
Vulnerability Management Analyst
2 days ago
Vulnerability Management Analyst
Level
Middle
Department
Other IT Positions
Type
Full Time
Project
bolttech
Locations:
Romania
Remote
Job Details
Posted on:
September 26, 2025
About the Company
Established in 2004, ALLSTARSIT was founded with a clear vision: to enhance the landscape of global IT employment by bridging the gap between companies and skilled professionals. The core belief was that assembling a team shouldn't be hindered by geographical constraints. Fast forward to the present day, ALLSTARSIT stands as an international outstaffing service provider committed to change the way businesses recruit, compensate, and oversee top talent worldwide.
With operational hubs scattered across Europe, Asia, and LATAM, and its headquarters situated in San Francisco, US, the company boasts a workforce of over 1,000 adept professionals. Spanning across more than 20 countries, ALLSTARSIT offers a diverse range of skilled employees across various verticals, including AI, cybersecurity, healthcare, fintech, telecom, media, and so on.
About the Project
bolttech is an international insurtech with a mission to build the world's leading, technology-enabled ecosystem for protection and insurance. With a full suite of digital and data-driven capabilities, bolttech powers connections between insurers, distributors, and customers to make it easier and more efficient to buy and sell insurance and protection products. A part of Pacific Century Group, bolttech serves customers in multiple markets across North America, Asia and Europe.
In this position you will…
Own the intake, prioritization, and dissemination of security vulnerabilities across bolttech, coordinate scanning across infrastructure, applications and cloud, translate findings into business‑aware risk, and drive closure by engaging system and business owners, while maintaining metrics, KPIs, and executive reporting.
Required skills:
- At least 3 years of hands‑on experience in vulnerability management, threat and vulnerability management or SecOps, with a track record of driving issues to verified closure.
- Proven expertise with VM tooling, for example Tenable, Qualys or Rapid7, plus exposure to application and cloud security scanners such as Snyk, container scanning and CSPM.
- Strong understanding of prioritisation models, including CVE, CVSS v4.0, EPSS and CISA KEV, and how to apply asset criticality and business context to focus effort.
- Practical experience coordinating scans, authenticated and unauthenticated, internal and external, defining safe windows, credentials, scopes and frequencies.
- Proficiency with workflow and evidence management, using Jira or similar to route, track, retest and document remediation activities.
- Data and automation skills to cleanse data, enrich findings, build dashboards and automate repeatable tasks.
- Working knowledge of enterprise platforms, for example AWS, Azure, GCP and Microsoft 365, plus operating system and patching fundamentals for Windows, Linux and macOS.
- Familiarity with compliance frameworks, ISO 27001, SOC 2 and PCI DSS, including preparing audit‑ready artefacts for scans, prioritization and retests.
- Clear written and verbal communication, able to translate technical issues into business‑relevant risk and influence stakeholders across global teams and time zones.
- Education and certifications, degree in Computer Science, Information Security or related field preferred, relevant certifications such as Security+, CySA+, GSEC, or vendor credentials for Tenable, Qualys, AWS, GCP or Azure are a plus.
Scope of work:
- Owning the end‑to‑end intake and triage of vulnerabilities from infrastructure and application scanners, code and container security tools, cloud posture sources, bug bounty, and trusted third parties.
- Coordinating internal and external, authenticated and unauthenticated scanning, agreeing safe windows, credentials, scopes and frequencies, and ensuring meaningful coverage of internet‑facing and crown‑jewel assets.
- Maintaining high‑quality vulnerability data hygiene by mapping findings to assets, applications and owners, deduplicating and suppressing noise according to agreed criteria.
- Normalizing and enriching findings in the RBVM platform with business tags, asset criticality and threat intelligence, for example CVSS v4.0, EPSS and CISA KEV, to produce a clear, risk‑based prioritization.
- Routing and tracking prioritized work through the agreed workflow and tooling, monitoring status through verification, scheduling retests and keeping records current.
- Operating the exception and risk acceptance workflow when required, documenting compensating controls, expiry dates and periodic reviews.
- Building and publishing dashboards and reports that show SLA adherence, MTTR, backlog age, KEV and high‑EPSS closure rates, scanner and asset coverage, and owner assignment rates.
- Driving continuous improvement by tuning scan policies, credentials and schedules, reducing false positives, refining deduplication and grouping, and improving tagging and risk weights.
- Supporting incident response and threat‑driven surges by rapidly identifying exposure, producing owner lists and fast‑tracking high‑risk remediation work.
