advanced analysis, risk-based prioritization and remediation efforts across infrastructure, apps, cloud and containers. You'll coordinate with specialized teams to drive automation, governance and service improvement, and oversee critical or exploited vulnerabilities.
This position offers the chance to shape vulnerability practices and contribute to secure, AI-assisted operations.
Compensaciones / Beneficios Hybrid working model
8 weeks teleworking outside usual area
Adaptable start and finish times career plan development training and language learning support national and international mobility
Responsabilidades Act as the technical reference for Vulnerability Management operations and resolve escalations
Perform advanced analysis and risk-based prioritization (CVSS, EPSS, CISA KEV, exposure, criticality, threat intelligence)
Define and monitor remediation activities, mitigations and compensating controls
Coordinate with Hacking, Cloud, Hardening/Compliance, Threat Intelligence and Automation teams
Supervising critical or actively exploited vulnerabilities, including verification and closure
Monitor SLAs, KPIs and reporting; identify automation and service improvement opportunities
Contribute to the evolution of the service and safe supervised use of AI in Vulnerability Management
Requisitos principales 5+ years in cybersecurity with substantial Vulnerability Management experience
Strong knowledge of vulnerability lifecycle and risk-based prioritization (CVSS, EPSS, CISA KEV, Threat Intelligence)
Experience with vulnerability scanning/management tools, preferably Qualys
Solid knowledge of Windows, Linux, networking, applications, Cloud and container environments
Experience in exploitation analysis, mitigations and compensating controls, plus SLA/KPI reporting
Knowledge of scripting, REST APIs, JSON and automation
Strong technical leadership, autonomy and cross-functional coordination leadership autonomy multidisciplinary coordination vulnerability lifecycle and risk-based prioritization
CVSS, EPSS, CISA KEV, Threat Intelligence
Qualys (and vulnerability scanning/management tools)
📌 Application Security and Secure Development (Madrid)
🏢 GMV
📍 Madrid