G

Senior Vulnerability Management Engineer

GMV Spain
Relocation
Apply
AI Summary

Lead technical vulnerability management for a financial sector organization, driving risk-based prioritization and remediation across infrastructure, applications, and cloud environments. Serve as the technical authority for vulnerability operations, coordinating with cross-functional teams to mitigate critical threats. Develop and optimize vulnerability management processes, leveraging advanced analysis tools and threat intelligence.

Key Highlights
Technical reference for Vulnerability Management operations and escalations
Risk-based prioritization using CVSS, EPSS, CISA KEV, and Threat Intelligence
Leadership in vulnerability lifecycle management across cloud, containers, and traditional infrastructure
Key Responsibilities
Act as the technical reference for Vulnerability Management operations and resolve technical escalations
Perform advanced analysis and risk-based prioritization using CVSS, EPSS, CISA KEV, exposure, criticality, and Threat Intelligence
Define and monitor remediation activities, mitigations, and compensating controls
Coordinate with specialized teams including Hacking, Cloud, Hardening/Compliance, Threat Intelligence, and Automation
Supervise critical or actively exploited vulnerabilities, including technical verification and closure
Monitor SLAs, KPIs, and reporting, identifying opportunities for automation and service improvement
Contribute to the evolution of the service and the safe use of AI in Vulnerability Management
Technical Skills Required
Vulnerability Management Risk Assessment Threat Intelligence
Benefits & Perks
Hybrid working model with 8 weeks of remote work outside usual area
Flexible start/finish times and intensive working hours on Fridays/summer
Health, dental, and accident insurance; wellbeing program
Nice to Have
Experience with Qualys vulnerability scanning and management tools
Knowledge of scripting, REST APIs, JSON, and automation
Familiarity with Prisma Cloud, Qualys WAAS, or Burp Suite
Knowledge of cybersecurity governance and risk
Security, Hardening/Compliance, or Pentesting experience

Job Description


If you want to take the next step in your cybersecurity career, becoming a technical reference in Vulnerability Management within a large-scale service for a financial sector organization, your place is with us

We´ll get to the point; we'll tell you what's not on the web. If you want to know more about de GMV

WHAT CHALLENGE WILL YOU BE TAKING ON?

You will act as the technical reference for a Vulnerability Management service, leading advanced analysis, risk-based prioritization and vulnerability treatment across infrastructure, applications, Cloud and container environments.

Your main responsibilities will include:

  • Acting as the technical reference for Vulnerability Management operations and resolving technical escalations.
  • Performing advanced analysis and risk-based prioritization, considering factors such as CVSS, EPSS, CISA KEV, exposure, criticality and Threat Intelligence.
  • Defining and monitoring remediation activities, mitigations and compensating controls.
  • Coordinating with specialized Hacking, Cloud, Hardening/Compliance, Threat Intelligence and Automation teams.
  • Supervising critical or actively exploited vulnerabilities, including technical verification and closure.
  • Monitoring SLAs, KPIs and reporting, identifying opportunities for automation and service improvement.
  • Contributing to the evolution of the service and the safe and supervised use of AI in Vulnerability Management.

WHAT DO WE NEED IN OUR TEAM?

We are looking for a professional with at least 5 years of experience in cybersecurity, with significant experience in Vulnerability Management, and a technical university degree or equivalent qualification.

You should have:

  • Strong knowledge of the vulnerability lifecycle and risk-based prioritization, including CVSS, EPSS, CISA KEV and Threat Intelligence.
  • Experience with vulnerability scanning and management tools, preferably Qualys.
  • Solid knowledge of Windows, Linux, networking, applications, Cloud and container environments.
  • Experience in exploitation analysis, defining mitigations and compensating controls, as well as SLA, KPI and reporting management.
  • Knowledge of scripting, REST APIs, JSON and automation.
  • Strong technical leadership, autonomy and multidisciplinary coordination skills.
  • Security, Hardening/Compliance, Pentesting and tools such as Prisma Cloud, Qualys WAAS or Burp Suite, will be valued.
  • Knowledge of cybersecurity governance and risk.
  • Technical English is required, with a B2 level being recommended.

WHAT DO WE OFFER?

🕑 Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.

💻 Flexible start and finish times, and intensive working hours Fridays and in summer.

🚀 Personalized career plan development, training and language learning support.

🌍 National and international mobility. Do you come from another country? We can offer you a relocation package.

💰 Competitive compensation with ongoing reviews, flexible compensation and discount on brands.

💪Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!

⚠️ In our recruitment processes you will always have telephone and personal contact, face-to-face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.

❤️ We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.

WHAT ARE YOU WAITING FOR? JOIN US


Similar Jobs

Explore other opportunities that match your interests

Senior Security Compliance Engineer (Privacy & Data Protection)

Cyber Security
1w ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Scopely

Spain

Senior Product Security Engineer

Cyber Security
3w ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

n26

Spain

Senior Cybersecurity Architect (Defence & Security)

Cyber Security
3w ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

GMV

Spain

Subscribe our newsletter

New Things Will Always Update Regularly