Senior Security Vulnerability Analyst

2 tygodni temu


Warszawa, Mazovia, Polska Sportradar Pełny etat

We're the world's leading sports technology company, at the intersection between sports, media, and betting. More than 1,700 sports federations, media outlets, betting operators, and consumer platforms across 120 countries rely on our know-how and technology to boost their business.

Job Description

Job Description:

All software and systems contain defects or vulnerabilities in them. This role is concerned with the management of vulnerabilities that are known about, so to ensure an effective remediation strategy is in place to avoid them being exploited by threat actors.
The Senior Security Vulnerability Analyst role in Sportradar's Attack Surface Management team is to be responsible for identifying, assessing the risk they pose and prioritising vulnerabilities for remediation in conjunction with the system owners, employing a risk-based approach. Thereafter actively reporting on their status and managing them to resolution thus reducing the overall risk to the business.

As a Security Subject Matter Expert (SME), Senior Security Vulnerability Analysts are required
to be technically equipped to understand the different types of vulnerabilities, assessing and
prioritise them based upon their exploitabilitiy, severity and other relevant factors including
exposure and business criticality.

They will also be good communicators and work collaboratively with the system owners and
other members of the Security group so that the risk posture can be easily understood with
vulnerabilities being remediated effectively and in a timely manner.

The Senior Security Vulnerability Analyst is a key member of the Attack Surface Management
Team and reports into the Senior Manager of the Product Security unit which is part of the wider Sportradar Security group).

He / She will be a team-player and always seek to learn, improve processes as well as helping collegues in the wider team.

Accountabilities and Activities:

  • Monitoring a variety of tools and systems for the identification of vulnerabilities of various types.
  • Triage findings for true and false positives based on a variety of factors.
  • Assess the risk of the vulnerability in the context of the system architecture, its data, business criticality, and the availability of exploits for that vulnerability.
  • Communicating the results of the analysis effectively to key stakeholders in order to create a realistic remediation plan.
  • Creating metrics and KPI reports to ensure that findings are being addressed in a timely mannerand overall risk to the business is reduced.
  • Becoming a Subject Matter Expert on the various tooling to ensure that it is returning optimal results.
  • Assisting investigations into security incidents, and acting as subject matter expert for the vulnerability management domain.
  • Identifying opportunities to improve effective vulnerability management across Sportradar.
  • Contribute to the development and implementation of security policies related to vulnerability management, ensuring application security principles are applied during design and into business as usual processes to reduce risk, drive adoption and adherence to policies, standardsand guidelines by the wider business.
  • Maintaining and developing documentation for internal processes, security procedures, and remediation guidelines, and ensuring adherence to them.
  • Clearly articulating security issues to Sportradar internal teams, both verbally and in written format as well as presenting information to management stakeholders to both technical and non-technical audiences.
  • Troubleshooting and helping to resolve security issues for Sportradar teams.
  • Acting as subject matter expert and primary point of contact for security questions from Sportradar internal teams.
  • Maintaining relationships with strategic third-party Information Security suppliers, partners and industry forums.
  • Generating bespoke reporting from the Sportradar monitoring solution in line with business requirements, ongoing investigations, or senior stakeholder requests.
  • Provide advice and guidance on procedural and technical security controls.
  • Provide advice and guidance to other teams within the business on good practice and maintain relevant and current industry knowledge.
  • Work with the technical and solution architects to provide domain/specialist security expertise to IT projects in line with security strategy; contributing to and reviewing project documentation as necessary.

Required Experience:

  • 5+ years experience working in an enterprise security environment, preferably in a technical security role.
  • Knowledge of common operating system & cloud computing platforms, software development frameworks, network protocols, and security architecture.
  • Knowledge of industry standard vulnerability management tools usage and implementation.
  • Knowledge of current vulnerabilities and attacks.
  • Excellent oral and written communication skills for both technical and non-technical audiences.

