(Cybersecurity) Vulnerability Response Senior SME

(Cybersecurity) Vulnerability Response Senior SME

Senior Vulnerability Management Specialist

Location: Kraków, Poland – hybrid
Contract: B2B
Office presence: 6 days per month

About the role

We are looking for an experienced Vulnerability Response Senior SME to join a cybersecurity team responsible for identifying, assessing and driving the remediation of security vulnerabilities across a large-scale technology environment.

In this role, you will focus on responding to newly identified critical and high-severity vulnerabilities, assessing their potential impact, validating exposure, and working with technical teams to ensure vulnerabilities are effectively remediated.

You will combine strong technical cybersecurity knowledge with stakeholder management and communication skills. The role requires the ability to understand complex technical issues, translate them into clear business impact, and coordinate remediation activities from initial assessment through to closure.

What you will do

  • Review critical and high-severity vulnerabilities identified through sources such as NIST/NVD, vendor advisories and security scanning tools.
  • Assess whether vulnerabilities affect the technology environment and communicate their potential impact, exploitability and risk in a clear and structured way.
  • Validate vulnerability findings using technical evidence such as software versions, configurations, logs and scan results.
  • Identify affected assets and work with relevant technical teams to establish ownership and scope.
  • Recommend appropriate remediation and mitigation approaches, including patching, upgrades, configuration changes and compensating controls.
  • Prepare clear technical documentation covering root cause, affected components, potential attack paths, business impact and remediation guidance.
  • Coordinate remediation activities with infrastructure, cloud, platform and application teams.
  • Track remediation progress, identify blockers and escalate significant delays or risks where appropriate.
  • Verify that remediation has been successfully completed through rescanning, validation testing or review of supporting evidence.
  • Assess and document residual risk where immediate full remediation is not possible.
  • Support cybersecurity governance activities, including risk reporting, management updates and security metrics.
  • Contribute to responses to audit and regulatory requests.
  • Support wider cybersecurity operational activities, escalations and ad-hoc vulnerability-related requests.

What you will bring

  • 5+ years of experience in IT Security, Cybersecurity, Vulnerability Management or a related area.
  • Proven experience assessing and responding to critical and high-severity vulnerabilities.
  • Strong understanding of common vulnerability types and attack techniques, including remote code execution, privilege escalation and authentication bypass.
  • Experience with vulnerability identification and assessment tools, ideally including Tenable.
  • Understanding of application security testing approaches such as SAST and DAST.
  • Good understanding of CI/CD processes and how security testing and remediation are integrated into software development and release pipelines.
  • Solid technical knowledge of networking and application delivery technologies, including WAFs, load balancers, certificates and TLS.
  • Understanding of security risks and exposure points across both on-premises and cloud environments.
  • Practical knowledge of vulnerability remediation, including patching, upgrades, configuration hardening and compensating controls.
  • Strong stakeholder management skills and the ability to work effectively with technical teams, service owners and other stakeholders.
  • Excellent written and verbal communication skills, with the ability to explain complex technical topics to both technical and non-technical audiences.
  • Strong organisational skills and a delivery-focused approach.
  • Experience working in cybersecurity operations, risk management or security governance within a medium or large enterprise environment.
  • Ability to work effectively in a hybrid and remote environment.

What we offer

  • B2B contract
  • Hybrid working model with 6 days per month from our Kraków office
  • Lux Med private medical care
  • MyBenefit cafeteria
  • Support from a dedicated Contractor Care specialist
  • Opportunity to work on complex cybersecurity and vulnerability management challenges within a large-scale technology environmen
ID: 16721 job_post.published_on: 22/09/2026
announcement.apply