Senior Vulnerability Assessment Specialist
- Hiring from
- United Arab Emirates
- Work type
- Remote
- Posted
507,475 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
📍 Location: United Arab Emirates (Remote)
💼 Employment Type: Full-Time
🎯 Experience Level: Mid-Level to Senior
🌐 Work Arrangement: Fully Remote
About UsWe are a construction-focused organization committed to delivering complex projects through disciplined contract management, commercial excellence, risk control, and collaborative project delivery. Our distributed teams collaborate across Project Management, Construction, Engineering, Procurement, Commercial, Legal, Finance, Human Resources, Design, Quality, HSE, Consultants, Contractors, Suppliers, Logistics, Administration, Information Technology, and Executive Leadership to maintain secure, resilient, compliant, and reliable business operations across the organization.
The RoleWe are seeking an experienced Senior Vulnerability Assessment Specialist to lead and support vulnerability identification, assessment, prioritization, remediation, and continuous improvement across the organization's technology environment. The ideal candidate will provide strong technical expertise throughout the vulnerability management lifecycle, from asset discovery and vulnerability scanning through validation, risk analysis, remediation coordination, reporting, and continuous security improvement. This role will work closely with Cybersecurity, Network, Infrastructure, Cloud, Application Development, IT Support, Engineering, Project Management, vendors, consultants, and business stakeholders to reduce security exposure and strengthen the organization's overall cyber resilience.
Key Responsibilities- Lead and manage enterprise vulnerability assessment and vulnerability management activities across the organization.
- Develop, implement, and continuously improve vulnerability assessment policies, standards, procedures, and operating processes.
- Conduct authenticated and unauthenticated vulnerability assessments across servers, endpoints, network devices, applications, databases, cloud resources, and other technology assets.
- Maintain comprehensive visibility of technology assets and ensure systems are appropriately included in vulnerability assessment programs.
- Coordinate asset discovery and identification activities to detect previously unknown, unmanaged, or unauthorized systems.
- Configure, administer, and optimize vulnerability scanning and assessment platforms.
- Develop appropriate scanning schedules, profiles, credentials, policies, exclusions, and assessment configurations.
- Perform recurring vulnerability scans in accordance with organizational risk requirements and established assessment schedules.
- Conduct targeted vulnerability assessments following major infrastructure changes, new deployments, security incidents, or emerging threats.
- Review vulnerability scan results and validate findings for accuracy, relevance, severity, and exploitability.
- Investigate potential false positives and perform manual validation where automated assessment results require additional analysis.
- Analyze technical vulnerability information, affected assets, attack vectors, exploit conditions, and potential business impact.
- Prioritize vulnerabilities based on severity, exploitability, asset criticality, exposure, threat intelligence, business impact, and available compensating controls.
- Maintain risk-based vulnerability prioritization models aligned with organizational security objectives.
- Track critical and high-risk vulnerabilities and ensure appropriate remediation actions are initiated promptly.
- Coordinate vulnerability remediation activities with Network, Infrastructure, Endpoint, Cloud, Application, Database, and IT Support teams.
- Provide detailed remediation guidance to technical teams and system owners.
- Monitor remediation progress and ensure vulnerabilities are addressed within established service-level agreements.
- Validate remediation activities through rescanning, manual verification, configuration review, or other appropriate testing methods.
- Maintain accurate records of identified vulnerabilities, remediation status, exceptions, risk acceptance decisions, and verification results.
- Develop and maintain vulnerability dashboards, metrics, reports, and management summaries.
- Prepare regular vulnerability management reports covering exposure levels, remediation performance, trends, aging vulnerabilities, and outstanding risks.
- Establish and monitor key performance indicators for vulnerability discovery, remediation, verification, and risk reduction.
- Identify recurring vulnerabilities and systemic weaknesses that may require broader security or architectural improvements.
- Conduct vulnerability trend analysis to identify patterns across systems, applications, technologies, business units, and project environments.
