Sign up to save this job, get alerts, and apply with an optimized CV.
Cybersecurity Vulnerability Analyst
Job description
We are looking for someone who has: Minimum 2 years of experience in Cybersecurity, Vulnerability Management, or Security Operations. Ability to develop technical reports and translate analysis results into clear conclusions and recommendations. Knowledge of operating systems: Windows Server, Linux, basic knowledge of Unix systems. Knowledge of vulnerability classification systems: CVE, CVSS v3/v4, CWE. Ability to analyze manufacturer security bulletins. Experience working with Vulnerability Scanner/Management tools. Knowledge of the Patch Management process. Ability to analyze system logs. Highly developed communication skills – ability to clearly explain risks and remediation methods to both technical teams and management. Analytical thinking. Autonomy, very good self-organization, and the ability to work under time pressure. Knowledge of English enabling reading technical documentation (minimum B2). Nice to have: Experience working with systems: SIEM, EDR / XDR. Knowledge of: Active Directory, VMware, Containerization, cloud technologies. Possession of industry certifications e.g.: CompTIA Security+, CompTIA CySA+, EC-Council CEH, Tenable Certified Nessus Auditor, ISACA CISM, ISACA CRISC, OffSec PEN-200 / OSCP (an additional asset). Your task will be: Maintaining asset inventory and identifying the attack surface (IT infrastructure, cloud environments, applications) as a basis for vulnerability management. Performing cyclical vulnerability scans of IT infrastructure, cloud environments, and applications, including configuration and tuning of scanning tools. Analyzing scan results, eliminating false positives, and verifying and prioritizing vulnerabilities based on actual organizational risk. Assessing vulnerabilities using CVSS, CVE, CWE standards, and information about active exploitation of vulnerabilities (e.g., KEV, EPSS). Monitoring newly published vulnerabilities and analyzing their impact on the organization's environment. Recommending remediation methods and alternative risk mitigation actions (mitigation), taking into account feasibility in the given environment. Collaborating with system owners on risk assessment and prioritization. Collaborating with technical teams on planning and execution of remediation actions. Defining and monitoring remediation deadlines (SLA) depending on the risk level and tracking remediation progress. Verifying the effectiveness of implemented fixes and conducting retests. Managing the exception handling process and formal risk acceptance for vulnerabilities that cannot be fixed. Preparing reports, dashboards, and recommendations for technical teams and management, including reporting on process effectiveness metrics. Participating in the development and automation of the Vulnerability Management process in accordance with best practices and regulatory requirements. Collaborating with SOC, Incident Response, Threat Intelligence, and IT Operations teams. What do we offer? It depends on your needs: Do you need challenges? Interesting, ambitious, and responsible work in a dynamically developing team awaits you. Want to take care of yourself and your loved ones? We offer private medical care and group life insurance. Do you want to develop? With us, you will have many opportunities: training and development programs, co-financing for professional qualifications, promotion opportunities... Do you like physical activity? We have a Multisport card for you. Do you want to have a moment for yourself? We offer co-financing for rest and recreation.
Required skills
incident response
cloud technologies
active directory
cybersecurity
siem
edr
oscp
xdr
containerization
sla
security operations
vulnerability management
vmware
cvss
it operations
patch management
threat intelligence
soc
vulnerability scanner
comptia security+
cve
isaca cism
cwe
comptia cysa+
kev
ec-council ceh
tenable certified nessus auditor
isaca crisc
offsec pen-200
epss
Sign up to apply
Create a free account to apply for this job and get access to:
- AI-powered CV optimization for this specific job
- Save jobs and create custom alerts
- See your CV match score for each job
Company information
- Company
- NASK S.A.
- Location
-
Polska, mazowieckie, Warszawa
Poland - Posted
- 1 month ago
Interested in this position?
Create your free account and tailor your CV to match this job.