Vulnerability Management Specialist
Job Reference: 160660
Industry: Oil, Gas and Energy
Consultant Registration Number: R1982194
EA License Number: 02C3423
Key Responsibilities
- Assess vulnerabilities and prioritise remediation based on risk, severity, exploitability, asset criticality and operational impact.
- Coordinate with business, application, infrastructure and system teams on remediation plans, patch schedules and approved maintenance windows.
- Support patch deployment and validation across servers, applications, network devices, databases, cloud platforms and related systems.
- Validate patch stability, effectiveness and compatibility after implementation.
- Conduct periodic vulnerability scans across air-gapped systems, OT environments, cloud services and other in-scope assets.
- Support asset visibility and vulnerability scan coverage across relevant environments.
- Track KPIs/KRIs, vulnerability exposure, patch compliance, remediation progress and SLA adherence.
- Prepare dashboards, technical reports and management updates for the security council, senior management and relevant stakeholders.
- Prepare and review documentation for Change Requests, deviations, risk acceptances, remediation evidence, security reviews, risk assessments and audits.
- Facilitate remediation meetings with system owners and stakeholders, track action items, follow up on SLA breaches and escalate risks where required.
- Provide weekend or after-hours support for emergency patches, critical deployments or approved maintenance windows when required.
- Support process improvement through automation of reporting, patching, tracking and workflow activities.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, or related field.
- 5+ years’ experience in IT, OT, or network administration.
- Understanding of the vulnerability management lifecycle, patch management, CIS Benchmarks, ISO 27001, risk assessment and network security.
- Troubleshooting skills for patching, firmware upgrades, configuration changes and implementation issues.
- Ability to translate technical vulnerabilities into business risk, remediation priority and management-level updates.
Technical Specialisations
Candidates are expected to have experience in one or more of the following areas. Experience across multiple areas will be advantageous:
- Operating Systems & Virtualisation: Linux, Red Hat, Windows, VMware vCenter, ESXi and Kubernetes.
- Database Platforms: Microsoft SQL Server, Oracle and PostgreSQL.
- SAP Systems: SAP Kernel, Process Orchestration, support packages and SAP Notes.
- Application Stacks: Java, .NET, Apache, nginx, IIS and WebLogic.
- Network Systems: Routers, switches, firewalls, load balancers, ACI, Cisco, Arista, F5, Check Point, Palo Alto and network flow analysis.
- Vulnerability Management & Analytics: Vulnerability management platforms, dashboards, reporting, Microsoft Excel, Power BI, Microsoft Copilot or equivalent analytics tools.
- Automation & Scripting: PowerShell, Python, shell scripting, API integration and workflow automation.
Advantageous Experience
- Practical use of AI tools to summarise vulnerability data, generate reports, improve dashboards or identify remediation trends.
- Awareness of AI-related security risks and responsible use of enterprise AI tools.
- Experience supporting vulnerability remediation governance, deviation tracking, audit preparation or security council reporting.
