Vulnerability Response Senior SME

Mindbox Sp. z o.o.Krakównofluffjobspublicēts 04.09.2026
Obligāti:CloudCI/CDSecurityRemoteHybrid

At Mindbox we connect top IT talents with technology projects for leading enterprises across Europe.

Join our client's team, where you'll play a key role in shaping the Vulnerability Management Response & Remediation function at one of the world's leading international banks. Your contribution will help deliver high-impact solutions in cybersecurity – protecting a global financial institution's technology estate across on-premise, cloud, and third-party environments.

Sounds like your kind of challenge?

Hybrid: 6x/msc from the office in Kraków

What you get in return

Flexible cooperation model – choose the form that suits you best (B2B, employment contract, etc.)

Hybrid work setup – Hybrid: 6x/msc from the office in Kraków

Collaborative team culture – work alongside experienced professionals eager to share knowledge

Continuous development – access to training platforms and growth opportunities

Comprehensive benefits – including Interpolska Health Care, Multisport card, Warta Insurance, and more

High quality equipment – laptop and essential software provided

Daily tasks

  • Assess and Review Vulnerabilities: Analyze critical and high-severity vulnerabilities (NIST/NVD, vendor advisories), determine exposure and impact on our environment.
  • Validate and Map Risks: Confirm findings, validate exposure, and map vulnerabilities to assets through CMDB and inventory collaboration.
  • Define Mitigation Strategies: Recommend remediation and mitigation approaches such as patching, upgrades, hardening, and compensating controls.
  • Drive Execution & Governance: Coordinate remediation progress, ensure timely delivery, and provide high-quality technical and governance reports.
  • Verify Effectiveness: Oversee validation testing and confirm closure of remediation activities.
  • Regulatory & Audit Support: Provide data and commentary for regulatory, audit, and governance reporting (Risk Maps, KCIs, KRIs).

Requirements

Minimum 5 years of experience in IT Security or a similar role

Proven experience reviewing and assessing critical/high-severity vulnerabilities from sources such as NIST/NVD and vendor advisories, translating findings into clear business impact

Strong understanding of common vulnerability types and attack techniques (e.g., remote code execution, privilege escalation, authentication bypass)

Experience with vulnerability scanning tools, including Tenable, and application security testing (SAST, DAST)

Solid technical foundation across networking and application delivery, including WAFs, load balancers, and TLS/certificates

Experience working across on-prem and cloud environments

Practical knowledge of remediation approaches: patching, upgrades, configuration hardening, and compensating controls

Strong stakeholder management skills – able to partner with service owners, platform teams, and governance stakeholders to drive actions to closure

Excellent written communication skills

Nice to have

Good understanding of the CI/CD lifecycle and how security testing integrates into build and release pipelines

Background in Cyber Security Operations, Risk Management, or Governance within a mid-to-large enterprise

Joining this project you’ll become part of Mindbox – a tech-driven company where consulting, engineering, and talent meet to build meaningful digital solutions. We’ll back you up every step of the way, accelerate your development, and ensure your skills make a difference.

Must have: Security, NIST, Testing, SAST, DAST, Networking, TLS, Cloud, Stakeholder management