- Maintaining SOPs, standards and knowledge articles for vulnerability management, and preparing audit‑ready evidence for ISO 27001, SOC 2 and PCI DSS where applicable.
- Partnering with IT, cloud, product and engineering teams to plan remediation activities and communicate risk and timelines clearly.
- Automating repeatable tasks to streamline enrichment, ticket creation and evidence collection.
For you to be successful…
- Think risk-first, translating technical findings into clear business impact and priorities.
- You are passionate about cybersecurity and turn vulnerability data into meaningful risk reduction for the business.
- Communicate effectively with engineers and other stakeholders, using data to influence decisions.
- You are collaborative, working across IT, cloud, DevOps and product teams to align remediation plans, timelines and validation steps.
- You are meticulous with data hygiene, maintaining accurate asset, owner and finding records, and reducing noise through sensible deduplication and suppression.
- You stay current, tracking emerging threats and evolving vulnerability management practices.
-
Threat Analyst
4 days ago
Romania Sophos Full time €120,000 - €150,000 per yearAbout Us Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure-play...
-
Threat Analyst
6 days ago
Romania Sophos Technology GmbH Full time €30,000 - €60,000 per yearAbout UsSophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure-play Managed...
-
Senior Python Engineer
5 hours ago
Romania Intetics Full time 40,000 - 60,000 per yearIntetics Inc., a global technology company providing custom software application development, distributed professional teams, software product quality assessment, and "all-things-digital" solutions, is seeking a highly skilled and experienced Senior Python Engineer to join our dynamic team on a full-time basis.About the project:This project offers a...
-
Business Analyst
4 days ago
Remote, Romania Nagarro Full time 40,000 - 60,000 per yearCompany Description We're Nagarro. We are a digital product engineering company that is scaling in a big way We build products, services, and experiences that inspire, excite, and delight. We work at scale — across all devices and digital mediums, and our people exist everywhere in the world experts across 39 countries, to be exact). Our work culture is...
-
Senior Cybersecurity Engineer/Analyst
5 hours ago
Romania Dhara Consulting Group Full time 40,000 - 60,000 per yearTodaySecretUnspecifiedUnspecifiedIT - SecurityMK, Romania (ON-SITE/OFFICE)Overview**CONTINGENT UPON CONTRACT AWARD** SOSi is seeking a highly qualified Senior Cybersecurity Engineer / Analyst to support US Army requirements in the Europe & Africa Area of Responsibility (AOR).Essential Job Duties Plan, implement, upgrade, or monitor security measures for...
-
Premier Helpdesk Analyst
1 week ago
Romania Travelport Full time 15,000 - 30,000 per yearWe're looking for GDS specialists to provide guidance and technical support to our frontline customer service across the full Travelport range.Travel obsessed? Big tech fan? Hey, you're in good company. If you want to be part of the industry that makes the world go round, then look no further.Travelport is the brains behind lots of your travel bookings-...
-
Transformation Business Analyst
6 days ago
Romania Autoliv Full time €40,000 - €80,000 per yearAutoliv's primary goal is to Save More Lives. Our products never get a second chance. This is why we can never compromise on quality. We are working to increase vehicle safety by developing seatbelts, airbags and steering wheels and you can be part of our team as Transformation Business Analyst.In this role you will collaborate cross-functionally to drive...
-
Junior Data Science Analyst
6 days ago
Romania Nokia Full time €15,000 - €30,000 per yearAt Nokia, the Network Infrastructure (NI) business group plays a pivotal role in providing actionable insights and analytics to senior leadership. We are in the midst of an exciting transformation, building a unified data lake, automating manual analysis, and enabling predictive models to improve business outcomes.As a Data Science Specialist, you'll play a...
-
Engineering Manager
1 week ago
Romania Globant Full time €60,000 - €80,000 per yearAt Globant, we are working to make the world a better place, one step at a time. We enhance business development and enterprise solutions to prepare them for a digital future. With a diverse and talented team present in more than 30 countries, we are strategic partners to leading global companies in their business process transformation.We are looking for an...
-
Romania Asahi Group Holdings Full time 25,000 - 60,000 per yearAsahi Breweries Europe Group is a leading brewing company with 128 years of heritage, offering premium brands like Pilsner Urquell and Asahi Super Dry across CEE.Ursus Breweries is the largest beer producer in Romania. The brands in the Ursus Breweries portfolio are: URSUS, Timișoreana, Ciucaș, Peroni Nastro Azzurro, Kozel, Azuga, Pilsner Urquell, Asahi...