Skip to content

Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector

DevoteamPorto, PT, PortugalSeptember 15, 2026
Hybrid
Full-time
Vulnerability Management
Management

Company Description

Devoteam Cyber Trust is the specialized cybersecurity unit of the Devoteam Group. With over 800 experts across the EMEA region, our mission is to position cybersecurity as a business enabler, not a barrier. We take a comprehensive approach to Cyber Resilience, Applied Security, and Security Service Management to safeguard the digital journey of large and mid-sized enterprises across all sectors and industries.

Since 2009, previously known as INTEGRITY, our Portugal-based team has specialized in delivering cutting-edge Managed Security Services. By combining expertise with proprietary technology, we consistently and effectively reduce our clients' cyber risk. Our wide range of services includes Persistent Penetration Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. Certified in ISO 27001 (Information Security) and ISO 9001 (Quality), PCI-QSA, and members of CREST and CIS (Center for Internet Security), we serve a significant number of clients in over 20 countries.

Job Description

Integration into a Threat Operations team, with responsibilities within the organization's Vulnerability Management Program, including vulnerability identification, prioritization, remediation SLA definition and tracking, and reporting.

  • Manage the vulnerability lifecycle across infrastructure and endpoints, including analysis, prioritization (CVE, CVSS, KEV, exploitability, business context), and definition of remediation SLAs.
  • Monitor and validate remediation or mitigation processes, identify SLA breaches, perform follow-ups, and escalate issues to the appropriate teams or management levels.
  • Identify and monitor vulnerabilities within development pipelines (SSDLC), in coordination with the AppSec team.
  • Assess and monitor the risk associated with technology obsolescence (End-of-Life / End-of-Support) across systems, applications, and components.
  • Identify and analyze security findings across cloud environments, containers, and images, in collaboration with AppSec and Cloud Security teams.
  • Critically validate the results generated by security tools, investigating false positives and confirming vulnerabilities.
  • Ensure adequate coverage of the vulnerability management platform across the asset estate, in coordination with Infrastructure and Workplace teams.
  • Produce vulnerability dashboards, KPIs, and reporting, including weekly status updates on critical vulnerabilities and remediation SLAs for management.
  • Automate, document, and standardize operational procedures within the Vulnerability Management Program.

Qualifications

Vulnerability Management

  • Fundamental knowledge of Vulnerability Management concepts, including CVE, CVSS, KEV, exploitability, severity, prioritization, and remediation.
  • Experience defining SLAs, monitoring remediation activities, conducting follow-ups, and escalating issues.
  • Knowledge of technology obsolescence (EOL/EOS) and associated risk assessment.
  • Experience creating dashboards and reports, with the ability to define and interpret KPIs.
  • Knowledge of cloud security and cloud resources, including security findings analysis.
  • Knowledge of container and container image vulnerabilities.
  • Familiarity with the Secure Software Development Lifecycle (SSDLC) and SCA/SAST concepts.
  • A critical approach to security tool results, with the ability to validate findings rather than assuming they are automatically accurate.

Technical Knowledge

  • Windows and Linux operating systems.
  • Networking and protocols: TCP/IP, DNS, HTTP/HTTPS, ports, and services.
  • Vulnerability Management platforms: Tenable One, CrowdStrike FEM.
  • Cloud platforms, particularly Microsoft Azure and Google Cloud.
  • Security tools integrated into development pipelines, including SCA, SAST, and IaC scanning.

Soft Skills

  • Effective communication with technical and operational teams.
  • Ability to communicate with different levels of the organization, including management, translating technical information into business risk and impact.
  • Strong analytical and problem-solving skills.
  • Autonomy, organization, and prioritization skills in a high-volume vulnerability environment involving multiple teams.

Certifications

Certifications in cybersecurity and Vulnerability Management are considered an advantage, particularly:

  • GIAC Enterprise Vulnerability Assessor (GEVA) — SANS SEC460.
  • CompTIA CySA+ or CompTIA Security+.
  • Cloud security certifications, such as Microsoft AZ-500 or Google Professional Cloud Security Engineer.
  • Vendor certifications related to vulnerability scanning and management tools.

Additional Information

What we offer:

  • Professional development and monitoring talent;
  • Commitment to our employees' development;
  • Collaboration in a company that is constantly growing and evolving;
  • Strong organizational culture: collaboration, sharing, flexibility, integrity and low ego.

The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.

Job Details

Experience

Management

Tools & Tech

Azure
CrowdStrike
GCP
Linux
Tenable
Windows

Preferred Certs

AZ-500
CySA+