Desired Experience:

  • Experience working in as a penetration tester or bug-bounty hunter.
  • Experience in one or more high-level programming or scripting language.
  • Hands-on experience with a variety of scanning tools at different stages of the SDLC.
  • A track record of technical delivery working within a fast paced and pressured environment.

Qualifications, Education and Certifications:

  • Bachelor's or Master's Degree in Computer Science, Information Technology, Information Security or similar, or equivalent industry experience.
  • Industry certifications (or currently working towards them) such as:
  • Security certs e.g. CISSP, CISM, CEH, OSCP, SANS etc
  • Other relevant certifications.
Additional Information

Sportradaris an Equal Opportunity Employer. We are committed to encourage diversity within our teams. All qualified applicants will receive consideration without regard to among other things, your background,status,or personal preferences

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr

  • Warszawa, Mazovia, Polska Sportradar Pełny etat

    Job DescriptionJob Description: All software and systems contain defects or vulnerabilities in them. This role is concerned with the management of vulnerabilities that are known about, so to ensure an effective remediation strategy is in place to avoid them being exploited by threat actors.The Senior Security Vulnerability Analyst role in Sportradar's Attack...


  • Warszawa, Mazovia, Polska Google Pełny etat

    Senior Security Engineer, Vulnerability Detection Google Google's mission is to organize the world's information and make it universally accessible and useful. View company page Bachelor's degree in a technical field or equivalent practical experience.Experience in Vulnerability Detection.Experience in device, OS, or embedded system security.Experience in...


  • Warszawa, Mazovia, Polska Google Inc. Pełny etat

    Senior Security Engineer, Vulnerability Detection corporate_fare Google place Warsaw, Poland Apply Bachelor's degree in a technical field or equivalent practical experience.Experience in Vulnerability Detection.Experience in device, OS, or embedded system security.Experience in C/C++ source code security analysis.Preferred qualifications:Experience with...


  • Warszawa, Mazovia, Polska Cyber Crime Pełny etat

    Aion Bank is a fully regulated European bank and credit institution that combines Vodeno's proprietary, private blockchain-based platform with its ECB banking license, balance sheet and regulatory and compliance expertise to offer a comprehensive suite of embedded banking products.Aion has a track record of delivering fully compliant embedded banking...


  • Warszawa, Mazovia, Polska IQVIA Argentina Pełny etat

    Location: Portugal, Poland, BrazilWork model: Hybrid (1-2 days per week in the office)This is one of a key cybersecurity role within the global Information Security organization.The individual fulfilling this Information Security Manager role in Vulnerability Management team will partner closely with IT professionals both within the core Global Information...


  • Warszawa, Mazovia, Polska Google Pełny etat

    Security Engineer, Vulnerability Detection Google Google's mission is to organize the world's information and make it universally accessible and useful. View company page Bachelor's degree in a technical field (e.g., Cyber Security, Computer Science) or equivalent practical experienceExperience in C/C++ source code security analysisExperience coding in one...


  • Warszawa, Mazovia, Polska Google Inc. Pełny etat

    Security Engineer, Vulnerability Detection corporate_fare Google place Warsaw, Poland Apply Bachelor's degree in a technical field (e.g., Cyber Security, Computer Science) or equivalent practical experienceExperience in C/C++ source code security analysisExperience coding in one or more coding languages (e.g., Java, Python, Go)Experience working in device,...


  • Warszawa, Mazovia, Polska ERGO Technology & Services S.A. Pełny etat

    Senior Vulnerability Management SpecialistYour responsibilitiesfacilitating and coordinating vulnerability assessment and scanninganalyzing assessment results and threat feeds to properly react to security weaknesses or vulnerabilitiescollaborating, coordinating, monitoring, and supporting activities in the areas of the VM programmaintaining control of...


  • Warszawa, Mazovia, Polska Nord Security Pełny etat

    Mid - Senior Security Engineer (Poland remote) The Infrastructure department is responsible for influencing and tracking change, providing frontline support, and delivering software-defined solutions. Main ResponsibilitiesSecure backend applications, networking components, and crypto services. White, grey box or black box – you name itShow your reverse...


