Product Security Analyst - Vulnerability Management

Reference: ADGProdSecAnalayst _1791555917

Product Security Analyst - Vulnerability Management

Department

Software Technology

Reports to

Business Information Security Officer (BISO)

Role Summary

We are seeking a Product Security Analyst - Vulnerability Management to operate and continuously improve the vulnerability management lifecycle across software products, cloud environments, and supporting technology platforms.

The role consolidates security findings, validates and prioritizes exposure using technical and business context, coordinates accountable remediation, and provides reliable product security posture reporting.

The successful candidate is technically credible, analytical, and highly structured, working closely with product and engineering teams to reduce risk rather than merely administer findings. This is a product security and vulnerability management role, not a 24/7 SOC monitoring position.

Responsibilities

  • Operate the end-to-end vulnerability management process across applications, APIs, cloud services, infrastructure components, containers, and third-party dependencies.
  • Consolidate findings from vulnerability scanners, penetration tests, application security tools, cloud security services, vendor advisories, and enterprise cybersecurity sources.
  • Validate findings, remove duplicates and false positives, and enrich records with asset ownership, exposure, exploitability, and business context.
  • Prioritize vulnerabilities using severity, known exploitation, reachability, internet exposure, compensating controls, product criticality, and customer impact.
  • Assign accountable remediation owners, agree target dates, track progress, challenge overdue items, and verify closure evidence.
  • Maintain an accurate inventory and mapping of covered products, repositories, services, and technical owners in coordination with Product, Architecture, and Platform teams.
  • Develop and maintain vulnerability dashboards, heatmaps, KRIs, and aging metrics for security leadership, business leadership, product teams, and governance forums.
  • Identify systemic weakness patterns and recommend preventive actions, platform improvements, secure configurations, and remediation campaigns.
  • Support risk treatment and exception workflows by preparing evidence, documenting residual exposure, and escalating material or overdue risks.
  • Coordinate operational follow-up from penetration tests, audits, incidents, external disclosures, and security advisories.
  • Perform focused vulnerability assessments and technical validation using approved tools and methods.
  • Monitor emerging vulnerabilities and threat intelligence relevant to the technology stack and initiate rapid assessment when urgent exposure is suspected.
  • Use CISA Known Exploited Vulnerabilities and other verified threat intelligence as inputs to risk-based vulnerability prioritization.
  • Use EPSS as one empirical exploitation likelihood signal alongside CVSS, reachability, exposure, product criticality, and customer impact.
  • Support Cyber Resilience Act reporting readiness through rapid assessment of active exploitation, evidence collection, and escalation to security leadership.
  • Maintain visibility of product versions, declared support periods, and end-of-support status to inform vulnerability treatment and customer obligations.
  • Use SBOM and dependency data to determine which products, versions, and services contain affected components and accelerate impact assessment.
  • Support security advisories, customer notifications, and coordinated vulnerability disclosure with Product Management, Legal, Quality, and Security stakeholders.
  • Support audit, regulatory, and ISO 27001 evidence requirements related to vulnerability management and operational security controls.
  • Collaborate with Application Security, DevSecOps, Platform Engineering, and Security teams on complex findings, scanning coverage, and automation.
  • Continuously improve workflows, service levels, data quality, and reporting to drive measurable exposure reduction.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience.
  • Several years of experience in vulnerability management, vulnerability analysis, security operations, cloud security, or a related technical cybersecurity role.
  • Hands-on experience with vulnerability scanning and security posture tools across applications, cloud, or infrastructure environments.
  • Strong understanding of CVE, CVSS, common vulnerability classes, exploitability, attack paths, and risk-based prioritization.
  • Ability to validate findings using logs, configurations, source information, command-line tools, and targeted technical testing.
  • Knowledge of cloud services, operating systems, networks, containers, identity and access management, APIs, and software dependencies.
  • Experience managing remediation workflows, security exceptions, evidence, and service-level reporting.
  • Strong data analysis skills and experience producing dashboards, metrics, and concise management reporting.
  • Excellent analytical, organizational, and problem-solving skills with strong attention to data quality.
  • Ability to communicate clearly with engineers, product owners, and senior stakeholders and drive accountable follow-through.
  • Strong written and verbal communication skills in English.
  • High level of integrity, judgment, and commitment to protecting customers and software assets.
  • Ability to travel internationally when required for key workshops, assessments, or team collaboration.
  • Ability to collaborate effectively across global time zones with teams distributed across multiple continents.

