Level

ING

Vulnerability Management (VM) Specialist

ING is hiring a Vulnerability Management (VM) Specialist. Level rates it ; you can apply on Level.

AI in this role

Manage the vulnerability management lifecycle and advise DevOps teams on security design and risk mitigation.

servicenowcheckmarxqualysnessuscloud-atlas
vulnerability-managementit-securityrisk-managementdevops

Vulnerability Management (VM) Specialist, Amsterdam HBP (36 hours)

Are you the go-to person for identifying risks and turning challenges into actionable solutions? Do you have a strong passion for Vulnerability Management, combined with a keen understanding of IT Security? If so, we have an exciting opportunity for you!

We’re currently hiring for a Business Control Specialist IV. In this role, you’ll serve as a trusted advisor to internal stakeholders, assisting them with the validation of security design, code, and configuration of assets. You’ll be responsible for managing Vulnerability Management issues as well as translating complex Vulnerability Management risks into clear, actionable guidance that enables our DevOps teams to identify and mitigate risks effectively.

You’ll operate as a First Line of Defence (1LoD) risk specialist, working closely with DevOps professionals, CISO and our 2LoD. Together, we keep ING ahead of the curve in risk management. Join us and help shape the future of IT risk & Security management!

Ready to make an impact and enjoy the journey?

The team
As a Vulnerability Management Specialist you’ll be part of the IAM & Resilience chapter, which is part of the Reliability, IT Risk & Security (RIRS) Tribe at CTO.

The IAM & Resilience chapter consists of risk & security experts who are supporting the Finance & Risk entity on IAM and Resilience (IAM, IT Resilience, Vulnerability Management & SDR) related Security topics. The IAM & Resilience chapter team, in close collaboration with the Change and Testing chapter and the DevOps teams focuses on the day-to-day management and execution of IT risk and security tasks.

Furthermore, the team steers the execution of the Risk Opinion and First Line Monitoring improvement activities that coincide with the execution of IT security controls. The members are typically experienced, they have diverse interdisciplinary technical, IT risk and/or IT security backgrounds.

Roles and responsibilities
The ideal candidate has Expertise in the overseeing the end to end vulnerability management lifecycle. This role ensures that identified vulnerabilities are properly assessed, prioritized, remediated, and monitored in alignment with risk appetite, compliance requirements, and business objectives.

We are looking for someone with hands on experience with Security tools (GSOC, ServiceNow, Checkmarx, Qualys, Nessus, Cloud Atlas, APF) who is able to support DevOps teams with Vulnerability Management issues by providing expert guidance and consultancy. Knowledge of IT Risk processes and the ability to identify, assess and document the impact of security defects is a must.

Your responsibilities will be to:

  • Perform validation/triage, risk scoring, remediation tracking, and verification.

  • Use CVSS, threat intel (exploitation in the wild), asset criticality, exposure, and compensating controls to drive risk-based remediation.

  • Orchestration Remediation: Taking sessions, coordinate owners, and ensure fix validation (patch, config, version upgrade, or mitigation).

  • Continuous improvement: Reduce noise (false positives/duplicates), tune scans, improve coverage, and drive automation.

  • Monitor the risk score of Finance & Risk and support the entity to be within Risk Appetite.

  • Participate in the Risk Opinion process for Vulnerability Management, ensuring a correct and complete assessment of Vulnerability Management metrics and controls.

  • Review Vulnerability Management risk metrics and manage the remediation of issues resulting from the metrics

How to succeed
We hire smart people like you for your potential. Our biggest expectation is that you’ll stay curious. Keep learning. Take on responsibility. In return, we’ll back you to develop into an even more awesome version of yourself.

The following skillset and experience are required to succeed in this role:

  • Strong knowledge of the end to end Vulnerability Management process.

  • Expertise in vulnerability identification, analysis and remediation.

  • Knowledge of and experience with common scanning and management tools (e.g. Nessus, Qualys, Tenable, Rapid7) and CVSS classification.

  • Experience with Vulnerability Management risk metrics and risk governance frameworks.

  • Familiarity with Vulnerability Management processes in complex, regulated environments.

  • Excellent stakeholder management and communication skills.

  • Certifications such as CISSP, OSCP, GCIH or similar are an advantage, but not a strict requirement.

  • Natural motivation and drive to take end-to-end ownership.

Rewards and benefits
We want to make sure that it’s possible for you to strike the right balance between your career and your private life. Find out more about our employment conditions.


The benefits of working with us at ING include:

  • 25-28 vacation days depending on contract

  • Pension scheme

  • 13th month salary

  • 8% Holiday payment

  • Hybrid working

  • Personal growth and challenging work with endless possibilities

  • An informal working environment with innovative colleagues


About us
Curious about how ING empowers people and businesses to move forward?

Discover what we do and what we can offer you.

Questions?
Please visit our Frequently Asked Questions section to find some answers on questions you might have.

Contact the recruiter attached to the advertisement. Want to apply directly? Please upload your CV and motivation letter by clicking the ‘Apply’ button.

How we rate this

Vulnerability Management (VM) Specialist at ING rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Vulnerability ManagementIt SecurityRisk ManagementDevopsServicenowCheckmarxQualysNessus

Questions you could be asked

  1. Tell me about a project where vulnerability management was part of your work. What did you do?
  2. Tell me about a project where it security was part of your work. What did you do?
  3. Tell me about a project where risk management was part of your work. What did you do?
  4. Tell me about a project where devops was part of your work. What did you do?
  5. Walk me through how you've used Servicenow in your day-to-day work.

Adapt your resume

  • List these exact terms on your resume: Vulnerability Management, It Security, Risk Management, Devops, and Servicenow. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get new AI jobs by email

One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Other roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at ING

Related searches

Same AI level