Vulnerability Manager

Il y a 8 heures

Brussels, Brussels, Belgique Collective.work Temps plein

Job description

Context

Our client is seeking a Vulnerability Manager to strengthen and mature its enterprise vulnerability management programme. The role involves overseeing vulnerability identification, assessment, prioritisation, remediation, reporting, and stakeholder engagement across on-premises, cloud, workplace, and application environments. The Vulnerability Manager will lead a team of analysts and collaborate with SOC, Incident Response, Infrastructure, Cloud, Application, and Risk teams to ensure vulnerabilities are remediated according to risk-based SLAs and regulatory requirements.

Missions

  • Act as the Vulnerability Management (VM) single point of contact (SPOC) for the CISO Office.

  • Maintain evidence packs sufficient for audit purposes, including compliance with NIS2.

  • Produce and present monthly governance reports for the CISO Steering Committee.

  • Define and evolve the vulnerability management scope.

  • Design, improve, and own the end-to-end VM operating process from scan ingestion through verified closure (remediation scanning).

  • Establish and maintain the VM RACI across all delivery groups and external partners.

  • Define and maintain risk-based prioritisation criteria considering CVSS, exploitability, business criticality, and threat intelligence.

  • Define and enforce SLA definitions for Critical, High, Medium, and Low vulnerabilities.

  • Define and monitor vulnerability management KPIs and KRIs.

  • Engage with IT, business, and security stakeholders to drive remediation commitments and SLA compliance.

  • Hold remediation and patching teams accountable to agreed SLAs; monitor weekly results per group and environment.

  • Ensure rapid and efficient detection and prioritisation of vulnerabilities across servers, laptops, cloud platforms, applications, and containers.

  • Arbitrate detection-versus-capacity conflicts.

  • Track remediation actions and maintain a single reporting pane for coverage, attainment, ageing, and end-of-life trends.

  • Own and manage the exception register, ensuring every deviation has compensating controls, a named authority, and a hard expiry date.

  • Prepare Risk Management Board submissions for time-boxed exceptions.

  • Promote vulnerability management good practices across the organisation.

Tools & Environment

  • Vulnerability management tools: Qualys, AWS Inspector, Microsoft Defender VM

  • Multi-cloud environments: AWS, Azure

  • ITSM integration tools: Jira, ServiceNow

  • Familiarity with container security and NIS2 compliance

Working Conditions

  • Location: Brussels / Hybrid

  • Contract: Full-time (initial contract duration: 3 months, renewable)

Requirements

  1. 5+ years in vulnerability or patch management with direct programme ownership
  2. Strong understanding of the vulnerability Management Lifecycle, CVSS scoring methodologies, patch and remediation process, threat Intelligence and exploitability analysis, enterprise infrastructure, cloud and networking technologies
  3. Hands-on experience with Qualys, AWS Inspector, and Microsoft Defender VM
  4. Large-enterprise or public-sector background with significant legacy / technical-debt exposure
  5. Multi-cloud (AWS + Azure), container security, NIS2 familiarity; ITSM integration experience (Jira / ServiceNow)
  6. Strong analytical and reporting skills
  7. Fluent in English; Dutch and/or French is a plus