Preferred Qualifications

  • Experience with tools such as Tenable, Qualys, Rapid7, Wiz, Microsoft Defender for Cloud, AWS Security Hub, Snyk, SonarQube, or equivalent.
  • Knowledge of CISA Known Exploited Vulnerabilities, EPSS, NIST guidance, CIS Benchmarks, and ISO 27001-aligned vulnerability management practices.
  • Experience with scripting, APIs, workflow automation, and reporting tools such as Power BI.
  • Familiarity with application security tooling and software development concepts sufficient to collaborate effectively with engineering teams.
  • Experience supporting incident response, coordinated vulnerability disclosure, or penetration testing follow-up.
  • Relevant certifications such as Security+, CySA+, GSEC, or equivalent.
  • Familiarity with engineering or technical software environments is advantageous

GCS is acting as an Employment Agency in relation to this vacancy.

COMPETITIVE SALARY
Added 09/10/2026
Reference: ADGProdSecAnalayst _1791555917

Product Security Analyst - Vulnerability Management

Pune, Maharashtra, India Permanent Cyber Security

Other similar jobs

Senior Analyst - Vulnerability Management (Contract)

Added 25/06/2026

Senior Analyst - Vulnerability Management (Contract)Location: London (hybrid)Duration: 6 monthsEngagement: Inside IR35OverviewA Senior Vulnerability Management Analyst is required to drive vulnerability identification, prioritisation, and remediation across enterprise IT and cloud environments. This role will improve the organisation's ability to manage exposure to cyber threats through robust vulnerability processes.Key Responsibilities* Operate and enhance the vulnerability management lifecycle (scan, assess, prioritise, remediate, report)* Perform and coordinate regular vulnerability scans across infrastructure, applications, and cloud environments* Analyse vulnerabilities and provide risk-based prioritisation aligned to business impact* Work with IT and engineering teams to track and drive remediation efforts* Provide detailed reporting on risk...

Learn more

Product Owner - (IAM - Identity Access Management)

Added 20/07/2026

Role Overview The Product Owner will play a key role in delivering and operating enterprise Identity & Access Management (IAM) capabilities. The role is responsible for managing the product backlog, ensuring delivery aligns with business objectives and regulatory requirements.The position works closely with IAM architects, business stakeholders and technology partners. We are undergoing a transformation of its Identity and Access Management practices including the delivery of a set of net new tools to overhaul how IAM is carried out in the industry. We are seeking experienced and dynamic product owners who have an excellent understanding of Identity Management, with a...

Learn more

Threat Intelligence and Vulnerability Manager

Added 02/09/2026

Threat Intelligence and Vulnerability Manager6-Month Contract | Inside IR35 | London 1-2 Days Per WeekWe're looking for an experienced security leader to take ownership of Threat Intelligence, Vulnerability Management, Threat Modelling, Security Testing and External Threat Hunting capabilities within a complex, high-profile environment.This is a hands-on leadership role where you'll help identify emerging threats, uncover vulnerabilities, drive assurance activities, and provide the intelligence needed to strengthen enterprise security across IT, OT, physical and people security domains.Key Experience✅ Threat Intelligence & Threat Hunting ✅ Vulnerability Management & Risk Prioritisation ✅ Threat Modelling & Security Assurance ✅ Penetration Testing & Control Validation...

Learn more

Cyber Threat and Vulnerability Manager

Added 15/06/2026

As a Cyber Threat & Vulnerability Manager, you will play a key role within the Security Operations function, leading the organisation's threat intelligence, vulnerability management, and intelligence-led testing capabilities across both IT and OT environments. Working closely with cybersecurity leadership, enterprise architects, programme delivery teams, and key business stakeholders, you will ensure that Threat and Vulnerability Management (TVM) services are effective, scalable, and continuously improved.This role contributes to the cyber resilience by driving a risk-based approach to vulnerability management, embedding threat intelligence into operational and strategic decision-making, and enhancing security maturity across the organisation. You will lead a team of...