  • Warszawa, Mazovia, Polska Appfire Pełny etat

    Senior Security Engineer @ Appfire Warsaw, Masovian Voivodeship Senior Security Engineer @ Appfire Warszawa Warsaw, Masovian Voivodeship, Polska Job DescriptionAppfire is seeking a highly skilled Senior Security Engineer to join our Appfire Information Security team. This Senior Security Engineer role will report to our CISO and work within our Security...

  • Senior Security Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska Aviva Pełny etat

    Aviva Our global corporate website for investors, shareholders, career hunters, the media and people interested in our social purpose. View company page Hi, we're glad you're here We are hiring to our Aviva Services Excellence Centre Take a look at our job description - maybe it suits you or one of your friends?Aviva is seeking a Senior Security Analyst...


  • Warszawa, Mazovia, Polska SimCorp Pełny etat

    Senior Security Compliance Analyst page is loaded Senior Security Compliance Analyst Apply locations Warsaw Manila time type Full time posted on Posted Yesterday job requisition id R Who we areFor over 50 years, we have worked closely with investment and asset managers to become the world's leading provider of integrated investment management solutions. We...

  • Security Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska Nordsterne Pełny etat

    We are looking for an experienced individual to join our Information Security Team as a Security Analyst. Functional responsibilities: assistance to sales teams with the preparation of tender documentation; communication with customers, auditors, and independent experts on the security of the company's products and services; support of projects and audits...


  • Warszawa, Mazovia, Polska SimCorp Pełny etat

    Senior Information Security Specialist page is loaded Senior Information Security Specialist Apply locations Warsaw time type Full time posted on Posted 7 Days Ago job requisition id R Who we areFor over 50 years, we have worked closely with investment and asset managers to become the world's leading provider of integrated investment management solutions....


  • Warszawa, Mazovia, Polska Experis ManpowerGroup Sp. z o.o. Pełny etat

    The Software Vulnerability ML Engineer is responsible for improving analysis of possible software defects and vulnerabilities through the application of machine learning to complex applications using available security – relevant data.They should possess a solid background in ML and be experienced in data visualization for conveying analytic results to...


  • Warszawa, Mazovia, Polska Nord Security Pełny etat

    Application Security Engineer (Poland remote) The Risk Department serves as a vital component within an organization, upholding the crucial task of safeguarding the company's digital landscape. This team functions as the company's first line of defense against cyber threats, ensuring business continuity and preserving the organization's reputation. Main...

  • IT Security Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska Cyclad Pełny etat

    In Cyclad we work with top international IT companies in order to boost their potential in delivering outstanding, cutting edge technologies that shape the world of the future. For our customer, leader on the industrial real estate market, we are looking for IT Security Analyst. Person on this position will report directly to the Security Manager. As a key...

  • Security Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska Aviva Pełny etat

    Aviva Our global corporate website for investors, shareholders, career hunters, the media and people interested in our social purpose. View company page Hi, we're glad you're here We are hiring to our Aviva Services Excellence Centre Take a look at our job description - maybe it suits you or one of your friends?Aviva is seeking a Security Analyst who will...


  • Warszawa, Mazovia, Polska Intrum Justitia Pełny etat

    Global Senior Cloud Security Engineer page is loaded Global Senior Cloud Security Engineer Solicitar locations Warsaw posted on Publicado hace 2 días job requisition id R5785 En Intrum, crecerás haciendo la diferencia. Lo harás en un entorno altamente internacional. Y en una cultura de apoyo donde el esfuerzo cuenta.Are you our new Global Senior Cloud...

  • Cybersecurity Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska Plazotechnologies Pełny etat

    Plazo Technologies is a successful IT company specializing in credit scoring, Data Science and financial digital technologies. And we invite Cybersecurity analyst to become part of our companyPRIMARY RESPONSIBILITIESMonitor and analyze the event correlation and incident data to identify trends, false positives, and provide enhancements where necessary to...