сегодня

vulnerability management consultant

ориентир по рынку
вакансия зп не указана
в среднем 346 799 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

описание

The project provides cybersecurity and digital services for international organizations in a complex multi-tenant environment. It includes cyber defense operations, security incident management, and continuous protection of critical systems and services to support secure and reliable operations worldwide.

задачи

  • Run and improve the end-to-end vulnerability management process, including discovery, scanning, prioritization, remediation tracking, and verification
  • Configure and operate vulnerability scanning tools for infrastructure, cloud, and web applications
  • Prioritize vulnerabilities by risk using CVSS, EPSS, exploitability, threat intelligence, and asset criticality
  • Coordinate remediation with IT, application, and infrastructure owners across multiple client organizations
  • Manage exceptions and risk acceptance, and track SLA compliance
  • Produce KPI/KRI reports and dashboards for technical and management audiences
  • Advise on patch management, hardening baselines such as CIS Benchmarks, and attack surface reduction

требования

  • At least 5 years of cybersecurity experience, including at least 3 years in vulnerability management
  • Hands-on experience with at least one enterprise scanning platform: Tenable Nessus, Tenable.io, Tenable.sc, Qualys VMDR, Rapid7 InsightVM, or Microsoft Defender Vulnerability Management
  • Experience with risk-based prioritization using CVSS, EPSS, CISA KEV, and asset criticality
  • Experience coordinating remediation across multiple teams and tracking SLAs
  • Knowledge of patch management for Windows, Linux, and network devices, and of CIS hardening standards
  • Clean record and readiness for background verification
  • Upper-Intermediate English or higher
  • Будет плюсом: cloud security posture management tools such as Defender for Cloud, Wiz, or Prisma Cloud; web application and container scanning; attack surface management tools; knowledge of ISO 27001 or NIST CSF; Python or PowerShell scripting for reporting automation and API integrations; CISSP, CompTIA Security+, CySA+, or vendor certifications such as Tenable or Qualys

условия

  • Opportunity to change projects and develop expertise in an interesting business domain
  • Professional, financial, and career growth; mentoring and onboarding systems for each new employee
  • Opportunity to earn up to an additional 1,000 EUR per month depending on expertise, included in the annual bonus, by participating in company activities
  • Access to the corporate training portal and its regularly updated knowledge base
  • Corporate events and perks, including parties, pizza days, PlayStation, fruit, coffee, snacks, and movies
  • Certification compensation, including AWS and PMP
  • Referral program
  • Private health insurance and sports compensation, depending on the type of employment

Международная компания по разработке ПО и цифровой трансформации с услугами заказной разработки и staff augmentation.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.