VULNERABILITY MANAGEMENT SPECIALIST (HYBRID)
Skills
About the role
VULNERABILITY MANAGEMENT SPECIALIST (HYBRID PORTO)
Portuguese company hires for hybrid position
Location: Porto, Portugal
️ Only candidates already based in Portugal will be considered
Work Model: Hybrid
️ Language Requirements: Very good written and spoken English (Mandatory)
Seniority: Senior (5+ years)
Sector: Banking
Rate Between €3600 - 3900 RV / €2400 - 2700 CTI
️ Instructions: Please send your CV in English and make sure to include all skills and experience that match the requirements of the opportunity. This will significantly increase your chances of success
About the Opportunity
You will join a corporate cybersecurity function responsible for ensuring that technology assets are regularly assessed, vulnerabilities are correctly prioritised, and remediation actions are completed within the expected timelines.
This transversal role provides exposure to different technology environments, business areas, and international cybersecurity teams. You will coordinate with asset owners, IT teams, security specialists, external providers, and other stakeholders to improve vulnerability-management processes and reduce cyber risk.
Main Responsibilities
Vulnerability Scanning
Ensure that all relevant technology assets are covered by approved vulnerability-scanning tools.
Monitor whether assets are scanned regularly and successfully.
Identify missing assets, scanning failures, and coverage gaps.
Analyse vulnerability-scan results.
Assess and prioritise vulnerabilities according to their severity, exposure, and business impact.
Define and propose appropriate remediation plans.
Follow up with the relevant entities and asset owners until remediation is completed.
Escalate overdue or high-risk vulnerabilities when necessary.
Produce regular and on-demand vulnerability reports.
Critical Patch Management
Analyse information concerning critical security patches.
Identify affected assets, systems, applications, and business perimeters.
Alert the teams and entities impacted by critical vulnerabilities and patches.
Monitor the deployment and implementation of critical patches.
Track remediation progress and identify delays or blockers.
Formalise and communicate clear progress reports to stakeholders.
Support risk-based prioritisation when immediate patching is not possible.
Penetration Testing
Coordinate and request penetration tests on behalf of internal entities.
Monitor the planning, execution, and delivery of penetration-testing activities.
Review and analyse penetration-test findings.
Prioritise identified weaknesses and propose remediation plans.
Monitor remediation activities through to closure.
Evaluate the quality of services delivered by penetration-testing providers.
Ensure testing services and reports comply with internal cybersecurity requirements.
Collaborate with internal stakeholders and external security providers.
Secure Code Review
Ensure that eligible internal and external applications are covered by code-review tools.
Monitor whether application code is scanned regularly and successfully.
Identify coverage gaps, scanning failures, and unresolved findings.
Follow up with development and application teams regarding remediation.
Support the improvement of application-security and secure-development practices.
Mandatory Requirements
Minimum of five years of professional experience in IT.
Broad understanding of IT systems, applications, infrastructure, and operational processes.
Experience or strong knowledge in vulnerability management.
Understanding of vulnerability scanning and remediation processes.
Ability to analyse technical security findings and prioritise remediation activities.
Knowledge of critical patch-management processes.
Understanding of penetration-testing activities and reporting.
Familiarity with application code reviews or security-scanning tools.
Experience coordinating with IT, cybersecurity, and application teams.
Ability to monitor remediation actions and ensure effective follow-up.
Experience producing regular and on-demand operational reports.
Advanced Microsoft Excel skills.
Strong analytical and organisational abilities.
Ability to lead meetings and communicate with different stakeholders.
Very good written and spoken English.
Availability to travel within Portugal and internationally.
Nice-to-Have Requirements
Previous professional experience in cybersecurity.
Experience in banking, insurance, financial services, or another regulated industry.
Knowledge of vulnerability-management tools such as Qualys, Tenable, Rapid7, or similar platforms.
Familiarity with CVE, CVSS, CWE, and vulnerability severity classification.
Experience with SAST, DAST, SCA, or secure code-review tools.
