← Back to list
Job

Security Controls Engineer - Vulnerability Management

Other • Hybrid • Full-time • Czechia CZE - Brno, Czechia

You will translate legal and security framework requirements into clear, actionable vulnerability management and remediation programs spanning multiple Security and DevOps teams, and help design and continually improve the vulnerability management lifecycle.

Responsibilities

  • ▹Translate legal and security framework requirements into clear, actionable vulnerability management and remediation programs
  • ▹Design, operationalize and continually improve the vulnerability management lifecycle: identification and triage, prioritization and remediation, validation and reporting
  • ▹Apply secure development practices within regulatory frameworks covering vulnerability handling, coordinated disclosure, SBOM transparency, patch management and post-deployment monitoring
  • ▹Track, report and escalate progress, risks and dependencies, partnering closely with a Senior Project Manager and reporting to senior leadership

Requirements

  • ▹Practical exposure or experience (typically 3-5 years) in vulnerability management, security engineering or security program delivery in a cloud/software environment
  • ▹Demonstrated ability to work independently and drive outcomes across multiple teams
  • ▹Working understanding of regulatory security requirements and demonstrated experience implementing common frameworks/regulations (e.g. ISO 27001, NIS2, SOC 2, GDPR, PCI DSS)
  • ▹Strong translation skills: turn policy and control language into developer-ready user stories, acceptance criteria, remediation tasks and runbooks
  • ▹Hands-on experience with work tracking tools (Jira, Azure DevOps, etc.) and crafting status reports and dashboards for leadership
  • ▹Strong communication skills: analyzing vulnerability trends including ageing, patch latency and systemic root causes, concise writing, clear meeting facilitation and stakeholder alignment
  • ▹Understanding of modern SDLC/DevOps practices (CI/CD, IaC, pipelines, change management)
  • ▹Experience in cloud environments (AWS/Azure/GCP), including shared responsibility and guardrail patterns

Nice to have

  • ▹Wry sense of humor

Soft skills

Independent and outcome-drivenClear communication and stakeholder alignment

What we offer

  • ▹Flexible working options and time off
  • ▹Competitive pay, benefits and well-being programs

About the company

Gen is a global company dedicated to powering Digital Freedom through consumer brands including Norton, Avast, LifeLock and MoneyLion. It delivers cybersecurity, online privacy, identity protection and financial wellness solutions to nearly 500 million users in more than 150 countries.

Similar jobs