Mid Vulnerability Manager
Retail group's digital and technology company operating across multiple markets. The role sits within a Threat Operations team responsible for the organization's vulnerability management program, covering identification, prioritization, remediation tracking, and reporting, with a strong focus on leveraging AI to improve operational efficiency.
What you will do
- Manage the vulnerability lifecycle across infrastructure and endpoints, including analysis, prioritization (CVE, CVSS, KEV, exploitability, business context) and definition of remediation SLAs
- Track and validate remediation and mitigation processes, identify SLA breaches, follow up and escalate to the relevant teams or management levels
- Identify and monitor vulnerabilities in development pipelines (SSDLC) in coordination with the application security team
- Assess and monitor risk associated with technology obsolescence (End-of-Life / End-of-Support) across systems, applications and components
- Identify and analyze security findings in cloud, container and image environments in collaboration with application and cloud security teams
- Critically validate security tooling outputs, investigating false positives and confirming vulnerabilities
- Produce dashboards, KPIs and reporting on vulnerabilities, including a weekly status update on critical vulnerabilities and SLAs for management
Location and work model
- Hybrid (2 days/week in the office, Porto)
-
Solid understanding of Vulnerability Management, including CVE, CVSS, KEV, exploitability, severity assessment, prioritization, and remediation;
-
Experience defining remediation SLAs, monitoring progress, following up with technical teams, and managing escalations;
-
Knowledge of technology obsolescence, including End of Life and End of Support risks;
-
Experience creating security dashboards and reports, as well as defining and interpreting relevant KPIs;
-
Knowledge of cloud security and experience analysing security findings across cloud resources;
-
Understanding of vulnerabilities affecting containers and container images;
-
Familiarity with Secure Software Development Lifecycle practices and security testing concepts such as SCA, SAST, and Infrastructure as Code scanning;
-
Ability to critically assess tool findings, validate their relevance, and identify false positives;
-
Good knowledge of Windows and Linux operating systems;
-
Understanding of network fundamentals and protocols, including TCP/IP, DNS, HTTP/HTTPS, ports, and services;
-
Experience with vulnerability management platforms such as Tenable One and CrowdStrike Falcon Exposure Management;
-
Experience with cloud platforms, particularly Microsoft Azure and Google Cloud Platform;
-
Strong analytical, organizational, and problem-solving skills;
-
Ability to manage and prioritize a high volume of vulnerabilities involving multiple teams;
-
Strong communication skills, with the ability to translate technical findings into clear business risks and impacts for technical teams, operational stakeholders, and management;
-
High level of autonomy, ownership, and attention to detail.
Nice to have
- Tenable
- CrowdStrike
- Azure
- Google Cloud Platform (GCP)
- TCP/IP
- DNS
What we offer:
- A project that matches your skills and ambitions, as well as your preferences for working policies and culture.
- A competitive salary with awesome benefits and opportunities to leverage your knowledge and network to earn additional income.
- An empowering and respectful work culture enriched with social and learning events.
- A People Experience Partner specially assigned to you - your go-to career guide, responsible for supporting your growth, facilitating training, and ensuring your work-life balance at KWAN.
What You Can Expect as a KWANer
Respect isn’t optional here
Dedicated People Experience Partner
Someone accountable for your growth, not your allocation.
Continuous learning, built in
Recognition that’s visible
A culture you can feel
Flexible spaces to work your way
Didn't find your mission yet?
Strong profiles don’t always match timing. That doesn’t mean there isn’t alignment.
We review every application. If there’s alignment, we won’t let it get lost in a database.