Knowledge of penetration-testing methodologies.
Understanding of risk acceptance and vulnerability-exception processes.
Experience with cybersecurity KPIs, dashboards, and executive reporting.
Knowledge of Power BI or other data-visualisation tools.
Familiarity with security standards or frameworks such as ISO 27001, NIST, CIS Controls, or OWASP.
Relevant cybersecurity certification.
Soft Skills
Rigorous and highly detail-oriented approach.
Dynamic and proactive attitude.
Strong focus on deliverables and deadlines.
Client- and stakeholder-oriented mindset.
Collaborative working style.
Ability to adapt to different teams and environments.
Resilience when managing competing priorities.
Strong analytical and problem-solving skills.
Confidence leading meetings and follow-up sessions.
Ability to communicate technical risks clearly.
Strong ownership of remediation and reporting activities.
The Ideal Profile
The ideal candidate is an experienced IT professional with a broad technical background and a strong interest in cybersecurity. You understand how applications, infrastructure, patching, scanning, and remediation processes interact and can use this knowledge to identify risk and coordinate effective corrective actions.
You are comfortable analysing scan and penetration-test results, prioritising findings, challenging remediation progress, and producing clear reports for technical and management stakeholders. You are organised, persistent, collaborative, and able to work effectively with international teams and external security providers.
Questions for Candidates
How many years of professional IT experience do you have?
How many years of experience do you have in cybersecurity or vulnerability management?
Which vulnerability-scanning tools have you used professionally?
Have you monitored vulnerability coverage across servers, applications, databases, or network assets?
Do you have experience analysing scan results and prioritising vulnerabilities?
Have you created and monitored vulnerability-remediation plans?
Do you have experience managing or tracking critical security patches?
How do you prioritise vulnerabilities when immediate remediation is not possible?
Have you coordinated penetration tests with internal teams or external providers?
Do you have experience reviewing penetration-test reports?
Have you monitored the remediation of penetration-testing findings?
Do you have experience with SAST, DAST, SCA, or code-review tools?
Are you familiar with CVE, CVSS, CWE, OWASP, NIST, CIS Controls, or ISO 27001?
Have you produced cybersecurity KPIs, dashboards, or management reports?
What is your level of proficiency with Microsoft Excel?
Do you have experience leading meetings with technical and business stakeholders?
Have you worked in banking, insurance, financial services, or another regulated industry?
Are you comfortable working with globally distributed teams?
What is your level of written and spoken English?
Are you based in Portugal and available to work from Porto?
Are you available to travel within and outside Portugal?
Which contract model do you prefer: B2B/RV or permanent employment/CTI?
What is your availability to start?
CV Keywords
Vulnerability Management Specialist, Vulnerability Management, Cybersecurity, Information Security, Corporate Cybersecurity, Vulnerability Assessment, Vulnerability Scanning, Security Scanning, Vulnerability Remediation, Remediation Management, Remediation Tracking, Patch Management, Critical Patches, Security Patching, Penetration Testing, Pentesting, Penetration Test Coordination, Secure Code Review, Application Security, AppSec, Static Application Security Testing, SAST, Dynamic Application Security Testing, DAST, Software Composition Analysis, SCA, CVE, CVSS, CWE, OWASP, Security Findings, Risk Assessment, Cyber Risk, Risk Prioritisation, Risk Acceptance, Security Exceptions, Asset Management, Asset Coverage, Security Controls, Qualys, Tenable, Nessus, Rapid7, InsightVM, Code Scanning, Security Testing, Security Reporting, Cybersecurity KPI, Dashboards, Microsoft Excel, Power BI, Root Cause Analysis, Remediation Plans, Stakeholder Management, Vendor Management, Financial Services, Banking, Insurance, ISO 27001, NIST Cybersecurity Framework, CIS Controls, English, Porto
#CI - PROC26465
Compensation
This Other role pays $4k/yr. Within typical range for other roles in Portugal.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.