Sii Poland

SII UKRAINE

SII SWEDEN

  • Trainings
  • Career
Join us Contact us
Back

Sii Poland

SII UKRAINE

SII SWEDEN

Back

Senior Application Vulnerability Management Consultant - Immediate Availability (f/m/x)

  • Senior
  • Remote, 
  • Hybrid, 
  • Office
  • Multiple locations Show all
This translation is generic and may include errors. Show original text
This offer base language is Polish. Translate into English.

Technologies & tools

We are looking for an experienced individual for the position of Senior Application Vulnerability Management Analyst to join the team responsible for developing and operationally managing the application vulnerability management process in a modern enterprise environment. You will be responsible for designing and maintaining vulnerability management processes, collaborating with development teams, DevOps, and security operations to improve vulnerability visibility and increase SLA compliance. If you are passionate about application security and want to impact the improvement of security within the organization, this offer is for you.

Your tasks

  • Designing and maintaining application vulnerability management processes and remediation processes
  • Analyzing and prioritizing vulnerabilities based on risk criteria such as CVSS, EPSS, exploitability, application criticality, data sensitivity, and production exposure
  • Monitoring and classifying results from SAST, DAST, and Software Composition Analysis (SCA) tools
  • Coordinating remediation efforts with development and DevOps teams, ensuring clear accountability
  • Creating and managing workflows in Jira, tickets, deadlines, and escalation paths for security findings
  • Tracking remediation SLAs, following up on overdue vulnerabilities, and coordinating risk acceptance or exception processes as needed
  • Verifying remediation through re-scanning and validation actions before closure
  • Developing operational dashboards, KPIs, and management reports regarding risk exposure, aging vulnerabilities, and remediation performance
  • Automating security processes, including ticket generation, assigning responsibilities, notifications, SLA tracking, reporting, and re-scanning
  • Driving continuous improvements in vulnerability management processes, automation capabilities, scanning coverage, and developer engagement

Requirements

  • Minimum 5 years of experience in Cyber Security, Application Security, or Vulnerability Management
  • Practical knowledge of application vulnerability management and remediation processes
  • Previous work with SAST, DAST, SCA tools, and Snyk-class platforms
  • Strong knowledge of DevSecOps, SDLC, and CI/CD processes
  • Ability to assess risk using CVSS, EPSS metrics, and business criteria
  • Experience working with Jira and coordinating efforts between technical teams
  • Knowledge of security process automation and reporting
  • Very good command of English - minimum B2 level

Job no. JOB-2YB6R

Sii ensures that all hiring decisions are made solely on the basis of qualifications and competence. We are committed to equal and fair treatment of all, regardless of legally protected characteristics. At Sii, we promote a diverse and inclusive work environment, in full compliance with applicable anti-discrimination laws.

Technologie i narzędzia

Szukamy doświadczonej osoby na stanowisko Senior Application Vulnerability Management Analyst, która dołączy do zespołu odpowiedzialnego za rozwój i operacyjne prowadzenie procesu zarządzania podatnościami aplikacji w nowoczesnym środowisku enterprise. Będziesz odpowiedzialny za projektowanie i utrzymywanie procesów zarządzania podatnościami, współpracując z zespołami deweloperskimi, DevOps oraz operacjami bezpieczeństwa w celu poprawy widoczności podatności i zwiększenia zgodności z SLA. Jeśli pasjonujesz się bezpieczeństwem aplikacji i chcesz wpływać na poprawę bezpieczeństwa w organizacji, ta oferta jest dla Ciebie.

