Product Security Analyst - Vulnerability Management
Product Security Analyst - Vulnerability Management
Department
Software Technology
Reports to
Business Information Security Officer (BISO)
Role Summary
We are seeking a Product Security Analyst - Vulnerability Management to operate and continuously improve the vulnerability management lifecycle across software products, cloud environments, and supporting technology platforms.
The role consolidates security findings, validates and prioritizes exposure using technical and business context, coordinates accountable remediation, and provides reliable product security posture reporting.
The successful candidate is technically credible, analytical, and highly structured, working closely with product and engineering teams to reduce risk rather than merely administer findings. This is a product security and vulnerability management role, not a 24/7 SOC monitoring position.
Responsibilities
- Operate the end-to-end vulnerability management process across applications, APIs, cloud services, infrastructure components, containers, and third-party dependencies.
- Consolidate findings from vulnerability scanners, penetration tests, application security tools, cloud security services, vendor advisories, and enterprise cybersecurity sources.
- Validate findings, remove duplicates and false positives, and enrich records with asset ownership, exposure, exploitability, and business context.
- Prioritize vulnerabilities using severity, known exploitation, reachability, internet exposure, compensating controls, product criticality, and customer impact.
- Assign accountable remediation owners, agree target dates, track progress, challenge overdue items, and verify closure evidence.
- Maintain an accurate inventory and mapping of covered products, repositories, services, and technical owners in coordination with Product, Architecture, and Platform teams.
- Develop and maintain vulnerability dashboards, heatmaps, KRIs, and aging metrics for security leadership, business leadership, product teams, and governance forums.
- Identify systemic weakness patterns and recommend preventive actions, platform improvements, secure configurations, and remediation campaigns.
- Support risk treatment and exception workflows by preparing evidence, documenting residual exposure, and escalating material or overdue risks.
- Coordinate operational follow-up from penetration tests, audits, incidents, external disclosures, and security advisories.
- Perform focused vulnerability assessments and technical validation using approved tools and methods.
- Monitor emerging vulnerabilities and threat intelligence relevant to the technology stack and initiate rapid assessment when urgent exposure is suspected.
- Use CISA Known Exploited Vulnerabilities and other verified threat intelligence as inputs to risk-based vulnerability prioritization.
- Use EPSS as one empirical exploitation likelihood signal alongside CVSS, reachability, exposure, product criticality, and customer impact.
- Support Cyber Resilience Act reporting readiness through rapid assessment of active exploitation, evidence collection, and escalation to security leadership.
- Maintain visibility of product versions, declared support periods, and end-of-support status to inform vulnerability treatment and customer obligations.
- Use SBOM and dependency data to determine which products, versions, and services contain affected components and accelerate impact assessment.
- Support security advisories, customer notifications, and coordinated vulnerability disclosure with Product Management, Legal, Quality, and Security stakeholders.
- Support audit, regulatory, and ISO 27001 evidence requirements related to vulnerability management and operational security controls.
- Collaborate with Application Security, DevSecOps, Platform Engineering, and Security teams on complex findings, scanning coverage, and automation.
- Continuously improve workflows, service levels, data quality, and reporting to drive measurable exposure reduction.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience.
- Several years of experience in vulnerability management, vulnerability analysis, security operations, cloud security, or a related technical cybersecurity role.
- Hands-on experience with vulnerability scanning and security posture tools across applications, cloud, or infrastructure environments.
- Strong understanding of CVE, CVSS, common vulnerability classes, exploitability, attack paths, and risk-based prioritization.
- Ability to validate findings using logs, configurations, source information, command-line tools, and targeted technical testing.
- Knowledge of cloud services, operating systems, networks, containers, identity and access management, APIs, and software dependencies.
- Experience managing remediation workflows, security exceptions, evidence, and service-level reporting.
- Strong data analysis skills and experience producing dashboards, metrics, and concise management reporting.
- Excellent analytical, organizational, and problem-solving skills with strong attention to data quality.
- Ability to communicate clearly with engineers, product owners, and senior stakeholders and drive accountable follow-through.
- Strong written and verbal communication skills in English.
- High level of integrity, judgment, and commitment to protecting customers and software assets.
- Ability to travel internationally when required for key workshops, assessments, or team collaboration.
- Ability to collaborate effectively across global time zones with teams distributed across multiple continents.
Preferred Qualifications
- Experience with tools such as Tenable, Qualys, Rapid7, Wiz, Microsoft Defender for Cloud, AWS Security Hub, Snyk, SonarQube, or equivalent.
- Knowledge of CISA Known Exploited Vulnerabilities, EPSS, NIST guidance, CIS Benchmarks, and ISO 27001-aligned vulnerability management practices.
- Experience with scripting, APIs, workflow automation, and reporting tools such as Power BI.
- Familiarity with application security tooling and software development concepts sufficient to collaborate effectively with engineering teams.
- Experience supporting incident response, coordinated vulnerability disclosure, or penetration testing follow-up.
- Relevant certifications such as Security+, CySA+, GSEC, or equivalent.
- Familiarity with engineering or technical software environments is advantageous
GCS is acting as an Employment Agency in relation to this vacancy.
Product Security Analyst - Vulnerability Management
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- IT Support & Infrastructure
- Engineering
- Controls & Automation
- Data
- Project Management
- BI & Data Analytics
- Network security consultant
- DevOps
- IT Audit & Risk
- Hardware & Electronics
- Testing & QA
- Software Development
LATEST JOBS
- Test Lead
- Senior DevSecOps Engineer
- Product Security Analyst - Vul...
- Application Security Engineer
- Product Owner (Security Cleare...
- Project Manager - Digital & St...
- Controls Technician
- Project Manager - Advertising...
- Project Manager - Ad Sales Cre...
- Fiber Optics Engineer
- Controls Engineer
- machine learning engineer
TOP SEARCHES
LOCATIONS
- Engineer
- Data Scientist
- Senior Data Scientist
- Head of Data Science
- Trainee Data Scientist
- Data Science Graduate
- Senior Financial Accountant
- Management Accountant
- Cost Accountant
- Civil Engineer
- Senior Civil Engineer
- Civil Design Engineer