Vulnerability Response Senior Subject Matter Expert - Cybersecurity
ITDS Polska Sp. z o.o.
Vulnerability Response Senior Subject Matter Expert – Cybersecurity
Miejsce pracy: Kraków
Technologies we use
Expected
- Nessus
- Tenable.io
- Checkmarx
- Fortify
- Microsoft Excel
Operating system
- Windows
- Linux
About the project
As a Vulnerability Response Senior Subject Matter Expert, you will be working for our client, a leading international bank in the digital transformation of financial services. In this role, you will help drive cutting-edge cybersecurity initiatives, protecting critical banking infrastructure and customer assets worldwide. Join us and contribute to shaping the future of secure banking.
Unleash the power of cybersecurity — lead vulnerability response strategies that safeguard global banking!
Krakow-based opportunity with hybrid work model.
Only candidates with an existing legal right to work in the European Union will be considered for this role.
Your responsibilities
- Lead the Vulnerability Management Response team in assessing and remediating emerging vulnerabilities with critical risk scores.
- Coordinate and drive initiatives such as Focussed Remediation Task Forces (FRTFs) and Imminent Threat Assessment Groups (ITAGs) to ensure swift mitigation efforts.
- Monitor external threat intelligence feeds for new risks and vulnerabilities.
- Manage documentation, track remediation activities, and produce comprehensive closure reports.
- streamline operational processes, identify improvement opportunities, and enhance overall security posture through systematic reviews.
- Collaborate with global teams including Threat Intelligence, Incident Management, and Control Owners to support vulnerability mitigation strategies.
- Contribute to compliance and regulatory reporting, including governance submissions and risk assessments.
- Support ad hoc operational activities, escalate issues when needed, and deputize for leadership in review sessions.
Our requirements
- At least 4 years of experience in IT Security, Cybersecurity Operations, or Vulnerability Management.
- Expertise in vulnerability scanning tools such as Nessus, Tenable.io, Checkmarx, Fortify, or similar platforms.
- Strong understanding of vulnerability assessment scoring, patch management, and control analysis.
- Solid knowledge of security principles, financial industry standards, and compliance regulations.
- Ability to interpret large data sets using MS Excel and present insights effectively.
- Excellent organizational, analytical, and problem-solving skills.
- Demonstrated ability to work independently, proactively, and collaboratively within a global team.
- Fluent in English, with excellent communication skills suitable for diverse stakeholder engagement.
Optional
- Certifications such as CISSP, CISM, or relevant cybersecurity qualifications.
- Experience in conducting security reviews or supporting regulatory audits.
This is how we organize our work
This is how we work
- at the client's site
- agile
- scrum
What we offer
- Stable and long-term cooperation with very good conditions
- Enhance your skills and develop your expertise in the financial industry
- Work on the most strategic projects available in the market
- Define your career roadmap and develop yourself in the best and fastest possible way by delivering strategic projects for different clients of ITDS over several years
- Participate in Social Events, training, and work in an international environment
- Access to attractive Medical Package
- Access to Multisport Program
- Access to Pluralsight
- Flexible hours
Benefits
- sharing the costs of sports activities
- private medical care
- flexible working time
- fruits
- integration events
- corporate gym
- saving & investment scheme
- no dress code
- coffee / tea
- drinks
- christmas gifts
- birthday celebration
- sharing the costs of a streaming platform subscription
- access to +100 projects
- access to Pluralsight
Recruitment stages
- online interview
- online interview
#GETREADY to meet with us!
ITDS Business Consultants is involved in many various, innovative and professional IT projects for international companies in the financial industry in Europe. We offer an environment for professional, ambitious, and driven people.
We would like to meet you. If you are interested please apply and attach your CV in English or Polish, including a statement that you agree to our processing and storing of your personal data.
ITDS’s Whistleblower Procedure
You can report violations in accordance with ITDS’s Whistleblower Procedure available here:
ITDS Polska Sp. z o.o.
ITDS supports financial service providers to take the next steps.
We identify what’s possible, every day. Opportunities in the areas of technology, organization, and digitization.
We see where banks, insurers, payment companies, or fintech can go and how they can get there.
That’s why we want to stimulate you to ramp up your ambition. Forget what you perceive as restraints and step towards the new reality.
ITDS in Poland - Pure player in new Technologies & Financial Industry
+300 IT implementation professionals
+20 clients in the Banking, Insurance, Payment & Fintech Industry
ITDS excels in digital strategy delivery and implementation of best-of-breed lending solutions. ITDS has delivered successful strategic projects throughout Europe since 1998. We combine the experience we’ve accumulated with in-depth knowledge of technologies, business processes, and EU legislation to unlock new business opportunities.
Informujemy, że administratorem danych jest ITDS z siedzibą w Warszawie, ul. Złota 59 (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Hello HR oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
Naruszenia można zgłaszać zgodnie z Procedurą zgłaszania nieprawidłowości ITDS dostępną tutaj: