via ats_lever · 16 de julio de 2026 ·hace 5 días

Vulnerability Operation Center Lead

jobgether
Spain Tiempo completo
335 ofertas más en Spain.
Sube tu CV y descubre cuáles encajan realmente contigo.
Subir CV

Accountabilities

  • Build and lead the Vulnerability Operations Center, defining processes, governance, and best practices for the complete vulnerability management lifecycle.

  • Manage vulnerability detection, validation, triage, remediation tracking, and reporting across cloud infrastructure, products, and hardware environments.

  • Improve automated vulnerability triage capabilities through data enrichment, AI-assisted workflows, contextual risk scoring, and vulnerability correlation techniques.

  • Perform hands-on validation and prioritization of critical and zero-day vulnerabilities to support rapid response efforts.

  • Collaborate closely with engineering, security, compliance, and operations teams to ensure timely remediation and continuous risk reduction.

  • Drive improvements in patch management processes and oversee remediation initiatives across multiple engineering teams.

  • Manage vulnerability intake from scanners, penetration testing, bug bounty programs, and threat intelligence sources.

  • Prioritize findings using industry-standard risk frameworks, including CVSS, EPSS, SSVC, exploitability, asset criticality, and business impact.

  • Contribute to the development and automation of internal vulnerability management and security orchestration platforms.

  • Define key vulnerability management metrics, monitor trends, and present actionable insights and KPIs to security leadership.

  • Coordinate organizational responses to critical security events and maintain integrations across the broader security ecosystem.

Requirements
  • 5–8 years of experience in information security, including at least 3 years focused on vulnerability management or security operations.

  • Strong expertise in vulnerability management processes across cloud-native and enterprise infrastructure environments.

  • Deep knowledge of vulnerability assessment methodologies, including CVE, NVD, CVSS, EPSS, SSVC, and risk-based prioritization frameworks.

  • Experience working with cloud platforms such as AWS, Google Cloud, Azure, or private cloud infrastructure.

  • Solid understanding of vulnerability scanning technologies, their capabilities, and their limitations in modern cloud environments.

  • Ability to write and review code, with experience or willingness to develop automation using Golang or similar programming languages.

  • Strong understanding of software and infrastructure vulnerability classes, exploitability analysis, and remediation validation.

  • Experience collaborating with engineering teams to drive remediation while balancing technical risk and operational priorities.

  • Excellent analytical, communication, and stakeholder management skills, with the ability to translate complex technical risks into business-focused recommendations.

  • Experience with Kubernetes security, container security, software supply chain security, SBOMs, dependency scanning, or bug bounty programs is considered an advantage.

  • Previous experience building or scaling a vulnerability management program from the ground up is highly desirable.
Benefits
  • Competitive compensation package, including equity participation opportunities.

  • Flexible remote-first working environment.

  • Opportunity to build and lead a strategic cybersecurity function from its inception.

  • High level of ownership and influence over security strategy, tooling, and operational processes.

  • Career growth, continuous learning, and professional development opportunities.

  • Collaborative, engineering-driven culture focused on innovation and technical excellence.

  • Opportunity to contribute to AI-powered security technologies and next-generation cloud infrastructure.

  • International work environment with highly experienced engineering and security professionals.

  • Fast-paced organization offering meaningful technical challenges and significant business impact.

El mercado para este tipo de puesto

Ofertas similares
335
ofertas en Spain
Jornada completa
82%
de las ofertas en España
Teletrabajo posible
14%
de las ofertas
jobgether

200 open positions · Argentina, Austria, Belgium, Denmark, France +11

📊 Job market · España
9992
active jobs
14.6%
Remote
Ø 3d
avg. online

Preguntas frecuentes

¿Cuántas ofertas hay disponibles en Spain?
Actualmente 335 puestos en Spain en AlmostHired, en 111 empresas diferentes. Nuestros datos se actualizan a diario.
¿Los puestos en España ofrecen teletrabajo?
14% de las ofertas en España permiten teletrabajo, parcial o completo. Para filtrar específicamente puestos en remoto, usa AlmostHired.
¿Cómo sé si encajo en esta oferta?
Sube tu CV — nuestra IA compara tu perfil con los requisitos del puesto y te da una puntuación de coincidencia precisa, con habilidades coincidentes y faltantes.