Cybersecurity - Vulnerability Management (VMS) - German Speaker - Staff - EY GDS Spain - Hybrid
EY
- Location
- Malaga, ES, 29590
- Work model
- Hybrid
- Level
- Staff
Skills
About this role
Vulnerability Management Specialist (VMS) - German Speaker - EY GDS Spain - Hybrid The opportunity Vulnerability Management is a core pillar of modern cybersecurity. In this role, you manage vulnerabilities end to end – from identification and risk-based prioritization to sustainable risk reduction. You operate at the intersection of technology, operations, and management, enabling informed security decisions and measurable improvement of the organization’s attack surface. As a VMS at EY GDS Spain, you are the first line of defense in a 24/7 Cyber Security German-speaking clients In addition, you help design and roll out vulnerability management landscapes (tooling, processes, integrations, and operating models) to establish scalable, repeatable capabilities across environments. As a member of our team in the EY GDS Spain office in Malaga , you’ll have a chance to extend your knowledge & experience by working on interesting projects with the newest technologies and approaches. You’ll support clients in choosing the most suitable business solution and take part in digital transformation. Your key responsibilities · Design, operate, and continuously improve an end-to-end vulnerability management process · Design and roll out vulnerability management landscapes: tooling strategy, target architecture, integrations (e.g., ITSM), and operating model · Continuously identify, consolidate, and assess vulnerabilities across technical systems and environments · Perform risk-based prioritization by considering technical and organizational context (asset criticality, exposure, compensating controls, business impact) · Coordinate and track remediation activities with responsible teams and stakeholders · Maintain transparency on status, progress, exceptions, and accepted risks · Prepare structured reporting for operational, tactical, and strategic stakeholders (status, risk, trends, KPIs) · Support internal reviews, audits, management assessments, and decision-making processes · Continuously optimize vulnerability management processes, methods, and metrics to improve maturity and measurable outcomes Skills and attributes for success · Structured, analytical, and self-driven working style with strong ownership · Ability to communicate complex technical topics clearly and effectively to diverse stakeholders · Strong coordination and stakeholder management skills across technology, operations, and management · High sense of responsibility and quality awareness; focus on auditability and traceability · Ability to translate security requirements into operationally feasible remediation plans and measurable progress To qualify for the role, you must have · 1 - +2 years of experience in vulnerability management, security management, or IT security · Solid understanding of IT infrastructures, platforms, and system environments · Experience with vulnerability lifecycle management from detection through remediation, verification, and risk acceptance · Completed education or degree in a technical or information-technology related field (or equivalent practical experience) · English at least B2 (written and spoken) is required. . German at least B2 (written and spoken) is required. Ideally, you’ll also have · Hands-on experience with vulnerability management platforms such as Tenable and/or Qualys (nice to have) · Experience working in regulated environments and/or supporting audit and compliance requirements · Familiarity with common scoring and prioritization approaches (e.g., CVSS as an input to risk-based prioritization) and KPI-driven reporting · Experience collaborating with engineering, operations, and service management teams in complex environments What we look for We look for proactive owners who turn vulnerability data into