Sophos

Vulnerability Management Engineer (Romania)

Job Description

Role Summary

The Senior Threat Analyst plays a critical role in supporting and enhancing the organisation’s vulnerability management and threat detection capabilities. This role is responsible for monitoring and responding to security support requests, collaborating closely with cross-functional teams, and providing expert guidance to customers on strengthening their vulnerability management strategies.

As a trusted technical advisor, the Senior Threat Analyst translates complex security and technical risks into actionable insights for both internal stakeholders and customers, driving improvements in security posture and operational efficiency. The role also contributes to root cause analyses, develops technical recommendations, and ensures high-quality documentation and knowledge sharing.


What You Will Do
  • Responsible for understanding, reviewing, and interpreting assessment and scanning results, reducing false positive findings and acting as a trusted security advisor to the customer 
  • Learn and adapt to customer’s culture, security strategies, security goals, security objectives, and security capabilities
  • Maintain knowledge of outstanding vulnerability management issues as it pertains to the Customer Vulnerability Management Service and communicate updates as appropriate
  • Collaborate with program management and Customer teams to create both tactical and strategic plans(establish and communicate a clear vision and ensure short term issues do not overtake strategic goals)
  • Serve as an escalation point for all Customer technical issues requiring support within the - Vulnerability Management offering
  • Providing Vulnerability Assessment Scanning and guidance, False Positive Validation, Attestation Signing, Compliance Scanning and policy creation using the QualysGuard Policy Compliance Suite and Web Application Scanning using the Qualys WAS Suite

  • What You Will Bring
  • 5+ years of experience in technical security support role
  • 3+ years of experience in a vulnerability management role
  • Strong network engineering experience with Linux/Unix, - Windows, and network infrastructure administration
  • Experience with Vulnerability Management platforms such as QualysGuard, Nessus, Rapid 7
  • Provide guidance and support for Vulnerability remediation scenarios
  • Strong technical, analytical, and interpersonal skills; ability to interact with stakeholders like customer support or executive leadership teams, vendors, etc.
  • Provide guidance in developing, maturing and implementing a Vulnerability Management security program
  • One or more of the following certifications: CISSP, GPEN, GCIH, CEH are desired, or equivalent Security Certification