GrantThornton - regiony

Vulnerability Management Engineer & Ops Senior Manager

Kontakt w sprawie rekrutacji

Weronika Szymanowska

Starszy Specjalista ds. Potencjału Ludzkiego

What you'll be responsible for:

We are looking for an experienced Vulnerability Management Engineering and Operations Senior Manager with strong hands-on expertise in Wiz (including Wiz UVM) and, additionally, Qualys, secure configuration assessments, policy compliance scanning, CrowdStrike exposure management, and enterprise vulnerability management. The ideal candidate will also have experience working with these and other cloud security platforms to identify, prioritize, and help remediate vulnerabilities across hybrid environments, using technology platforms and innovative automation solutions using AI.

Key Responsibilities

  • Administer and enhance the organization's vulnerability management program, ensuring vulnerabilities are identified, assessed, and remediated across on-premises, cloud, and hybrid infrastructures.

  • Execute vulnerability assessments, secure configuration reviews, and policy compliance scans using Wiz, Qualys, and related security tools.

  • Investigate, prioritize, and remediate vulnerabilities identified by Qualys, Wiz, and other Cloud Security Posture Management (CSPM) platforms.

  • Hands-on experience in generating actionable vulnerability reports for patch management teams, enabling timely and efficient remediation of security vulnerabilities.

  • Partner with relevant teams to prioritize remediation activities based on business risk and compliance requirements.

  • Experience in patch management and creating patch jobs, and coordinating with relevant teams to execute patch management processes.

  • Integrate vulnerability management solutions with SIEM, ITSM, and other platforms to improve operational efficiency and remediation workflows.

  • Create and maintain dashboards, reports, and security metrics for leadership, compliance, and audit purposes.

  • Monitor emerging security threats, newly disclosed vulnerabilities, and industry best practices to continuously improve the vulnerability management process.

  • Assist with compliance initiatives, including PCI-DSS, ISO 27001, and SOC 2, by providing vulnerability assessment results and configuration compliance reporting.

  • Design and implement AI-powered automation solutions to streamline workflows, reduce manual tasks, improve operational efficiency, and automate repetitive business processes.

Our expectations:

Required Qualifications

  • 10–12 years of experience in vulnerability management, cybersecurity, or a related information security role.

  • Practical experience with Wiz, Qualys, including vulnerability scanning, secure configuration assessment, and policy compliance modules.

  • Working knowledge of Wiz UVM and other comparable CSPM solutions for cloud vulnerability and misconfiguration management.

  • Hands-on experience integrating vulnerability management platforms with SIEM, ITSM, and patch management solutions.

  • Strong understanding of Windows and Linux operating systems, networking fundamentals, and cloud platforms including AWS, Azure, and GCP.

  • Solid knowledge of CVSS scoring, risk-based vulnerability prioritization, and remediation methodologies.

  • Familiarity with AI tools, workflow automation platforms, and integrating AI into existing systems is preferred.

  • Fluency in Polish and English.

Preferred Qualifications

  • Experience developing automation using Copilot or other Agentic AI frameworks

  • Industry certifications such as Qualys Certified Specialist, Wiz Certified Professional, CISSP, CEH, or CompTIA Security+ are highly desirable.

Soft Skills

  • Excellent communication, collaboration, and stakeholder management abilities.

  • Strong analytical and problem-solving skills with the ability to manage multiple priorities in a fast-paced environment.

  • Experience working within multinational environments with complex IT asset landscapes.

  • Attention to detail and accuracy.

  • Strong problem-solving and analytical abilities.

  • Ability to translate compliance requirements into technical controls.

  • Commitment to continuous improvement and maturity enablement of the program.

What we offer:

  • Hybrid working model (2 days in the office and 3 days working remotely)
  • Stable employment with an employment contract, private medical care, and a benefits package including MultiSport and a benefits platform
  • Opportunity to work in an international environment and collaborate with experienced Grant Thornton experts and professionals from around the world
  • A culture based on teamwork, trust, and knowledge sharing
  • A well-structured onboarding program to support a smooth start and successful integration into your new role
  • Clear career development paths and access to learning and certification programs
  • Access to training platforms and tools that support professional growth
  • An inclusive workplace that welcomes people with disabilities
  • A modern office in Poznań, located in Malta Office Park
Poznań
Vulnerability Management Engineer & Ops Senior Manager

Jak przebiega rekrutacja?