- Monitor emerging vulnerabilities, security advisories, vendor notifications, threat intelligence, and publicly disclosed exploits.
- Assess newly disclosed vulnerabilities for relevance to the organization's technology environment.
- Coordinate accelerated assessments for vulnerabilities associated with active exploitation or significant security threats.
- Support emergency vulnerability response activities when critical vulnerabilities require immediate investigation or remediation.
- Evaluate exploitability and potential attack paths associated with critical vulnerabilities.
- Conduct network vulnerability assessments covering firewalls, routers, switches, wireless infrastructure, VPN systems, and other network technologies.
- Assess servers, workstations, laptops, mobile devices, virtual machines, and other endpoint technologies for security weaknesses.
- Conduct vulnerability assessments across cloud infrastructure, virtual networks, storage services, containers, and cloud-hosted workloads where applicable.
- Assess web applications, APIs, databases, middleware, and other application components for known security vulnerabilities.
- Coordinate application vulnerability assessments with development and application security teams.
- Support secure configuration assessments against approved organizational hardening standards and recognized security benchmarks.
- Identify insecure configurations, missing security controls, outdated software, unsupported systems, weak protocols, and unnecessary services.
- Review operating system, application, firmware, and third-party software versions for known vulnerabilities.
- Support patch management teams by providing accurate vulnerability intelligence and remediation priorities.
- Analyze the security impact of delayed patching, compensating controls, and temporary risk mitigation measures.
- Support vulnerability exception and risk acceptance processes with appropriate technical analysis and documentation.
- Review proposed remediation exceptions and assess whether compensating controls adequately reduce associated risk.
- Ensure accepted risks have appropriate ownership, documented justification, approval, and expiration or review dates.
- Conduct periodic reviews of vulnerability management coverage to identify gaps in scanning, asset visibility, credentials, or remediation processes.
- Integrate vulnerability assessment platforms with SIEM, ticketing, CMDB, asset management, SOAR, and other security technologies where appropriate.
- Automate vulnerability ticket creation, reporting, prioritization, notification, and remediation tracking where practical.
- Develop scripts and automation to improve assessment efficiency, data quality, validation, and reporting.
- Coordinate with penetration testing teams to provide vulnerability intelligence and support deeper security validation.
- Use penetration testing, threat intelligence, configuration reviews, and other security assessment results to strengthen vulnerability management activities.
- Support security audits, compliance assessments, internal control reviews, and regulatory examinations involving vulnerability management.
- Maintain evidence and documentation required for cybersecurity audits, contractual obligations, compliance programs, and management reviews.
- Ensure vulnerability assessment activities align with applicable United Arab Emirates cybersecurity, privacy, regulatory, contractual, and organizational requirements.
- Develop and maintain technical documentation covering vulnerability assessment procedures, scanning standards, remediation workflows, exception processes, and reporting requirements.
- Participate in cybersecurity architecture reviews and provide vulnerability risk input for new systems, applications, infrastructure, and projects.
- Assess security risks associated with legacy technologies, unsupported platforms, third-party applications, and externally exposed services.
- Work with system owners to develop practical remediation plans that balance security risk, operational requirements, project schedules, and business priorities.
- Provide security recommendations to reduce attack surface and improve system hardening.
- Support vulnerability management activities for remote workers, project sites, offices, cloud environments, and third-party connected systems.
- Evaluate third-party and vendor technology risks where vulnerability assessment information is available or contractually required.
- Maintain awareness of vulnerability research, common attack techniques, threat actor activity, exploitation trends, and emerging security technologies.
- Provide technical guidance and mentoring to junior vulnerability analysts, cybersecurity specialists, and IT personnel.
- Promote a proactive security culture focused on early vulnerability identification, timely remediation, measurable risk reduction, and continuous improvement.
- Recommend improvements to vulnerability management processes, tooling, automation, reporting, remediation workflows, and organizational security controls.
- Support business continuity and cyber resilience initiatives by identifying vulnerabilities that could materially affect critical business services.