Learn more

Technical Analyst - Identity & Access Management (IAM)

Added 29/07/2026

We are looking for an experienced Technical Analyst to join a strategic Identity & Access Management (IAM) transformation programme within a leading banking environment.You will provide L2 production support for Microsoft Identity Manager (MIM) and related IAM services, troubleshooting incidents, supporting integration's, and working with engineering teams to deliver permanent fixesLocation: Remote (UK)Contract: 6 Months (Initial With possible extension)IR35: Inside IR35Key Skills:✅ Microsoft Identity Manager (MIM) support experience✅ Strong SQL Server / T-SQL troubleshooting skills✅ .NET application support (logs, configuration, services)✅ Active Directory, LDAP, Kerberos & authentication technologies✅ Incident, problem and change management experience✅ Experience working in enterprise or regulated...

Learn more

Identity & Access Management (IAM) Test Analyst/Tester

Added 28/07/2026

Role OverviewWe are seeking an experienced Test Analyst/QA Tester with a background in Identity & Access Management (IAM) to test identity processing and user provisioning solutions across the identity lifecycle (Joiner, Mover, Leaver - JML).The successful candidate will be responsible for validating that user accounts, access rights, and entitlements are correctly provisioned, updated, and removed across multiple integrated systems, including HR systems, Active Directory (AD/LDAP), IAM platforms, and business applications.The role involves executing functional, integration, end-to-end, regression, and negative testing, validating identity data and business rules, performing SQL data validation, API testing using Postman, managing defects in Jira/ALM, and supporting...

Learn more

Senior Analyst - Identity & Access Management (IAM) (Contract)

Added 25/06/2026

Senior Analyst - Identity & Access Management (IAM) (Contract)Location: London (hybrid)Duration: 6 monthsEngagement: Inside IR35OverviewA Senior IAM Analyst is required to support and enhance identity and access management capabilities across a large-scale, enterprise environment. The role will focus on strengthening access controls, improving identity governance, and supporting ongoing transformation initiatives.Key Responsibilities* Support the design, implementation and optimisation of IAM controls and processes* Manage and improve user lifecycle management (joiners, movers, leavers)* Conduct access reviews, recertifications, and role-based access control (RBAC) activities* Ensure enforcement of least privilege and segregation of duties (SoD)* Work with application and infrastructure teams to onboard systems...

Learn more

Product Owner (Security Cleared - SC)

Added 09/10/2026

We are looking for Security Cleared Product Owner having strong epxerience with API integration environment. We are looking for either SC as Active or recently lasped. Principal AccountabilitiesIncorporate feature requests into a product roadmapReview and prioritise backlogDevelop user stories and define acceptance criteriaSet sprint goalsWrite acceptance testsPlan releases and upgradesFollow progress of work and address production issues during sprintsAnalyse preferences and requests of end usersRefine our agile methodology based on results and client feedbackKeep track of industry trends Complexity, Planning And Time SpansManagement of own workload and time.Coordinating delivery datesTracking and monitoring of Development workReviewing, collating, maintaining and highlighting changes...

Learn more

Security Architect - Tooling & Product Architecture

Added 07/08/2026

Security Architect - Tooling & Product ArchitectureLocation: Dublin City Centre / HybridType: PermanentSalary: CompetitiveAbout the RoleWe're looking for a Security Architect who genuinely enjoys working with security tools and products. This is not a governance-heavy architecture role - it's for someone who gets excited about evaluating new security technologies, understanding how they work under the hood, and designing integrated security ecosystems that deliver real operational value.You'll combine hands-on technical depth with strategic architecture thinking, working across endpoint security, identity, cloud security, SIEM, and threat detection platforms. A key requirement is extensive CrowdStrike experience.The role focuses on architecting and optimising security...

