About this role
As part of the Cyber Security Operations Center (SOC), the Vulnerability Manager is responsible for overseeing and continuously improving the organization’s vulnerability management process.
The role ensures transparency on the company’s vulnerability landscape, drives risk-based prioritization, and coordinates remediation activities across IT and business stakeholders.
Monitor and analyze the development of open vulnerabilities across all vulnerability management systemsTrack trends, risk exposure, and remediation progressPerform initial assessment and prioritization of vulnerabilities based on severity and business contextEnsure vulnerability scans are executed according to defined policies and schedulesOperate and monitor vulnerability scanning tools and ensure sufficient scan coverage across the organizationIdentify scan gaps and enforce compliance with vulnerability scanning requirementsApply a risk-based approach to prioritize vulnerabilities based on severity, asset criticality, and exposure Communicate critical vulnerabilities (e.g., zero-days, high/critical risks) in a timely and structured mannerProvide clear reporting on vulnerability status, trends, and risk exposure to stakeholdersInitiate and coordinate remediation campaigns using a risk-based prioritization approachTrack remediation progress and escalate delays or risk deviationsSupport asset and service owners in understanding vulnerabilities and required remediation actions Act as the interface between SOC, IT Operations, Technical Security, and business stakeholdersContinuously improve vulnerability management processes, tooling, and reportingContribute to the definition and optimization of policies, standards, and KPIs. Strong understanding of vulnerability management processes and frameworksExperience with vulnerability scanning tools (e.g., Qualys, Tenable, Rapid7 or comparable solutions)Knowledge of vulnerability scoring systems (e.g., CVSS) and risk-based prioritization approachesGood understanding of IT infrastructure, including networks, endpoints, and cloud environmentsStrong analytical skills for risk assessment and prioritizationExperience with reporting, KPIs, and data-driven decision makingAbility to translate technical vulnerabilities into business riskStrong communication skills and ability to work with cross-functional teamsProactive and structured working style with a focus on ownership and accountabilityExperience in a SOC or cyber security operations environment is beneficialFamiliarity with regulatory and security frameworks (e.g., ISO 27001, NIS2, TISAX) is an advantageCertifications such as CISSP, CISM, GIAC Enterprise Vulnerability Assessor (GEVA) or similar are a plus. What we offer:
Pay for Performance:
Achievement Bonuses and Rewards;Recommendation Bonuses for new team members;Flexibility Program including flexible hours, mobile work and sabbaticals.Wellbeing:
Health & Wellness (Private Health Insurance, Life Insurance, Sport activities etc.);Different discounts (glasses, tires, medical, shopping);In-house restaurant & coffee corners.Life-Long Learning:
Dedicated Programs and Conferences;Free Language Courses (English, German, French etc);Access to e-learning platforms;Career development opportunities (local and international);Internal development communities (Experts, Agile Community of Practice, Artificial Intelligence etc). Ready to take your career to the next level? The future of mobility isn’t just anyone’s job. Make it yours! Join AUMOVIO. Own What’s Next.