Senior Vulnerability Management Engineer

🕒 vor 10 Tagen

🇬🇧 Vereinigtes Königreich – Remote

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of LSEG (London Stock Exchange Group)

LSEG (London Stock Exchange Group)

10.000+ Mitarbeiter

💸 Finanzen

💳 Fintech

🤝 B2B

Finance • Fintech • B2B

LSEG (London Stock Exchange Group) ist ein vielfältig aufgestelltes internationales Infrastrukturunternehmen für Marktplätze und genießt seit über 300 Jahren das Vertrauen unserer Kunden. Dieses Erbe kundenorientierter Exzellenz garantiert, dass Sie sich auf unsere Expertise in der Kapitalbildung, im Bereich des geistigen Eigentums sowie im Risiko- und Bilanzmanagement verlassen können. Als weltweit führendes Unternehmen in der finanziellen Indexierung, Benchmarking und Analysedienstleistungen bieten wir unvergleichlichen Zugang zu internationalen Kapitalmärkten. Unsere Hochleistungstechnologielösungen ermöglichen es Unternehmen weltweit, Finanzmittel für Wachstum und Entwicklung zu beschaffen. Und mit unseren Bereichen Daten & Analysen, Kapitalmärkte und Nachhandelsdienste bieten wir ein umfassendes, integriertes Angebot vertrauenswürdiger Finanzmarktinfrastrukturdienste an, die unseren Kunden helfen, ihre Ambitionen zu verfolgen und zu erreichen. Sie können sich auf unser Open-Access-Modell für beispiellose Partnerschaften, Flexibilität, Stabilität und Unterstützung in all unseren Geschäftsbereichen verlassen. So machen wir den Unterschied – indem wir sicherstellen, dass Menschen weltweit ihr Potenzial ausschöpfen können.

Beschreibung

• Analyze and review penetration test reports to understand technical impact, exploitability, and business risk. • Develop, document and maintain remediation guidance, patterns, and blue-prints for common vulnerability types (e.g. injections, access control, auth, session management, misconfigurations). • Provide consultation to application and platform teams on secure design and remediation approaches, including code-level, configuration-level and business-level recommendations. • Coordinate remediation activities across multiple teams, ensuring, clear ownership, agreed timelines, and risk-based prioritization. • Validate fixes by retesting vulnerabilities (manually and/or via tools/scripts) and updating the status of findings through closure. • Manage and track the remediation backlog, including SLAs, aging findings, and critical issues when needed. • Produce and maintain documentation on remediation processes, workflows, and controls for audit and compliance purposes. • Prepare and deliver regular status reports and metrics on remediation progress, trends, and risk reduction to management and partners. • Perform root cause analysis for recurring or systemic issues and work with engineering, architecture, and governance teams to implement long-term corrective actions. • Contribute to continuous improvement of the pentest-to-remediation lifecycle, including automation, standardization and integration with SDLC/DevSecOps pipelines. • Compile technical documents, track and document remediation metadata Engagement details (who, what, when, where) Testing team members and roles Tools and methodologies used Schedule and timelines Target systems and environments Constraints, exclusions, and limitations Testing activities and event logs. • Contribute to team improvement efforts and ensure all initiatives and feedback are well documented for future references. • Contribute to the continuous improvement of testing methodologies, tooling, automation. • Stay ahead of with emerging threats, vulnerabilities, and offensive security techniques. • Participate in R&D initiatives as guided from leadership. • Support knowledge sharing and mentoring within the team.

🎯 Anforderungen

• Proven hands-on experience in penetration testing of Web Applications, APIs, Thick Client and Common Infrastructures (Active Directory, Cloud and Cloud-native based environments). • Proficiency with tools such as Burp Suite, common command-line tools, and ability to write custom scripts when needed. • Experience in automating pentesting tasks. • Solid understanding of application security, network protocols, and operating systems. • Experience with cloud platforms (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes). • Solid understanding of common vulnerabilities and exposures (OWASP Top 10, SANS Top 25) and secure coding practices in at least one major language stack (e.g. Java/ Springboot , .NET, JavaScript/Node, Python) • Ability to write clear, technical reports and communicate findings and fixes to both technical and non-technical partners. • Experience working in large, complex enterprise environments. • Proficient communication skills in English, both written and verbal. • Relevant certifications and engagement with the security community is a plus. • Threat Modelling experience is a plus. • Proven track record of successfully managing and driving security engagements for various organizations with differing operational and technical profiles. • Ability to identify, assess, and communicate technical and project risks to partners. • Understanding project requirements and aligning work with agreed upon objectives and timelines.

🏖️ Vorteile

• Healthcare • Retirement planning • Paid volunteering days • Wellbeing initiatives

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 10 Tagen

Carrier

10.000+ Mitarbeiter

🏗️ Bauwesen

🏥 Gesundheitswesen

📦 Logistik

Lead BMS Engineer responsible for commissioning and optimizing Building Management Systems across various customer sites. Provide technical support and expertise to project teams throughout the project lifecycle.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 10 Tagen

Atos

10.000+ Mitarbeiter

💼 Beratung

🏥 Gesundheitswesen

📦 Logistik

Wintel Engineer role at Atos Group managing complex changes for government clients. Responsibilities include ITIL process contributions and proactive incident resolution.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 10 Tagen

Zencargo

201 - 500

📦 Logistik

🚗 Transport

☁️ SaaS

Forward-Deployed Engineer at Zencargo solving operational and customer problems with software and AI. Collaborating with various stakeholders to automate freight processes and improve workflows.

🇬🇧 Vereinigtes Königreich – Remote

💰 €42.000.000 Series B im 2021-05

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 10 Tagen

INDEPTH HYGIENE SERVICES LIMITED

-

🏗️ Bauwesen

🏥 Gesundheitswesen

📦 Logistik

Damper & Ventilation Hygiene Engineer role at Indepth Hygiene Services focusing on ventilation hygiene and fire damper inspections. Full-time remote position with lots of potential for career growth.

🇬🇧 Vereinigtes Königreich – Remote

💵 £29.900 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 10 Tagen

Chalk

51 - 200

🤖 Künstliche Intelligenz

☁️ SaaS

🤝 B2B

Build bespoke technical solutions and feature pipelines for machine learning applications in healthcare and finance. Collaborate with customers to gather requirements and implement Chalk’s technology.

🇬🇧 Vereinigtes Königreich – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich