Vulnerability Manager
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Job description
Context
Our client is seeking a Vulnerability Manager to strengthen and mature its enterprise vulnerability management programme. The role involves overseeing vulnerability identification, assessment, prioritisation, remediation, reporting, and stakeholder engagement across on-premises, cloud, workplace, and application environments. The Vulnerability Manager will lead a team of analysts and collaborate with SOC, Incident Response, Infrastructure, Cloud, Application, and Risk teams to ensure vulnerabilities are remediated according to risk-based SLAs and regulatory requirements.
Missions
-
Act as the Vulnerability Management (VM) single point of contact (SPOC) for the CISO Office.
-
Maintain evidence packs sufficient for audit purposes, including compliance with NIS2.
-
Produce and present monthly governance reports for the CISO Steering Committee.
-
Define and evolve the vulnerability management scope.
-
Design, improve, and own the end-to-end VM operating process from scan ingestion through verified closure (remediation scanning).
-
Establish and maintain the VM RACI across all delivery groups and external partners.
-
Define and maintain risk-based prioritisation criteria considering CVSS, exploitability, business criticality, and threat intelligence.
-
Define and enforce SLA definitions for Critical, High, Medium, and Low vulnerabilities.
-
Define and monitor vulnerability management KPIs and KRIs.
-
Engage with IT, business, and security stakeholders to drive remediation commitments and SLA compliance.
-
Hold remediation and patching teams accountable to agreed SLAs; monitor weekly results per group and environment.
-
Ensure rapid and efficient detection and prioritisation of vulnerabilities across servers, laptops, cloud platforms, applications, and containers.
-
Arbitrate detection-versus-capacity conflicts.
-
Track remediation actions and maintain a single reporting pane for coverage, attainment, ageing, and end-of-life trends.
-
Own and manage the exception register, ensuring every deviation has compensating controls, a named authority, and a hard expiry date.
-
Prepare Risk Management Board submissions for time-boxed exceptions.
-
Promote vulnerability management good practices across the organisation.
Tools & Environment
-
Vulnerability management tools: Qualys, AWS Inspector, Microsoft Defender VM
-
Multi-cloud environments: AWS, Azure
-
ITSM integration tools: Jira, ServiceNow
-
Familiarity with container security and NIS2 compliance
Working Conditions
-
Location: Brussels / Hybrid
-
Contract: Full-time (initial contract duration: 3 months, renewable)
Requirements
- 5+ years in vulnerability or patch management with direct programme ownership
- Strong understanding of the vulnerability Management Lifecycle, CVSS scoring methodologies, patch and remediation process, threat Intelligence and exploitability analysis, enterprise infrastructure, cloud and networking technologies
- Hands-on experience with Qualys, AWS Inspector, and Microsoft Defender VM
- Large-enterprise or public-sector background with significant legacy / technical-debt exposure
- Multi-cloud (AWS + Azure), container security, NIS2 familiarity; ITSM integration experience (Jira / ServiceNow)
- Strong analytical and reporting skills
- Fluent in English; Dutch and/or French is a plus