Vulnerability Management Specialist
Indexed description
We are growing. And we are looking for talented people.
At Decskill, we believe that technological excellence is driven by human talent.
We are an IT consulting company with more than 10 years of consolidated experience in the market, focused on building long-term relationships with both our clients and our people. Today, we are a community of over 800 professionals, working from Lisbon, Porto, and Madrid, contributing to impactful technology initiatives.
As part of the Astek Group, we combine a strong local culture with a global presence, being active in around 23 countries across 4 continents. This allows us to offer an international context, diverse challenges, and long-term career opportunities, while staying close to our teams.
We are looking for an Vulnerability Management Specialist!
Mission: We are looking for a Vulnerability Management Specialist to join the Corporate Cybersecurity function and contribute to the continuous improvement of the organisation’s overall cybersecurity posture.
The role has a transversal scope, requiring regular interaction with IT teams, Cybersecurity teams across different countries, business units and external stakeholders.
The successful candidate will be responsible for ensuring effective vulnerability identification, prioritisation, remediation and reporting, with a particular focus on vulnerability scanning, critical patch management, penetration testing and code security reviews.
Responsibilities:
Vulnerability Management:
- Ensure that all relevant assets are covered by vulnerability scanning tools and scanned regularly.
- Monitor the quality, coverage and successful execution of vulnerability scans.
- Analyse scan results and prioritise vulnerabilities based on their severity, exposure and potential business impact.
- Define and propose appropriate remediation plans in collaboration with the relevant teams.
- Follow up on remediation activities and ensure vulnerabilities are addressed within the expected timelines.
- Identify gaps in vulnerability coverage and drive corrective actions.
Critical Patch Management:
- Analyse information regarding critical security patches and identify impacted assets and environments.
- Alert the relevant teams regarding critical patches and required remediation actions.
- Monitor and follow up on the deployment of critical patches.
- Track remediation progress and identify delays or risks.
- Produce and communicate regular progress and status reports to relevant stakeholders.
Penetration Testing:
- Coordinate and monitor penetration testing activities.
- Request and follow up on penetration tests according to security requirements and identified needs.
- Analyse penetration testing results and identify critical findings.
- Prioritise vulnerabilities and define appropriate remediation actions.
- Monitor remediation activities through to closure.
- Assess the quality of penetration testing services and ensure alignment with corporate security requirements and standards.
- Coordinate with external penetration testing providers and challenge results or deliverables when required.
Code Security & Code Reviews:
- Ensure eligible internal and external assets are covered by the appropriate code review and security scanning tools.
- Monitor the regular execution and successful completion of code security scans.
- Analyse identified vulnerabilities and follow up on remediation activities.
- Identify gaps in code review coverage and ensure appropriate corrective actions are implemented.
Reporting & Cybersecurity Governance:
- Produce regular and ad-hoc cybersecurity reports covering vulnerability management, critical patches, penetration testing and code reviews.
- Consolidate information from multiple teams and stakeholders.
- Provide clear visibility on vulnerability exposure, remediation progress, outstanding risks and critical issues.
- Escalate significant risks, delays or remediation gaps to the appropriate stakeholders.
- Contribute to the continuous improvement of vulnerability management processes, tools and reporting.
Requirements:
- Minimum 5 years of professional experience in IT.
- Broad understanding of the IT landscape, including infrastructure, applications and technology environments.
- Strong analytical and problem-solving skills.
- Ability to analyse technical information and translate findings into clear remediation actions.
- Experience working with multiple stakeholders across different teams and/or countries.
- Strong reporting and documentation capabilities.
- Very good written and spoken English.
- Advanced Microsoft Excel skills, including the ability to analyse, consolidate and report on large datasets.
- Good level of english.
Nice to Have:
- Previous experience in Cybersecurity.
- Experience in Vulnerability Management.
- Knowledge of vulnerability scanning and remediation processes.
- Experience with Patch Management.
- Experience with Penetration Testing and security assessments.
- Knowledge of Application Security / Code Security.
- Experience working with cybersecurity tools and security dashboards.
- Experience in large, international and/or regulated organisations.
- Knowledge of corporate security requirements and standards.
Professional & Soft Skills:
- Strong analytical and organisational skills.
- Ability to manage multiple topics and priorities simultaneously.
- Strong attention to detail and follow-up capabilities.
- Ability to work with technical and non-technical stakeholders.
- Good communication and stakeholder management skills.
- Ability to challenge stakeholders and service providers when required.
- Proactive approach to identifying risks and remediation gaps.
- Ability to work independently while collaborating effectively with international teams.
- Strong sense of ownership and accountability.
- Ability to produce clear, concise and accurate reports.
- Comfortable working in a multicultural and international environment.
Are you looking for an environment that values curiosity and commitment? Here, your contribution has real impact and individual growth is taken seriously.
Find with us the right opportunity to grow!
What you can expect from us
- Long-term projects with national and international context.
- Opportunities to grow technically and professionally.
- A people-first culture, focused on transparency and trust.
- Teams that value ownership, collaboration and stability.
If you’re interested in this job, please send your CV to [email protected] with reference “CA/ VulnerabilityManagementSpecialist”.
Your next challenge might start here.
Join us! 😊
At Decskill, we are committed to equal opportunities and non-discrimination. We promote a culture of diversity and inclusion, where recruitment and career progression are based solely on talent, regardless of age, gender, ethnicity, race, nationality, or any other form of discrimination incompatible with human dignity.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search