Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector

Devoteam
Porto
Workplace: HybridFull timeFunction: CybersecuritySkills: ["Communication","Analytical and problem-solving","Autonomy","Organization","Prioritization"]

Own the vulnerability management lifecycle across infrastructure, endpoints, and development pipelines for enterprise clients in the retail and e-commerce sector. Define and track remediation SLAs, monitor and escalate SLA breaches, and critically validate tool findings (reducing false positives). Assess cloud, container/image, and technology obsolescence risks, produce dashboards and KPI reporting, and automate/standardize operational procedures within the Vulnerability Management Program.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Devoteam
Devoteam
22 hours ago

Devoteam Cyber Trust | Vulnerability Manager | Retail & E-commerce Sector

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Own the vulnerability management lifecycle across infrastructure, endpoints, and development pipelines for enterprise clients in the retail and e-commerce sector. Define and track remediation SLAs, monitor and escalate SLA breaches, and critically validate tool findings (reducing false positives). Assess cloud, container/image, and technology obsolescence risks, produce dashboards and KPI reporting, and automate/standardize operational procedures within the Vulnerability Management Program.
Location: Porto
Workplace: Hybrid
Employment Type: Full time · Permanent
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Manage the vulnerability lifecycle across infrastructure and endpoints, including analysis and prioritization using CVE/CVSS/KEV/exploitability and business context.
  • •Define, monitor, and validate remediation or mitigation processes, identify SLA breaches, perform follow-ups, and escalate issues to the right teams.
  • •Identify and monitor vulnerabilities within development pipelines (SSDLC), coordinating with the AppSec team.
  • •Assess and analyze risk from technology obsolescence (EOL/EOS) and security findings across cloud environments, containers, and images.
  • •Produce vulnerability dashboards and KPI reporting, and automate/document operational procedures within the Vulnerability Management Program.

Key Requirements

  • •Fundamental knowledge of vulnerability management concepts including CVE, CVSS, KEV, exploitability, severity, prioritization, and remediation.
  • •Experience defining and managing vulnerability remediation SLAs, monitoring progress, following up, and escalating issues.
  • •Knowledge of security obsolescence risk assessment (EOL/EOS) and secure software concepts such as SSDLC, SCA, and SAST.
  • •Hands-on technical knowledge of Windows and Linux, networking (TCP/IP, DNS, HTTP/HTTPS), and vulnerability management platforms.
  • •Ability to critically validate security tool results, investigating false positives and confirming findings rather than assuming accuracy.
Skills:CommunicationAnalytical and problem-solvingAutonomyOrganizationPrioritization
Certifications:GIAC Enterprise Vulnerability Assessor (GEVA) (SEC460)CompTIA CySA+CompTIA Security+Microsoft AZ-500Google Professional Cloud Security Engineer
Languages:English
Tech Stack:CVECVSSKEVWindowsLinuxTCP/IPDNSHTTP/HTTPSTenable OneCrowdStrike FEMMicrosoft AzureGoogle CloudSCASASTIaC scanningSecure Software Development Lifecycle (SSDLC)Cloud securityContainer vulnerabilitiesContainer image vulnerabilitiesDashboards

Company Brief

Devoteam
Devoteam is an IT consulting firm specializing in digital transformation, cloud, cybersecurity, and data solutions for enterprise clients across Europe and the Middle East, combining technology partnerships with management consulting services.
Industry: Consulting
Company Size: Enterprise (1,001+ employees)
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Paris, France
Founded: 1995
WebsiteLinkedIn