Senior Cyber Threat & Vulnerability Management Engineer
Indexed description
About us
In Piraeus our purpose is to be a pillar of stability for the Greek economy, to fuel growth and to promote innovation. We aim our footprint in society to be positive and lasting, for the benefit of our customers, our people, our shareholders and society at large, fully reflecting our values. In this way we express in practice our will to: create value in all we do, challenge the frontiers, enthuse our customers and build relationships of trust.
Piraeus is the leading financial institution in Greece, in terms of domestic market shares in loans, deposits, and branch presence. The Group provides a comprehensive range of financial products and services to 4.5mn customers, with recognized leadership in SME banking, retail banking, digital banking, insurance and capital markets.
In 2026, Piraeus was recognized at the Euromoney Awards for Excellence as Europe’s Best Bank for Corporate Social Responsibility, Greece’s Best Bank for ESG, Greece’s Best Retail Bank and Greece’s Best Bank for Large Corporates, and by the Banker as the “Best Bank in Greece” for Growth and for Liquidity at the prestigious Bank of the Year Awards, reflecting our ongoing commitment to responsible banking and sustainability.
About the Job
We are looking for an experienced Cyber Security professional to take ownership of Threat & Vulnerability Management across the Group's technology estate. In this role you will drive the Bank's Threat & Vulnerability Management framework end to end, from the discovery of vulnerabilities and exposures through risk-based prioritisation, remediation governance and assurance, setting the methodology and standards that infrastructure, cloud and application teams follow. You will act as the technical reference point for vulnerability and offensive security testing matters, provide direction to engineers and external specialists working in the domain, and represent the function to senior management, internal audit and supervisory authorities.
Responsibilities:
- Lead the continuous evolution of the Bank's Threat & Vulnerability Management framework, covering the identification, assessment, prioritization, remediation and monitoring of security exposures across infrastructure, cloud, applications, containers, databases and end-user platforms.
- Coordinate the development and continuous enhancement of the risk-based prioritization methodology, combining technical severity (CVSS), exploitation likelihood (EPSS) and confirmed active exploitation (CISA KEV) with asset criticality and technical exposure, and maintain the scoring model, escalation rules and remediation SLAs.
- Define and maintain the annual security testing and scanning plan, including scope, method (authenticated, unauthenticated, agent-based and continuous scanning) and frequency, ensuring full coverage of the ICT asset estate and the enhanced scanning cadence required for critical or important functions under DORA.
- Analyze vulnerability intelligence, threat trends and exploit activity, assess the Bank's exposure to emerging and zero-day vulnerabilities, and recommend emergency escalations, priority overrides and interim mitigations where required.
- Drive remediation with infrastructure, cloud, application and technology teams, consolidating findings into remediation campaigns with clear ownership, and monitor remediation performance against agreed SLAs and backlog reduction targets.
- Govern the vulnerability exception process, assessing risk acceptance requests, compensating controls and expiry dates, and escalating residual risk to the appropriate governance bodies.
- Drive the execution of Attack Surface Management (ASM/EASM) and Exposure Management initiatives to improve visibility of the internal and external attack surface and reduce cyber risk.
- Coordinate the integration of security assessment results into the vulnerability lifecycle, including SAST, DAST, SCA, container scanning, red team and penetration testing findings, and validate exploitability and the effectiveness of remediation through hands-on verification and re-testing.
- Manage the penetration testing programme and third-party security assessment providers, from scoping and quality review of deliverables through to findings management, retesting and periodic vendor rotation, and support threat-led penetration testing (TLPT) exercises.
- Define the domain's metrics, KPIs and KRIs (open critical, high and KEV vulnerabilities, SLA compliance, mean time to remediate, overdue campaigns, active exceptions) and produce reporting for senior management and the Board.
- Shape and drive the evolution of the tooling roadmap for vulnerability, exposure and attack surface management, including platform selection and rollout, integration with CMDB and ticketing, automation, and continuous improvement of asset coverage and data quality.
- Ensure that ICT third-party providers apply vulnerability and patch management controls of an equivalent standard and drive ongoing assurance over their remediation performance.
- Act as the domain point of contact for internal and external audits, regulatory inspections and supervisory requests, providing evidence and driving the closure of related findings.
- Provide technical guidance and mentoring to engineers and external specialists working on vulnerability management activities and promote high-quality and consistent delivery across the domain.
Qualifications:
- BSc degree in Computer Science, Cybersecurity, Information Technology, or related field.
- MSc degree in a relevant discipline will be considered an asset.
- 5-8 years of working experience in Cyber Security, Vulnerability Management, Offensive Security, Security Operations or Security Engineering, including demonstrable experience acting as technical owner of a security domain.
- Deep hands-on experience with enterprise vulnerability management platforms such as Qualys, Tenable, Rapid7 or Microsoft Defender Vulnerability Management, including deployment, tuning, authenticated scanning and asset coverage management.
- Strong understanding of enterprise infrastructure, networking, operating systems, virtualization, and cloud technologies.
- Proven experience designing and operating Risk-Based Vulnerability Management, including scoring models, prioritisation logic, remediation SLAs and exception governance.
- Strong command of CVEs, CVSS, EPSS, MITRE ATT&CK, CISA KEV, threat intelligence and exposure management concepts, and the ability to translate them into defensible prioritisation decisions.
- Hands-on experience across Windows, Linux, cloud environments (preferably Microsoft Azure), databases, containers, Kubernetes and network technologies.
- Understanding of Secure SDLC and application security practices, including OWASP Top 10 and OWASP ASVS.
- Familiarity with regulatory and security frameworks such as DORA, NIS2, ISO 27001, PCI DSS, CIS Benchmarks and NIST CSF, and experience operating under regulatory and audit scrutiny.
- Experience with Exposure Management platforms (Qualys ETM, Kenna, XM Cyber, Brinqa, Nucleus, Cisco Vulnerability Management), will be appreciated.
- Experience with Attack Surface Management (ASM/EASM), will be appreciated.
- Knowledge of Threat Intelligence, SIEM, and SOAR platforms, will be appreciated.
- Professional certifications such as CISSP, CISM, GSEC, GCIH, GCIA or vendor certifications (e.g. Qualys), will be appreciated.
- Hands-on offensive security experience, such as penetration testing, exploit validation, red teaming or purple teaming, together with the ability to challenge and quality-review third-party test results, will be strongly appreciated.
- Offensive security certifications such as OSCP, OSEP, OSWE, GPEN, GXPN or CRTO, will be strongly appreciated.
- Experience with scripting and automation (Python, PowerShell) and with reporting or BI tooling for security metrics, will be appreciated.
- Strong stakeholder management and communication skills, with the ability to present technical risk to senior management and to challenge technology teams constructively.
- Experience in guiding, mentoring or coordinating technical teams and external providers, will be appreciated.
What's In It For You
In our bank it is a top priority to provide a modern work environment, where all our employees can perform and grow. As an employee of Piraeus Bank, you will be part of an organization that:
- Holds a leading position in the Greek economy and maintains a robust presence in the community
- Instills a workplace culture that embraces open communication, respect, inclusion and equal opportunities
- Offers a competitive remuneration package, private health insurance program and other benefits for both employees and their families
- Provides a challenging working environment that values accountability and celebrates high performance by implementing appropriate incentives
- Empowers personal & career development and continuous learning while encouraging creative thinking and innovation
- Provides an all-bank wellbeing program, fostering initiatives that enhance physical, mental & emotional health
- Provides digital technologies and tools that fully support new ways of working and flexible working options, while communicate regularly and effectively
All applications will be treated with confidentiality.
Application Deadline : 24/08/2026
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search