Vulnerability Management Specialist

  •  Job Reference: 160660
  •  Industry: Oil, Gas and Energy
  •  Consultant Registration Number: R1982194
  •  EA License Number: 02C3423

Key Responsibilities

  • Assess vulnerabilities and prioritise remediation based on risk, severity, exploitability, asset criticality and operational impact.
  • Coordinate with business, application, infrastructure and system teams on remediation plans, patch schedules and approved maintenance windows.
  • Support patch deployment and validation across servers, applications, network devices, databases, cloud platforms and related systems.
  • Validate patch stability, effectiveness and compatibility after implementation.
  • Conduct periodic vulnerability scans across air-gapped systems, OT environments, cloud services and other in-scope assets.
  • Support asset visibility and vulnerability scan coverage across relevant environments.
  • Track KPIs/KRIs, vulnerability exposure, patch compliance, remediation progress and SLA adherence.
  • Prepare dashboards, technical reports and management updates for the security council, senior management and relevant stakeholders.
  • Prepare and review documentation for Change Requests, deviations, risk acceptances, remediation evidence, security reviews, risk assessments and audits.
  • Facilitate remediation meetings with system owners and stakeholders, track action items, follow up on SLA breaches and escalate risks where required.
  • Provide weekend or after-hours support for emergency patches, critical deployments or approved maintenance windows when required.
  • Support process improvement through automation of reporting, patching, tracking and workflow activities.

 

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, or related field.
  • 5+ years’ experience in IT, OT, or network administration.
  • Understanding of the vulnerability management lifecycle, patch management, CIS Benchmarks, ISO 27001, risk assessment and network security.
  • Troubleshooting skills for patching, firmware upgrades, configuration changes and implementation issues.
  • Ability to translate technical vulnerabilities into business risk, remediation priority and management-level updates.

 

Technical Specialisations

Candidates are expected to have experience in one or more of the following areas. Experience across multiple areas will be advantageous:

  • Operating Systems & Virtualisation: Linux, Red Hat, Windows, VMware vCenter, ESXi and Kubernetes.
  • Database Platforms: Microsoft SQL Server, Oracle and PostgreSQL.
  • SAP Systems: SAP Kernel, Process Orchestration, support packages and SAP Notes.
  • Application Stacks: Java, .NET, Apache, nginx, IIS and WebLogic.
  • Network Systems: Routers, switches, firewalls, load balancers, ACI, Cisco, Arista, F5, Check Point, Palo Alto and network flow analysis.
  • Vulnerability Management & Analytics: Vulnerability management platforms, dashboards, reporting, Microsoft Excel, Power BI, Microsoft Copilot or equivalent analytics tools.
  • Automation & Scripting: PowerShell, Python, shell scripting, API integration and workflow automation.

 

Advantageous Experience

  • Practical use of AI tools to summarise vulnerability data, generate reports, improve dashboards or identify remediation trends.
  • Awareness of AI-related security risks and responsible use of enterprise AI tools.
  • Experience supporting vulnerability remediation governance, deviation tracking, audit preparation or security council reporting.