Vulnerability & Incident Response Analyst

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of HBK - Hottinger Brüel & Kjær

HBK - Hottinger Brüel & Kjær

1001 - 5000 employees

Founded 2019

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

HBK - Hottinger Brüel & Kjær is a prominent company formed in 2019 through the merger of HBM and Brüel & Kjær, two organizations with over 80 years of experience in precision test and measurement technology. HBK delivers innovative solutions across multiple domains including mechanical, sound and vibration, and electrical testing. The company provides a wide range of products and services such as data acquisition systems, electroacoustic setups, vibration testing equipment, and custom sensor assemblies. HBK caters to diverse industries such as aerospace, automotive, and energy, focusing on quality, reliability, and sustainability in all offerings. The company's mission is to empower innovators by providing exceptional sensing and insights, thus contributing to a cleaner, healthier, and more productive world.

📋 Description

• Perform initial triage, validation, and analysis of product vulnerabilities • Assess vulnerability severity using CVSS, exploitability, product applicability, and business impact criteria • Review vulnerability reports and collaborate with product teams to determine applicability, exploitability, remediation requirements, and prioritization • Maintain vulnerability records, evidence, and audit trails • Coordinate security incident and exploited vulnerability reporting activities • Prepare information for regulatory notifications with Product Security, Legal, and Product Teams • Track incident reporting timelines and complete escalation activities within regulatory timeframes • Support incident readiness exercises and reporting process validation • Monitor vulnerability disclosure channels, PSIRT mailboxes, public disclosures, security advisories, and threat intelligence feeds • Identify emerging threats affecting HBK products and coordinate investigations • Track Known Exploited Vulnerabilities, industry alerts, and relevant security advisories • Coordinate remediation activities with Product Teams, DevSecOps, and Product Security stakeholders • Track remediation progress against targets and service level objectives • Support review of security updates, patches, and mitigation plans • Produce vulnerability status reports, metrics, and management updates • Serve as operational liaison across Product Security, DevSecOps, Customer Support, Legal, and Product Teams • Facilitate communication and issue resolution across stakeholders • Support implementation and continual improvement of vulnerability management and coordinated vulnerability disclosure processes • Contribute to EU Cyber Resilience Act regulatory readiness initiatives

🎯 Requirements

• Bachelor’s or master’s degree in cybersecurity, Computer Science, Information Security, Software Engineering, or related technical discipline • Experience in vulnerability management, security operations, incident response, PSIRT, application security, or related cybersecurity discipline • Understanding of vulnerability assessment methodologies, CVSS scoring, exploitability analysis, and remediation workflows • Familiarity with vulnerability management platforms, ticketing systems, and security scanning tools • Knowledge of vulnerability databases and threat intelligence sources, including CVE, NVD, and KEV • Understanding of software development lifecycles and secure development practices • Familiarity with cybersecurity regulations and standards including EU CRA, ISO/IEC 30111, ISO/IEC 29147, IEC 62443, NIST SP 800 series, or ISO 27001 • Strong analytical and problem-solving skills • Ability to prioritize and manage multiple activities simultaneously • Excellent stakeholder management and communication skills across technical and non-technical teams • Experience preparing security reports, metrics, and compliance evidence is desirable • Preferred experience working within a PSIRT • Preferred exposure to regulatory reporting obligations and coordinated vulnerability disclosure programmes • Preferred experience with vulnerability management automation, DevSecOps pipelines, SBOM tooling, or software composition analysis platforms • Familiarity with cloud, desktop, SaaS, embedded, or industrial control system products • Knowhow on penetration testing • Prior experience with bug bounty portals is an added advantage

Apply Now