Vulnerability and Exposure Management Specialist
2 days ago
Barcelona
ppSchwarz Digits creates the technological foundation for digital sovereignty in Europe. As the IT and digital division of the Schwarz Group, we develop and manage the IT infrastructures for the retail divisions Lidl and Kaufland, as well as Schwarz Production and PreZero. At the same time, we operate as an independent provider in the external market to support companies across Europe in their digital transformation. We bundle our core services in the areas of Cloud, Cyber Security, Data AI, Communication, and Workspace. /p pJoin us and contribute to digital sovereignty in Europe. With us, you will work at the intersection of agility and security: You will benefit from fast decision‑making processes, enjoy genuine creative freedom in your projects, and be able to build upon the stable foundation of the Schwarz Group. /p h3Your Tasks /h3 ul liJoin our dynamic Vulnerability Exposure Management Operations team, where we proactively strengthen the organization's security posture. We are a strategic partner dedicated to prioritising, assigning, advising, addressing and monitoring vulnerabilities and exposures in a structured and collaborative way. Our approach is founded on two core principles: robust governance to ensure our processes are consistent and reliable, and unwavering customer centricity to foster strong, collaborative partnerships with technical and business teams. /li liManage, maintain and optimize our already established processes and services to prioritise, assign, advise, address and monitor detected vulnerabilities and exposures. /li liActively work on new services, processes and projects, helping to define action plans and improvements, contributing with their operationalization and automatization. /li liAnalyze and triage vulnerabilities and exposures, applying risk‑based prioritization and environment context using different frameworks like CVSS. /li liCollaborate with asset owners, infrastructure teams, and other relevant stakeholders, providing clear, actionable guidance on secure configuration standards and best practices to facilitate effective remediation activities. /li liWork on the operationalization of the findings detected by our web application scanning tool, working and supporting directly the development teams on how to resolve web application based vulnerabilities and exposures. /li liDevelop and maintain remediation guidelines for security misconfigurations (Non‑CVE’s) in different environments (eg. Active Directory) and web applications related vulnerabilities and exposures to ensure consistent and effective risk reduction across multiple environments. /li liGenerate and present metrics, reports, and dashboards to communicate the effectiveness of current security and risk posture to stakeholders at all levels. /li liAct as the primary (1st level) point of contact for stakeholders, providing timely support, troubleshooting guidance, and driving engagement through targeted workshops, training sessions, and enablement initiatives. /li liStay updated on emerging threats, misconfigurations, and best practices for securing enterprise environments. /li /ul h3Your Profile /h3 ul li5–6 years of working experience on Cybersecurity Operations as a Security Analyst or similar role, with a focus on Vulnerability and Exposure Management. /li liStrong hands‑on experience with vulnerability and exposure management tools (e.g., Tenable, Burp Suite, XM Cyber). /li liSolid understanding of security misconfigurations (Non‑CVE’s) and CVE’s, and their remediation techniques. /li liKnowledge of security industry‑standard frameworks and methodologies, such as OWASP for web applications and APIs. /li liKnowledge of operating systems (Windows, Linux), networking principles, web application architecture and IAM environments (eg. Active Directory). /li liExcellent communication and interpersonal skills, with a proven ability to translate complex technical issues for diverse audiences. /li liProficiency with IT service management or ticketing systems (e.g., Jira, ServiceNow). /li liFluent English, written and spoken. /li liLove to work with customers and satisfy their needs. /li liGood work quality. /li liTasks prioritization. /li liIndependent working ability. /li liAbility to document. /li liProfessional behaviour. /li liCapacity of team work. /li liSelf‑critical thinking and acting. /li liIndependence. /li liInitiative. /li liWillingness to learn. /liliFlexibility to changes. /li /ul h3Nice to Have /h3 ul liKnowledge of security best practices in cloud environments (AWS, Azure, GCP). /li liFamiliarity with assessing and remediating security misconfigurations based on frameworks like CIS Benchmarks. /li liBasic scripting skills (Python, PowerShell) for task automation or data analysis. /li liRelevant security certifications (e.g., CISSP, CEH, Security+). /li /ul /p #J-18808-Ljbffr