- Location
- HBP (Amsterdam - Haarlerbergpark), Netherlands
- Type
- Full-time
- Department
- Management
- Closing date
- Today
- Source
- Workday
Description
Vulnerability Management (VM) Specialist, Amsterdam HBP (36 hours)
Are you the go-to person for identifying risks and turning challenges into actionable solutions? Do you have a strong passion for Vulnerability Management, combined with a keen understanding of IT Security? If so, we have an exciting opportunity for you!
We’re currently hiring for a Business Control Specialist IV. In this role, you’ll serve as a trusted advisor to internal stakeholders, assisting them with the validation of security design, code, and configuration of assets. You’ll be responsible for managing Vulnerability Management issues as well as translating complex Vulnerability Management risks into clear, actionable guidance that enables our DevOps teams to identify and mitigate risks effectively.
You’ll operate as a First Line of Defence (1LoD) risk specialist, working closely with DevOps professionals, CISO and our 2LoD. Together, we keep ING ahead of the curve in risk management. Join us and help shape the future of IT risk & Security management!
Ready to make an impact and enjoy the journey?
The team
As a Vulnerability Management Specialist you’ll be part of the IAM & Resilience chapter, which is part of the Reliability, IT Risk & Security (RIRS) Tribe at CTO.
The IAM & Resilience chapter consists of risk & security experts who are supporting the Finance & Risk entity on IAM and Resilience (IAM, IT Resilience, Vulnerability Management & SDR) related Security topics. The IAM & Resilience chapter team, in close collaboration with the Change and Testing chapter and the DevOps teams focuses on the day-to-day management and execution of IT risk and security tasks.
Furthermore, the team steers the execution of the Risk Opinion and First Line Monitoring improvement activities that coincide with the execution of IT security controls. The members are typically experienced, they have diverse interdisciplinary technical, IT risk and/or IT security backgrounds.
Roles and responsibilities
The ideal candidate has Expertise in the overseeing the end to end vulnerability management lifecycle. This role ensures that identified vulnerabilities are properly assessed, prioritized, remediated, and monitored in alignment with risk appetite, compliance requirements, and business objectives.
We are looking for someone with hands on experience with Security tools (GSOC, ServiceNow, Checkmarx, Qualys, Nessus, Cloud Atlas, APF) who is able to support DevOps teams with Vulnerability Management issues by providing expert guidance and consultancy. Knowledge of IT Risk processes and the ability to identify, assess and document the impact of security defects is a must.
Your responsibilities will be to:
Perform validation/triage, risk scoring, remediation tracking, and verification.
Use CVSS, threat intel (exploitation in the wild), asset criticality, exposure, and compensating controls to drive risk-based remediation.
Orchestration Remediation: Taking sessions, coordinate owners, and ensure fix validation (patch, config, version upgrade, or mitigation).
Continuous improvement: Reduce noise (false positives/duplicates), tune scans, improve coverage, and drive automation.
Monitor the risk score of Finance & Risk and support the entity to be within Risk Appetite.
Participate in the Risk Opinion process for Vulnerability Management, ensuring a correct and complete assessment of Vulnerability Management metrics and controls.
Review Vulnerability Management risk metrics and manage the remediation of issues resulting from the metrics
How to succeed
We hire smart people like you for your potential. Our biggest expectation is that you’ll stay curious. Keep learning. Take on responsibility. In return, we’ll back you to develop into an even more awesome version of yourself.
The following skillset and experience are required to succeed in this role:
Strong knowledge of the end to end Vulnerability Management process.
Expertise in vulnerability identification, analysis and remediation.
Knowledge of and experience with common scanning and management tools (e.g. Nessus, Qualys, Tenable, Rapid7) and CVSS classification.
Experience with Vulnerability Management risk metrics and risk governance frameworks.
Familiarity with Vulnerability Management processes in complex, regulated environments.
Excellent stakeholder management and communication skills.
Certifications such as CISSP, OSCP, GCIH or similar are an advantage, but not a strict requirement.
Natural motivation and drive to take end-to-end ownership.
Rewards and benefits
We want to make sure that it’s possible for you to strike the right balance between your career and your private life. Find out more about our employment conditions.
The benefits of working with us at ING include:
25-28 vacation days depending on contract
Pension scheme
13th month salary
8% Holiday payment
Hybrid working
Personal growth and challenging work with endless possibilities
An informal working environment with innovative colleagues
About us
Curious about how ING empowers people and businesses to move forward?
Discover what we do and what we can offer you.
Questions?
Please visit our Frequently Asked Questions section to find some answers on questions you might have.
Contact the recruiter attached to the advertisement. Want to apply directly? Please upload your CV and motivation letter by clicking the ‘Apply’ button.