Specialist - Vulnerability Management
On-site · Dubai, Dubai, United Arab Emirates or Abu Dhabi, Abu Dhabi, United Arab Emirates
Job Summary
Specialist – Vulnerability Management embedded within a major banking client to oversee the continuous discovery, analysis, and tracking of vulnerabilities across enterprise networks, systems, and applications; coordinating remediation with administrators, engineers, and owners; ensuring remediation aligns with SLAs and banking regulatory baselines; providing accurate vulnerability metrics, risk summaries, and governance-ready reporting.
Required Qualifications
- Vulnerability Tool Proficiency: operating enterprise-scale vulnerability scanning platforms (e.g., Qualys, Tenable Nessus, Rapid7, or cloud-native security utilities)
- Risk Assessment: understanding CVSS v3/v4 and prioritization based on exploitability
- Security Frameworks: knowledge of NIST CSF, CIS Benchmarks, ISO/IEC 27001
- Technical Troubleshooting: OS architectures, network configurations, and patching understandings
- Collaborative Communication: ability to convey security findings to non-security teams
- Essential Experience: minimum 4 years in corporate cybersecurity, including vulnerability identification/patch tracking or security auditing; experience in financial services context and consulting delivery
- System Administration Foundation: experience with Windows Server, Linux, and core network configurations
- Professional Certifications: relevant designations (e.g., CompTIA Security+, CEH, GIAC certifications)
- Cloud Infrastructure Security: understanding of cloud vulnerability vectors (AWS/Azure) and container security
- Automation Familiarity: scripting skills (PowerShell, Bash, Python) for reporting and data cleanup
- Compliance & Change Management: experience aligning with ITIL or equivalent change processes
Desired Qualifications
- Vulnerability Tool Proficiency in enterprise-scale scanning platforms (e.g., Qualys, Tenable Nessus, Rapid7, or cloud-native tools)
- Risk assessment using CVSS v3/v4
- Knowledge of security frameworks (NIST CSF, CIS Benchmarks, ISO/IEC 27001)
- Technical troubleshooting across OS architectures, networks, and patches
- Strong collaborative communication to convey security findings to non-security teams
- Professional experience in corporate cybersecurity, ideally in financial services or regulated environments
- Consulting or professional services background with SLAs and timelines
- Windows Server and Linux system administration experience
- Cloud security concepts (AWS/Azure) and containerization understanding
- Scripting ability (PowerShell, Bash, Python) to support automation and reporting
- Relevant security certifications (e.g., CompTIA Security+, CEH, GIAC Enterprise Vulnerability Assessor)
- Familiarity with vulnerability remediation lifecycle and change management processes
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.