Cyber Security Analyst II – Vulnerability
Indexed description
Are you passionate about Cyber Security and Vulnerability Management and enjoy working across infrastructure, cloud and engineering environments?
We are looking for a Cyber Security Analyst II – Vulnerability to join an international security team focused on identifying, assessing and reducing infrastructure vulnerabilities and strengthening the organization's overall security posture.
This is an opportunity to work on a broad range of security technologies and collaborate with Security, Infrastructure, Engineering, CSIRT and Offensive Security teams in a highly dynamic environment.
📍 Bucharest | Fixed-term contract until June 30, 2027
What will you do?
As part of the Infrastructure Vulnerability Management team, you will:
- Own and manage the infrastructure vulnerability scanning process and tools, ensuring alignment with vulnerability identification KPIs;
- Identify, triage, assign and follow up on infrastructure vulnerabilities, driving the remediation lifecycle through to resolution;
- Monitor and assess cloud vulnerability and compliance vulnerability assessment findings across different cloud environments;
- Monitor container and image scanning capabilities and analyse vulnerabilities to ensure effective remediation;
- Work closely with system and service owners, providing guidance on patching and vulnerability remediation;
- Collaborate with CSIRT teams on the detection, mitigation and remediation of security incidents and vulnerabilities;
- Validate moderately to highly complex vulnerability security reports and provide actionable recommendations;
- Work with Engineering teams on patch management, providing customized vulnerability reports, metrics and insights;
- Support infrastructure penetration testing assessments and PCI compliance assessments, including follow-up and remediation of identified findings;
- Drive remediation activities to ensure vulnerable assets are patched or addressed with compensating controls within agreed SLAs;
- Prepare vulnerability management reporting for technical teams, compliance stakeholders and management;
- Analyse vulnerability data and identify opportunities to improve infrastructure vulnerability management processes;
- Research new methods, tools and strategies for improving vulnerability identification and remediation.
What are we looking for?
- Bachelor's Degree or equivalent experience;
- 3–5 years of experience working in security practices;
- Advanced understanding of systems hardening and security configuration baselines, both from technical and procedural perspectives;
- Strong experience with infrastructure vulnerability scanning tools, including:
- Network vulnerability scanning
- Cloud vulnerability scanning
- Container scanning
- Image scanning
- Experience implementing and maintaining scanning tools across endpoints, bare-metal, cloud and container environments;
- Experience with Docker and Kubernetes, with a good understanding of container and image vulnerability remediation processes;
- Strong analytical, communication and negotiation skills, with excellent attention to detail;
- Ability to collaborate effectively with both technical and business stakeholders;
- Adaptability, customer focus, continuous learning and strong problem-solving skills.
Why this opportunity?
You will have the chance to work on enterprise-scale infrastructure security, across cloud and container environments, while collaborating with experienced Security and Engineering professionals.
If Vulnerability Management, Cloud Security, Docker, Kubernetes, penetration testing and security remediation are areas you enjoy working in, we'd love to hear from you.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search