Twoje zadania

  • Projektowanie i utrzymywanie procesów zarządzania podatnościami aplikacji oraz procesów naprawczych
  • Analiza i priorytetyzacja podatności na podstawie kryteriów ryzyka, takich jak CVSS, EPSS, możliwość wykorzystania, krytyczność aplikacji, wrażliwość danych i ekspozycja w produkcji
  • Monitorowanie i klasyfikowanie wyników z narzędzi SAST, DAST oraz analizy składu oprogramowania (SCA)
  • Koordynowanie działań naprawczych z zespołami deweloperskimi i DevOps, zapewniając jasną odpowiedzialność
  • Tworzenie i zarządzanie przepływami pracy w Jira, zgłoszeniami, terminami i ścieżkami eskalacji dla ustaleń bezpieczeństwa
  • Śledzenie SLA naprawczych, follow-up w przypadku przeterminowanych podatności oraz koordynowanie procesów akceptacji ryzyka lub wyjątków w razie potrzeby
  • Weryfikowanie naprawy poprzez ponowne skanowanie i działania walidacyjne przed zamknięciem
  • Rozwój operacyjnych pulpitów nawigacyjnych, KPI oraz raportów zarządzających dotyczących ekspozycji na ryzyko, starzejących się podatności i wydajności naprawy
  • Automatyzacja procesów bezpieczeństwa, w tym generowanie zgłoszeń, przypisywanie odpowiedzialności, powiadomienia, śledzenie SLA, raportowanie i ponowne skanowanie
  • Napędzanie ciągłych ulepszeń w procesach zarządzania podatnościami, możliwościach automatyzacji, pokryciu skanowania i zaangażowaniu deweloperów

Wymagania

  • Minimum 5 lat doświadczenia w obszarze Cyber Security, Application Security lub Vulnerability Management
  • Praktyczna znajomość zarządzania podatnościami aplikacyjnymi oraz procesów remediacji
  • Wcześniejsza praca z narzędziami SAST, DAST, SCA oraz platformami klasy Snyk
  • Bardzo dobra znajomość zagadnień DevSecOps, SDLC oraz procesów CI/CD
  • Umiejętność oceny ryzyka z wykorzystaniem wskaźników CVSS, EPSS i kryteriów biznesowych
  • Doświadczenie w pracy z Jira oraz koordynacji działań między zespołami technicznymi
  • Znajomość automatyzacji procesów bezpieczeństwa i raportowania
  • Bardzo dobra znajomość języka angielskiego - poziom minimum B2

Nr oferty JOB-2YB6R

Sii ensures that all hiring decisions are made solely on the basis of qualifications and competence. We are committed to equal and fair treatment of all, regardless of legally protected characteristics. At Sii, we promote a diverse and inclusive work environment, in full compliance with applicable anti-discrimination laws.

Quick apply

Senior Application Vulnerability Management Consultant - Immediate Availability (f/m/x)

Work mode*

Choose at least one option

Option was not selected

angle-down

Option was not selected

Attach CV*

Uploaded file:
  • file_icon Created with Sketch.

Acceptable files: doc, docx, pdf. (max 5MB)
Please submit your file in DOC, DOCX or PDF format
The upload size is limited to 5 MB
File is empty
File was not uploaded

At any time, you may withdraw your consent to the processing of personal data, but such withdrawal shall not affect the legal compliance of any processing of such data, which had occurred before you withdrew your consent. Detailed information on the processing of your personal data is specified in the Sii Poland Group Privacy Policy.

Sii Poland Group follows the Procedure for reporting law violations.

Create MySii account to follow your application's status
success

Your application has been submitted

We will contact you as soon as we review your CV

Processing...

Sorry, something went wrong and your message was not delivered

Refresh the page and try again. Contact us, if problem occurs again

We’re sorry, but the selected file appears to be damaged and we can't process it.

Please try uploading a different copy or a new version of the file. Contact us, if problem occurs again.

Benefits for you

  • Great Place to Work
  • Solid financial situation
  • Contracts with the biggest brands
  • Centre of internal trainings
  • Many experts you can learn from
  • Open and accessible management team
  • Profit sharing
  • Passion Sponsorship program
  • Regular integration events and trips
  • Comfortable and well-equipped offices
  • MySii app
  • Medical care
Apply now Recommend a friend

Änderungen im Gange

Wir aktualisieren unsere deutsche Website. Wenn Sie die Sprache wechseln, wird Ihnen die vorherige Version angezeigt.

Einige Inhalte sind nicht in deutscher Sprache verfügbar.
Sie werden zur englischen Version der ausgewählten Seite weitergeleitet.

Möchten Sie fortfahren?

Einige Inhalte sind nicht in deutscher Sprache verfügbar.
Sie werden auf die deutsche Homepage weitergeleitet.

Möchten Sie fortsetzen?

Ta treść jest dostępna tylko w jednej wersji językowej.
Nastąpi przekierowanie do strony głównej.

Czy chcesz opuścić tę stronę?