Application Security Analyst – Vulnerability Management Expert.
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Operating mode : Hybrid
Type of contract : Freelance
Start date : ASAP
Level of education required : Bac+5
Looking for a new challenge ? Join Eleveight
We are hiring on behalf of our partner in the technology sector and are looking for a Vulnerability Management Expert
We are seeking an experienced Application Security Analyst to own end-to-end vulnerability identification, analysis and reporting. The ideal candidate will manage DAST, SAST, and SCA execution, ensure high quality findings maintain visibility through dashboards and reports, and provide risks insights to Governance team. This role requires strong technical depth in vulnerabilities, excellent communication skills, and the ability to translate findings into actionable remediation.
Responsibilities:
· Perform Static and Dynamic Application Security Testing (SAST/DAST) and Software Composition Analysis (SCA) for in-scope assets; analyze findings, assess severity, and prioritize end-to-end remediation with IT stakeholders.
· Create and maintain a customized vulnerability management dashboard to enable GRC and remediation teams to track actions efficiently.
· Document and maintain comprehensive records of vulnerability scan results, analysis, and recommended mitigation paths.
· Provide regular reports and risk summaries to stakeholders (management, IT teams, and other relevant parties) on the status of vulnerabilities.
· Assist in developing and implementing vulnerability assessment policies, procedures, and guidelines to ensure consistent, effective practices.
· Articulate findings clearly with recommendations; stay current with industry trends, emerging threats, and best practices in vulnerability management.
· Generate, analyze, and present reports on security ratings, trends, anomalies, and areas for improvement.
· Serve as a Subject Matter Expert (SME) on vulnerability assessment tools, techniques, and methodologies.
Profile required
· Bachelor’s degree in computer science, information security, or a related field.
· 4–7 years of experience in vulnerability management.
· Hands-on experience with vulnerability scanning tools and platforms; specifically, Qualys, Checkmarx, SonarQube Advanced Security, and Tenable.io.
· Strong analytical skills to assess scan results, identify false positives, and prioritize remediation efforts.
· Knowledge of Security frameworks and standards: OWASP Top 10, CVE/CVSS, NIST CSF, ISO 27001, PCI DSS, HIPAA
· Understanding of SDLC and Agile methodologies; foundational knowledge of secure coding practices and information security policies.
· Excellent communication and teamwork abilities; ability to work with cross-functional teams and senior stakeholders.
Skills /Abilities
· Able to work effectively in large, complex organizations by building good relationships and helping different teams work together, even when they have different goals or ways of working.
· Strong interpersonal and communication skills, including assertiveness, active listening, and empathy—essential for building trust and influencing across technical and non-technical teams.
· A collaborative team player with a proactive mindset, capable of leading cross-functional initiatives and fostering a culture of shared responsibility in security.
· Demonstrated ability to apply analytical rigor to assess complex business and technical scenarios, translating them into actionable security strategies.
· Fluent in English, with the ability to clearly articulate technical concepts, risks, and recommendations to both technical and executive audiences.
Preferred Qualifications:
· Certifications such as CySA+, CEH, or vendor certifications such as Qualys /Checkmarx).
· Experience with regulatory standards and frameworks (ISO/IEC 27001, NIST, PCI DSS, HIPAA).
· Scripting skills (e.g., Python, PowerShell) for automation.
· Cloud security experience (AWS, Azure, GCP).
· Familiarity with regulatory requirements related to vulnerability management.
About Eleveight
Eleveight is a consulting and recruitment company specializing in tailored talent solutions to support businesses in their transformation.
We connect top experts in Change & Transformation, Business Applications, and Data & AI with ambitious projects, offering opportunities that match their skills and career goals. With our personalized approach and international network, we provide high-quality support throughout the process, ensuring engaging missions and a work environment that fosters professional growth. Join Eleveight and unlock opportunities that recognize your expertise and accelerate your career.