Vulnerability Management Analyst
2 days ago
Vulnerability Management Analyst
Level
Middle
Department
Other IT Positions
Type
Full Time
Project
bolttech
Locations:
Romania
Remote
Job Details
Posted on:
September 26, 2025
About the Company
Established in 2004, ALLSTARSIT was founded with a clear vision: to enhance the landscape of global IT employment by bridging the gap between companies and skilled professionals. The core belief was that assembling a team shouldn't be hindered by geographical constraints. Fast forward to the present day, ALLSTARSIT stands as an international outstaffing service provider committed to change the way businesses recruit, compensate, and oversee top talent worldwide.
With operational hubs scattered across Europe, Asia, and LATAM, and its headquarters situated in San Francisco, US, the company boasts a workforce of over 1,000 adept professionals. Spanning across more than 20 countries, ALLSTARSIT offers a diverse range of skilled employees across various verticals, including AI, cybersecurity, healthcare, fintech, telecom, media, and so on.
About the Project
bolttech is an international insurtech with a mission to build the world's leading, technology-enabled ecosystem for protection and insurance. With a full suite of digital and data-driven capabilities, bolttech powers connections between insurers, distributors, and customers to make it easier and more efficient to buy and sell insurance and protection products. A part of Pacific Century Group, bolttech serves customers in multiple markets across North America, Asia and Europe.
In this position you will…
Own the intake, prioritization, and dissemination of security vulnerabilities across bolttech, coordinate scanning across infrastructure, applications and cloud, translate findings into business‑aware risk, and drive closure by engaging system and business owners, while maintaining metrics, KPIs, and executive reporting.
Required skills:
- At least 3 years of hands‑on experience in vulnerability management, threat and vulnerability management or SecOps, with a track record of driving issues to verified closure.
- Proven expertise with VM tooling, for example Tenable, Qualys or Rapid7, plus exposure to application and cloud security scanners such as Snyk, container scanning and CSPM.
- Strong understanding of prioritisation models, including CVE, CVSS v4.0, EPSS and CISA KEV, and how to apply asset criticality and business context to focus effort.
- Practical experience coordinating scans, authenticated and unauthenticated, internal and external, defining safe windows, credentials, scopes and frequencies.
- Proficiency with workflow and evidence management, using Jira or similar to route, track, retest and document remediation activities.
- Data and automation skills to cleanse data, enrich findings, build dashboards and automate repeatable tasks.
- Working knowledge of enterprise platforms, for example AWS, Azure, GCP and Microsoft 365, plus operating system and patching fundamentals for Windows, Linux and macOS.
- Familiarity with compliance frameworks, ISO 27001, SOC 2 and PCI DSS, including preparing audit‑ready artefacts for scans, prioritization and retests.
- Clear written and verbal communication, able to translate technical issues into business‑relevant risk and influence stakeholders across global teams and time zones.
- Education and certifications, degree in Computer Science, Information Security or related field preferred, relevant certifications such as Security+, CySA+, GSEC, or vendor credentials for Tenable, Qualys, AWS, GCP or Azure are a plus.
Scope of work:
- Owning the end‑to‑end intake and triage of vulnerabilities from infrastructure and application scanners, code and container security tools, cloud posture sources, bug bounty, and trusted third parties.
- Coordinating internal and external, authenticated and unauthenticated scanning, agreeing safe windows, credentials, scopes and frequencies, and ensuring meaningful coverage of internet‑facing and crown‑jewel assets.
- Maintaining high‑quality vulnerability data hygiene by mapping findings to assets, applications and owners, deduplicating and suppressing noise according to agreed criteria.
- Normalizing and enriching findings in the RBVM platform with business tags, asset criticality and threat intelligence, for example CVSS v4.0, EPSS and CISA KEV, to produce a clear, risk‑based prioritization.
- Routing and tracking prioritized work through the agreed workflow and tooling, monitoring status through verification, scheduling retests and keeping records current.
- Operating the exception and risk acceptance workflow when required, documenting compensating controls, expiry dates and periodic reviews.
- Building and publishing dashboards and reports that show SLA adherence, MTTR, backlog age, KEV and high‑EPSS closure rates, scanner and asset coverage, and owner assignment rates.
- Driving continuous improvement by tuning scan policies, credentials and schedules, reducing false positives, refining deduplication and grouping, and improving tagging and risk weights.
- Supporting incident response and threat‑driven surges by rapidly identifying exposure, producing owner lists and fast‑tracking high‑risk remediation work.
