Vulnerability Management Expert
On-siteMedellín, Antioquia, Colombia or Guatemala City, Guatemala, Guatemala
Job Summary
Define the methodology and procedures for a tailored vulnerability management process aligned with global security strategy and industry best practices. Establish risk-based vulnerability management and penetration testing guidelines to prioritize remediations and reduce exposure to threats. Lead standardization efforts, develop key performance indicators for visibility, and manage vendor relationships to support process evolution. Provide high-level executive visibility on scope coverage, remediation progress, and risk status while acting as an advisor to internal and third-party stakeholders. Partner with in-country leaders to ensure compliance with global policies and collaborate with threat intelligence and response teams to integrate vulnerability data into broader security outcomes.
Required Qualifications
- Minimum of 10 years relevant experience in developing and managing information technology and security risk and compliance programs in a mid to large-scale enterprise environments
- At least 3 years in a management role leading a technical team
- Master's degree in relevant discipline (IT, Cyber Security)
- Qualified Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Offensive Security Certified Expert (OSCE), Offensive Security Certified Professional (OSCP), or equivalent professional qualification
- Experience of working in a complex multinational and multicultural corporate environment
- Understanding of global business and systems during previous roles in central IT functions and/or business units
- Ability to absorb new information and assess processes using a risk and control-based approach
- Detailed understanding and strong technical knowledge of cyber security matters, development and integration, vulnerability management, threat analysis and incident response (incl. MITRE ATT&CK), penetration testing / ethical hacking, data analytics and reporting
- Strong knowledge in IT controls, risk assessments, design and testing of security measures
- Experience with digital environments, mobile and web applications, service-oriented architectures, etc.
- Strong knowledge of core IP networking and common protocols
- Strong understanding of Windows and Linux internals
- Hands on experience with vulnerability management tools
- Experience and clear understanding of vulnerability scan reports, vulnerabilities analysis and technical recommendations for an effective and practical remediation
- Mixed skillset covering both offensive and defensive security
- Basic development and scripting skills
- Experience with modern offensive techniques and APT TTP's (tools, tactics, and techniques)
- Ability to judge when to support, when to intervene and when to escalate
- Excellent verbal, presentation, and written skills – fluent English, Spanish is a must
- Professionally skeptical mindset with ability to probe and challenge management information
- Root cause analysis - understanding an issue or complex problem and the key drivers behind it
- Solution oriented – partnering with subject matter experts (e.g., system and process owners) to articulate potential risks and defining detailed action plans to address identified vulnerabilities
- Business partnering mindset with ability to support and manage improvement will also holding stakeholders to account in relation to delivery timelines
- Tenacity, commitment and personal drive to deliver whatever it takes
- Agile and responsive, with proven track record of fast, accurate delivery to deadlines
- Attention to detail, and consistently demonstrate integrity and professionalism
- Take ownership of the process and drive changes throughout the organization without hierarchical authority
- Management skills
- Stakeholder management – ability to challenge and influence key stakeholders
- Cross functional engagement – proactive engagement with peers across corporate functions, partnering with colleagues across the regional and local teams including IT functions, Network function, Risks and Controls, and with external consultants
- Ability to work autonomously, effectively manage competing priorities and drive multiple concurrent workstreams
- Strong analytical and problem-solving skills
- Strong project management skills
- Must be available for international travel
- Must be based at any of the countries where we operate
Desired Qualifications
- Telecom's and Technology experience
- Experience working in emerging markets
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.