Wybierz interesującą Cię ofertę
  • Wybierz interesującą Cię ofertę
    Znajdź stanowisko, które Cię interesuje, na liście poszukiwanych przez nas profili:
    Wybierz interesującą Cię ofertę
  • Zaaplikuj
    Wyślij swoje CV w języku polskim w odpowiedzi na interesującą Cię ofertę.
    Zaaplikuj
  • Daj się poznać!
    Jeżeli pasujesz do profilu osoby, której poszukujemy, zaprosimy Cię na spotkanie online. W rozmowie weźmie udział rekruter oraz Twój przyszły menedżer. Porozmawiamy o Twoich dotyczasowych doświadczeniach i obecnej sytuacji zawodowej, a także o aspiracjach na przyszłość. Spodziewaj się pytań z obszarów merytorycznych, a jeśli stanowisko tego wymaga – to również krótkiej rozmowy po angielsku.
    Daj się poznać!
  • Wypatruj odpowiedzi
    Jeśli wszystko poszło dobrze, otrzymasz od nas ofertę współpracy. Jeśli nie – powiemy, co miało wpływ na naszą decyzję.
    Wypatruj odpowiedzi
  • Witamy na pokładzie!
    Ustalimy dogodny dla obu stron termin i formę rozpoczęcia współpracy.
    Witamy na pokładzie!
  • Is it possible to work remotely?
    We work in a hybrid model that combines the flexibility of remote work with the benefits of in-person collaboration. Regular presence in our Poznań office is important to us, typically 2-3 days per week. For more details about the working model, feel free to ask during the recruitment process.
  • What is the dress code at Grant Thornton?
    We ask that you follow specific guidelines depending on the business situation. When working independently—and provided there are no scheduled meetings with clients or business partners—a casual dress code applies; you can wear whatever is comfortable, such as a T-shirt, jeans, or a casual shirt. After all, hardly anyone sits at home in a suit and tie or a formal business suit unless they have to. However, if meetings are scheduled, your attire should be more formal and appropriate for the client. You will certainly receive detailed information about these guidelines before you start at GT, so you know what to expect.
  • Will I always receive feedback after a job interview?
    We always get back to candidates with feedback—regardless of the recruitment outcome—within a maximum of two weeks following the interview. This contact may be via phone or email. We also inform candidates if the recruitment process takes longer than expected. We strive to ensure our candidates always know the current status of their application.
  • What are the possible forms of cooperation?
    We offer employment based on a contract of employment (Umowa o Pracę). Details regarding the employment terms are discussed during the recruitment process.

Kontakt w sprawie rekrutacji

Karolina Winiarczuk

Starszy specjalista ds. potencjału ludzkiego

Poznań
Vulnerability Management Engineer & Ops Senior Manager
Informacja o ciasteczkach

1. W ramach witryny Administrator stosuje pliki Cookies w celu świadczenia usług na najwyższym poziomie, w tym w sposób dostosowany do indywidualnych potrzeb.

2. Korzystanie z witryny bez zmiany ustawień dotyczących Cookies oznacza, że będą one zapisywane na Twoim urządzeniu końcowym. Możesz w każdym czasie dokonać zmiany ustawień dotyczących Cookies w swojej przeglądarce internetowej.

3. Administrator używa technologii Cookies w celu identyfikacji odwiedzających witrynę, w celu prowadzenia statystyk na potrzeby marketingowe, a także w celu poprawnego realizowania innych, oferowanych przez serwis usług.

4. Pliki Cookies, a w tym Cookies sesyjne mogą również dostarczyć informacji na temat Twojego urządzenia końcowego, jak i wersji przeglądarki, której używasz. Zadania te są realizowane dla prawidłowego wyświetlania treści w ramach witryny Administratora.

3. Cookies to krótkie pliki tekstowe. Cookies w żadnym wypadku nie umożliwiają personalnej identyfikacji osoby odwiedzającej witrynę i nie są w nim zapisywane żadne informacje mogące taką identyfikację umożliwić.

Aby zobaczyć pełną listę wykorzystywanych przez nas ciasteczek i dowiedzieć się więcej o ich celach, odwiedź naszą Politykę Prywatności.