Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector
Employer · pt
Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector at Employer, based in pt. This is a permanent role.
- Salary
- Competitive
- Location
- pt
- Contract
- Permanent
- Posted
- 9 hours ago
- Closes
- 1 Oct 2026
- Sector
- Retail Security
Reference j_bb94ac28
About the role
Integration into a Threat Operations team, with responsibilities within the organization's Vulnerability Management Program, including vulnerability identification, prioritization, remediation SLA definition and tracking, and reporting. Manage the vulnerability lifecycle across infrastructure and endpoints, including analysis, prioritization (CVE, CVSS, KEV, exploitability, business context), and definition of remediation SLAs. Monitor and validate remediation or mitigation processes, identify SLA breaches, perform follow-ups, and escalate issues to the appropriate teams or management levels. Identify and monitor vulnerabilities within development pipelines (SSDLC), in coordination with the AppSec team. Assess and monitor the risk associated with technology obsolescence (End-of-Life / End-of-Support) across systems, applications, and components. Identify and analyze security findings across cloud environments, containers, and images, in collaboration with AppSec and Cloud Security teams. Critically validate the results generated by security tools, investigating false positives and confirming vulnerabilities. Ensure adequate coverage of the vulnerability management platform across the asset estate, in coordination with Infrastructure and Workplace teams. Produce vulnerability dashboards, KPIs, and reporting, including weekly status updates on critical vulnerabilities and remediation SLAs for management. Automate, document, and standardize operational procedures within the Vulnerability Management Program. Vulnerability Management Fundamental knowledge of Vulnerability Management concepts, including CVE, CVSS, KEV, exploitability, severity, prioritization, and remediation. Experience defining SLAs, monitoring remediation activities, conducting follow-ups, and escalating issues. Knowledge of technology obsolescence (EOL/EOS) and associated risk assessment. Experience creating dashboards and reports, with the ability to define and interpret KPIs. Knowledge of cloud security and cloud resources, including security findings analysis. Knowledge of container and container image vulnerabilities. Familiarity with the Secure Software Development Lifecycle (SSDLC) and SCA/SAST concepts. A critical approach to security tool results, with the ability to validate findings rather than assuming they are automatically accurate. Technical Knowledge Windows and Linux operating systems. Networking and protocols: TCP/IP, DNS, HTTP/HTTPS, ports, and services. Vulnerability Management platforms: Tenable One, CrowdStrike FEM. Cloud platforms, particularly Microsoft Azure and Google Cloud. Security tools integrated into development pipelines, including SCA, SAST, and IaC scanning. Soft Skills Effective communication with technical and operational teams. Ability to communicate with different levels of the organization, including management, translating technical information into business risk and impact. Strong analytical and problem-solving skills. Autonomy, organization, and prioritization skills in a high-volume vulnerability environment involving multiple teams. Certifications Certifications in cybersecurity and Vulnerability Management are considered an advantage, particularly: GIAC Enterprise Vulnerability Assessor (GEVA) — SANS SEC460. CompTIA CySA+ or CompTIA Security+. Cloud security certifications, such as Microsoft AZ-500 or Google Professional Cloud Security Engineer. Vendor certifications related to vulnerability scanning and management tools. What we offer: Professional development and monitoring talent; Commitment to our employees' development; Collaboration in a company that is constantly growing and evolving; Strong organizational culture: collaboration, sharing, flexibility, integrity and low ego. The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities. Devoteam Cyber Trust is the specialized cybersecurity unit of the Devoteam Group. With over 800 experts across the EMEA region, our mission is to position cybersecurity as a business enabler, not a barrier. We take a comprehensive approach to Cyber Resilience, Applied Security, and Security Service Management to safeguard the digital journey of large and mid-sized enterprises across all sectors and industries. Since 2009, previously known as INTEGRITY, our Portugal-based team has specialized in delivering cutting-edge Managed Security Services. By combining expertise with proprietary technology, we consistently and effectively reduce our clients' cyber risk. Our wide range of services includes Persistent Penetration Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. Certified in ISO 27001 (Information Security) and ISO 9001 (Quality), PCI-QSA, and members of CREST and CIS (C…
Reference: j_bb94ac28 · Posted 9 hours ago · Closes 1 Oct 2026 · Listed via Employer
Apply for this job
This role is listed via Employer. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.