About the Role
We are looking for a Senior Vulnerability Manager to lead and mature an enterprise-wide vulnerability management programme within a complex technology environment. You will own the vulnerability management lifecycle from detection and assessment through risk-based prioritisation, remediation tracking, verification and closure.
You will work closely with IT, infrastructure, cloud, application, security, risk and business stakeholders to drive remediation commitments and ensure compliance with agreed SLAs and regulatory requirements. The role also involves leading vulnerability analysts and stakeholders, improving governance and reporting, and continuously strengthening vulnerability management capabilities across on-premises, cloud, workplace, application and container environments.
Key Responsibilities
- Own the end-to-end vulnerability management operating process.
- Lead vulnerability identification, assessment, prioritisation and remediation.
- Define and continuously improve vulnerability management scope and governance.
- Establish and maintain RACI responsibilities across delivery teams and external partners.
- Define risk-based prioritisation using CVSS, exploitability, business criticality and threat intelligence.
- Define and enforce risk-based remediation SLAs.
- Monitor vulnerability management KPIs and KRIs.
- Coordinate vulnerability detection, remediation and patching activities.
- Engage IT, security, business and technical stakeholders to drive remediation commitments.
- Monitor remediation performance across teams and environments.
- Track vulnerability coverage, remediation attainment, ageing and end-of-life trends.
- Manage vulnerability exceptions, including compensating controls, accountable authorities and expiry dates.
- Prepare governance and risk reporting for senior stakeholders.
- Maintain audit evidence supporting vulnerability management and regulatory compliance.
- Promote vulnerability management best practices across the organisation.
Required Skills
Mandatory Skills
- 5+ years of experience in vulnerability or patch management.
- Direct ownership of vulnerability management programmes.
- Strong understanding of the vulnerability management lifecycle.
- Strong knowledge of CVSS scoring methodologies.
- Experience with vulnerability remediation and patch management processes.
- Understanding of threat intelligence and exploitability analysis.
- Enterprise infrastructure knowledge.
- Cloud and networking technology knowledge.
- Strong analytical and reporting capabilities.
- Fluent English.
- Hands-on experience with Qualys.
- Hands-on experience with AWS Inspector.
- Hands-on experience with Microsoft Defender Vulnerability Management.
Nice-to-Have Skills
- Multi-cloud experience across AWS and Azure.
- Container security experience.
- Familiarity with NIS2.
- ITSM integration experience with Jira and/or ServiceNow.
- Dutch and/or French language skills.
- Experience in large enterprises or public-sector environments.
- Experience working with legacy infrastructure and technical debt.
Experience
5+ years in vulnerability or patch management with direct programme ownership.
Languages
- English: Fluent – Mandatory
- Either Dutch or French: Fluent - Mandatory
- The other language between Dutch or French: Elementary proficiency
About NISH Tech BV
NISH Tech BV is an IT consulting and staffing company connecting skilled technology professionals with leading organizations across Europe. We support clients across cybersecurity, digital transformation, data, infrastructure and enterprise technology, helping organizations access specialized expertise for critical technology initiatives.
Application
Interested candidates are invited to send their CV to:
[email protected]
📌 Senior vulnerability manager (España)
🏢 NISH Tech
📍 España