Our client is looking for a Vulnerability Analyst / Exposure Management Analyst
Position Title
Group Vulnerability Analyst
Alternative title: Exposure Management Analyst
Company
Our client is a leading international company undergoing a major digital transformation. Under its strategic transformation program, the organization is simplifying a previously complex portfolio of business entities into distinct commercial business units to drive growth across Western Europe, North America, and Asia.
Cyber security is a critical enabler of the organization’s operations, service continuity and digital transformation.
As the Group becomes more connected and digitally integrated, cyber security must evolve from a fragmented, local responsibility to a coherent, Group-level capability.
To support this, the Group has launched a Cyber Security Improvement Plan focused on strengthening core security foundations, increasing maturity across entities and enabling secure digital products and operations.
Key capabilities at Group level include Identity & Access Management, SOC and Network Security, supported by a federated operating model combining Group standards and platforms with local execution.
Mission
The Group Vulnerability Analyst is part of the Group Cyber Centers of Excellence (CoE) and coordinates vulnerability discovery, analysis, prioritisation, reporting and remediation follow-up across the Group.
The role ensures that vulnerabilities are visible, risk-ranked, assigned to the right owners and followed through until remediation or formal risk acceptance.
This is a coordination, analysis and follow-up role — not a local IT operations or patching role.
Position Overview
The Vulnerability Analyst operates within the Group Cyber Security Operations capability and works closely with Entity VM SPOCs, Entity Security SPOCs, IT Operations, Group SOC, outsourcing partners and IT SWAT.
The role supports the Group in building a consistent view of exposure across entities, enabling faster remediation decisions and reducing the window of attack exposure.
This aligns with the VM initiative’s ambition to move from fragmented visibility and manual follow-up towards a more coordinated, intelligence-led exposure management capability.
Key Responsibilities
1. Vulnerability Discovery Coordination
- Coordinate vulnerability discovery activities across in-scope entities, platforms and asset groups.
- Support onboarding of entities into the Group VM platform and ensure discovery coverage is progressing.
- Work with VM Tooling Engineers and outsourcing partners to validate scan scope, asset coverage, scan quality and data completeness.
- Identify blind spots in asset visibility, scan coverage or entity onboarding.
2. Vulnerability Analysis & Prioritisation
- Assist entities in analyzing vulnerability findings and support risk-based prioritization using severity, exploitability, exposure, asset criticality and business context.
- Work with Entity VM SPOCs and IT Operations to validate findings, false positives and remediation feasibility.
- Support prioritization of urgent vulnerabilities, critical exposures and emerging threats.
- Translate technical findings into actionable remediation priorities for IT teams.
3. Remediation Follow-Up
- Track remediation progress across entities, owners and technology domains.
- Follow up with Entity VM SPOCs and IT Operations on overdue, high-risk or recurring vulnerabilities.
- Escalate blocked remediation items through the agreed governance channels.
- Ensure remediation status, exceptions and risk acceptances are properly documented.
4. Reporting & Governance
- Produce recurring vulnerability and exposure reports for Group Security, Entity Security SPOCs, IT leadership and governance bodies.
- Maintain dashboards on vulnerability posture, remediation progress, ageing, SLA adherence and risk exposure.
- Provide clear management summaries on key risks, blockers, trends and required decisions.
- Support evidence gathering for audit, compliance, NIS2 readiness and internal control assurance.
5. Stakeholder Coordination
- Act as the operational coordination point between Group Cyber CoE, outsourcing partners, Entity VM SPOCs, Entity Security SPOCs and IT Operations.
- Facilitate remediation meetings and exposure review sessions.
- Promote consistent working practices across entities while respecting the federated operating model.
- Support entities in understanding priorities, expectations and remediation responsibilities.
6. Continuous Improvement
- Identify recurring root causes, systemic weaknesses and process improvement opportunities.
- Contribute to improving vulnerability workflows, dashboards, prioritisation rules and escalation mechanisms.
- Support future evolution towards automation, contextualised prioritisation and integration with ITSM/CMDB platforms.
Key Deliverables
- Group vulnerability posture reports.
- Entity remediation follow-up dashboards.
- Prioritised vulnerability action lists.
- Exception and risk acceptance tracking.
- Coverage and scan quality reports.
- Input to SteerCo / CDO / CISO reporting.
- Escalation packs for overdue or high-risk remediation.
Required Experience
- Minimum of three years experience in a similar role.
- Experience in vulnerability management, security operations, IT operations, infrastructure security or risk management.
- Good understanding of vulnerability scanning, asset discovery, CVEs, CVSS, exploitability and remediation workflows.
- Experience working with infrastructure, cloud, network, endpoint or application teams.
- Experience with tools such as Qualys, Tenable, Rapid7, Defender Vulnerability Management or similar.
- Experience in federated, multi-entity or complex enterprise environments would be a major bonus.
Skills & Competencies
- Strong analytical mindset.
- Ability to translate technical vulnerabilities into business-relevant risk priorities.
- Strong coordination and follow-up discipline.
- Good stakeholder management across security and IT teams.
- Structured reporting and executive communication skills.
- Pragmatic, persistent and outcome-driven.
- Able to operate without direct hierarchical authority.
Success Measures
- Improved visibility of Group vulnerability exposure.
- Reduced ageing of critical and high vulnerabilities.
- Improved remediation follow-up discipline across entities.
- Clear ownership of vulnerability findings.
- Fewer unresolved or unassigned critical exposures.
- Better quality reporting for Group and entity leadership.