Skip to content

IT Security Vulnerability Management Specialist

Gate Serve LLCBelgrade, RS, SerbiaJuly 26, 2026
On-site
Full-time
Vulnerability Management
Mid · 3+ yrs

We’re looking for motivated, engaged people to help make everyone’s journeys better.

Job summary:

Reporting to the Global Manager IT Security Operations, the IT Security Vulnerability Management Specialist is responsible for leading and managing the organization’s vulnerability management lifecycle. This includes identifying, classifying, prioritizing, remediating, and reporting vulnerabilities across IT and OT environments.

The role ensures continuous security improvement through collaboration with IT, development, operations, business and risk teams, aligning with the organization’s risk appetite and compliance mandates. The ideal candidate is both a strategic thinker and a hands-on executor with deep technical expertise and a strong understanding of business impact.

Main Duties and Responsibilities:

The IT Security Vulnerability Management Specialist will develop, maintain, or support an intelligence capability to anticipate and identify current and emerging security risks to the organization. The IT Vulnerability Management specialist will:

 Vulnerability Management Operations

  • Lead the end-to-end vulnerability management process, including scanning, identification, triage, and reporting.
  • Coordinate with infrastructure, cloud, and application teams to remediate vulnerabilities in a timely and risk-informed manner.
  • Maintain and tune vulnerability scanning tools to ensure accurate detection and comprehensive coverage.
  • Establish SLAs for vulnerability remediation based on criticality, and track compliance.

Threat Intelligence Integration

  • Work with threat intelligence teams to assess exploitability and real-world threat context of identified vulnerabilities.
  • Integrate CVE and threat feeds (e.g., CISA KEV, NVD, vendor advisories) into the prioritization model.

Risk & Compliance Alignment

  • Ensure vulnerability management processes align with security policies, ISO/IEC 27001, NIST 800-53, and regulatory requirements.

Core Competencies and Requirements:

  • Bachelor's or master's degree in IT, engineering, business, management or a related field, or equivalent work experience
  • Tertiary qualifications in information or security, or industry qualifications such as Offensive Security Certified Professional (OSCP), GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), CERT Incident Response Process Professional Certificate, or EC-Council Certified Incident Handler (ECIH)
  • Minimum 3 years of experience in cybersecurity, with at least 1 year in vulnerability management or threat/risk analysis roles.
  • Hands-on experience with enterprise vulnerability scanning tools and ticketing systems.
  • Proven track record managing complex remediation across hybrid IT environments (on-prem, cloud, containers).
  • Deep knowledge of common vulnerabilities and exposures (CVEs), CVSS, MITRE ATT&CK, and threat modeling.
  • Expertise in vulnerability management platforms: Tenable.sc, Qualys, Rapid7, etc.
  • Familiarity with :
    • SIEMs (e.g., Splunk, Sentinel)
    • Patch management
    • ITSM platforms (e.g., ServiceNow)
    • CMDBs.
  • Understanding of secure coding practices and integration into DevSecOps pipelines (e.g., SAST/DAST tools).
  • Competent in scripting or automation (Python, PowerShell, Bash) to streamline processes.
  • Strong communication skills with a proven ability to understand key concepts and communicate with technical staff, lines of business and senior management.
  • Proven ability to build relationships and influence individuals at all levels in a matrixed environment, as well as external vendors and service providers, to ensure that segregation and overlapping roles are identified and coordinated.
  • Ability to consume and synthesize intelligence about actors, techniques, or situations to identify emerging risk scenarios.
  • Fluent English (required) – strong written and spoken communication for cross-regional collaboration and executive reporting.
  • Other languages (e.g., German, French, Spanish) are a plus for global organizations.

If you want to be part of a team that helps make travel and culinary memories, join us!

Job Details

Experience

Mid · 3+ yrs

Tools & Tech

Bash
Microsoft Sentinel
PowerShell
Python
Qualys
Rapid7
ServiceNow
Splunk
Tenable

Preferred Certs

CISA
GCIH
OSCP