Learn more

Senior Identity & Privileged Access Management (IAM/PAM) Architect

Added 30/09/2026

Senior Identity & Privileged Access Management (IAM/PAM) ArchitectLocation: Dublin (Hybrid) Type: ContractOur client is seeking an experienced Senior IAM/PAM Architect to lead the design, implementation and governance of enterprise-wide identity and privileged access management solutions within a highly secure and complex environment.This is a key role for a senior security professional with deep expertise across Microsoft identity technologies, Identity Governance & Administration (IGA), Privileged Access Management (PAM) and Zero Trust security principles.Key ResponsibilitiesDefine and drive the IAM and PAM architecture strategy across the organisation.Design, deploy and secure Microsoft identity platforms, including Active Directory, Microsoft Entra ID, Group Policy, DNS and...

Learn more

IAM Developer | GCP | Identity & Access Management | Contract

Added 21/09/2026

One of our leading banking clients is looking for an experienced IAM Developer to join a large-scale Identity & Access Management transformation programme.Key Skills Required:Identity & Access Management (IAM)Auth0, Okta, WorkOS, or similar identity platformsPython, Go, or Node.jsREST API & Micro services developmentGCP (Cloud Run, Cloud Functions, GKE)Pub/Sub / Event-Driven ArchitectureTerraform & CI/CDOAuth2, OIDC, JWT, SAMLNice to Have:ReactKubernetesAzure AD / Entra IDPing IdentityFinancial Services experienceThis is an excellent opportunity to work on a high-profile cloud and identity transformation programme within a global banking environment.If interested, please share your updated CV and contact details. GCS is acting as an Employment Business...

Learn more

Identity & Access Management Architect

Added 14/07/2026

Identity & Access Management Architect📍 Ireland | HybridDesign the future of enterprise identity.Identity has become the new security perimeter, and we're looking for an Identity & Access Management Architect who wants to solve some of the most challenging IAM problems in enterprise environments.You'll join a growing Cyber Security practice delivering large-scale identity transformation projects for some of Ireland's most recognised organisations. This isn't a support role and it isn't BAU. You'll be designing solutions, leading technical conversations and helping organisations modernise how they manage identity across cloud-first environments.If you've built your career around Microsoft Identity and enjoy working directly with...

Learn more

Senior QA Analyst - Product & Application Testing

Added 16/09/2026

Senior QA Analyst - Product & Application Testing We're seeking a Senior QA Analyst who can take ownership of testing across software and mobile applications while partnering closely with Developers, Business Analysts, and Product teams.This role is ideal for someone who doesn't simply execute test cases - they look at the entire product, understand how functionality should work, identify risk areas, and continuously improve test coverage.What You'll OwnDevelop and maintain manual test cases for new functionality and regression testing.Plan and execute functional, regression, exploratory, and ad-hoc testing.Analyze application functionality to identify testing gaps and potential risks.Develop testing data and validate...

Learn more

Product Manager - Laboratory Integration

Added 08/10/2026

PRODUCT MANAGER - LIFE SCIENCES - HYBRIDRole - Product Manager - Laboratory IntegrationDuration - 6 months with very likely extensionLocation - Hybrid IR35 - Inside IR35Rate - £400 - £600OverviewWe are seeking an experienced Product Manager to lead the integration of laboratory instruments across Research & Development and Manufacturing Science & Technology (MSAT) environments. This is a highly visible role focused on delivering seamless connectivity between laboratory equipment, digital laboratory platforms, and enterprise systems.The successful candidate will own the laboratory integration roadmap, manage a diverse stakeholder community, gather and prioritise requirements, and oversee the successful delivery of integration initiatives across...

Learn more

Product Owner (SC Active is mandatory)

Added 23/09/2026

Prefered candidate from public sector such as Home Office, Defra, FCDO, MOJ, MOD, Cabinet Office, Centeral Gov bodies. SC Active or recently lapsed would be preferred. Principal AccountabilitiesIncorporate feature requests into a product roadmapReview and prioritise backlogDevelop user stories and define acceptance criteriaSet sprint goalsWrite acceptance testsPlan releases and upgradesFollow progress of work and address production issues during sprintsAnalyse preferences and requests of end usersRefine our agile methodology based on results and client feedbackKeep track of industry trends Complexity, Planning And Time SpansManagement of own workload and time.Coordinating delivery datesTracking and monitoring of Development workReviewing, collating, maintaining and highlighting changes...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.