- Maintaining SOPs, standards and knowledge articles for vulnerability management, and preparing audit‑ready evidence for ISO 27001, SOC 2 and PCI DSS where applicable.
- Partnering with IT, cloud, product and engineering teams to plan remediation activities and communicate risk and timelines clearly.
- Automating repeatable tasks to streamline enrichment, ticket creation and evidence collection.
For you to be successful…
- Think risk-first, translating technical findings into clear business impact and priorities.
- You are passionate about cybersecurity and turn vulnerability data into meaningful risk reduction for the business.
- Communicate effectively with engineers and other stakeholders, using data to influence decisions.
- You are collaborative, working across IT, cloud, DevOps and product teams to align remediation plans, timelines and validation steps.
- You are meticulous with data hygiene, maintaining accurate asset, owner and finding records, and reducing noise through sensible deduplication and suppression.
- You stay current, tracking emerging threats and evolving vulnerability management practices.
-
Threat Analyst
5 days ago
Romania Sophos Technology GmbH Full time €30,000 - €60,000 per yearAbout UsSophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure-play Managed...
-
Product Security Engineer
2 weeks ago
Romania Edenred Full time €40,000 - €80,000 per yearTake a step forward and let Edenred surprise you.Every day, we deliver innovative solutions to improve the life of millions of people, connecting employees, companies, and merchants all around the world.We know there are hundred ways for you to grow. With us, you will expand your skills in a multicultural, challenging, and dynamic environment.Dare to join...
-
Psychologist – Romania, Moldova
2 weeks ago
Romania Word Made Flesh Full time €20,000 - €60,000 per yearExplore our openings below. Each community may also have ongoing needs not listed here—roles in education, administration, communications, advocacy, or program support are often needed. If you don't see a position that matches your skills, we still encourage you to reach out. If you are interested in learning more about staff needs in a specific field...
-
SAP Business Analyst Logistics
4 days ago
Romania TRELLEBORG Full time 15,000 - 25,000 per yearTrelleborg is a world leader in engineered polymer solutions for almost every industry on the planet. And we are where we are because our talents brought us here. By specializing in the polymer engineering that makes innovation and application possible, Trelleborg works closely with leading industry brands to accelerate their performance, drive their...
-
Premier Helpdesk Analyst
7 days ago
Romania Travelport Full time 15,000 - 30,000 per yearWe're looking for GDS specialists to provide guidance and technical support to our frontline customer service across the full Travelport range.Travel obsessed? Big tech fan? Hey, you're in good company. If you want to be part of the industry that makes the world go round, then look no further.Travelport is the brains behind lots of your travel bookings-...
-
Transformation Business Analyst
5 days ago
Romania Autoliv Full time €40,000 - €80,000 per yearAutoliv's primary goal is to Save More Lives. Our products never get a second chance. This is why we can never compromise on quality. We are working to increase vehicle safety by developing seatbelts, airbags and steering wheels and you can be part of our team as Transformation Business Analyst.In this role you will collaborate cross-functionally to drive...
-
Junior Data Science Analyst
5 days ago
Romania Nokia Full time €15,000 - €30,000 per yearAt Nokia, the Network Infrastructure (NI) business group plays a pivotal role in providing actionable insights and analytics to senior leadership. We are in the midst of an exciting transformation, building a unified data lake, automating manual analysis, and enabling predictive models to improve business outcomes.As a Data Science Specialist, you'll play a...
-
Retail Business Software Analyst with German
4 days ago
Romania Goodyear Full time 15,000 - 30,000 per yearWhy This Role MattersAs a Retail Business Software Analyst with German , you will play a key role in ensuring the accuracy, stability, and optimization of Goodyear's Retail Service systems. Acting as a second point of contact for Retail Service Agents, you'll bridge business needs with IT solutions, analyzing requirements, implementing enhancements, and...
-
IT Business Analyst POS Health Insurance
2 weeks ago
Romania UNIQA Raiffeisen Software Service Full time €15,000 - €30,000 per yearThis is a full-time job suitable for passionate professionals who want to work for a leading European Insurance Group on a very flexible work schedule.You will work as part of a multinational group with true, large, enterprise-wide systems, complex architectures and real-life constraints (speed, performance, non-stop systems availability) and are going to be...
-
Engineering Manager
1 week ago
Romania Globant Full time €60,000 - €80,000 per yearAt Globant, we are working to make the world a better place, one step at a time. We enhance business development and enterprise solutions to prepare them for a digital future. With a diverse and talented team present in more than 30 countries, we are strategic partners to leading global companies in their business process transformation.We are looking for an...