Vulnerability Management Expert – Patch Orchestration Team

Euroclear · Poland

Salary not stated · Compare UK pay by role →

Full-timeMid-levelSept 2026 · checked today

As a global critical financial infrastructure, the protection of Euroclear information and assets is fundamental to the company’s business. Security is at the core of our services, firmly embedded in the management systems and processes of the company.

You will be joining our Group Technology Services (GTS) division as member of the Patch Orchestration Team, where you will play a crucial role in safeguarding our organization's digital assets by reporting and coordinating the remediation activities for identified Vulnerabilities and Weaknesses across all major IT technologies. This proactive approach to security ensures that we stay ahead of potential threats of cyber-attacks and continuously improve our defences.

We are looking for a highly motivated Vulnerability Management Expert to facilitate Vulnerability remediation activities to a wide audience of IT stakeholders. You will be the bridge between the CISO offensive security teams responsible for Vulnerability scanning of the company wide IT platforms, and the IT platform owners responsible for fixing the detected Vulnerabilities.

Responsibilities

Vulnerability Scanning & Data Collection

Support stakeholders to use tools like Rapid7 InsightVM

Monitor weekly reports to ensure successful execution and data integrity

Validate and verify scan findings to reduce exceptions, remove duplicate findings, and improve data quality.

Reporting & Dashboard Updates

Generate and update vulnerability reports for relevant teams.

Maintain and enhance dashboards in Excel and Power BI to reflect current security exposure.

Update remediation KPIs, trends, and compliance scores.

Monitor remediation SLAs and drive adherence across teams.

Track key indicators such as overdue vulnerabilities, mean time to remediate, reopened findings, exception volumes, and recurring vulnerabilities.

Identify systemic causes of delayed remediation and propose process improvements.

Provide actionable insights to reduce vulnerability backlog and improve patch compliance.

Remediation Coordination

Review open vulnerabilities and track remediation progress with the relevant asset or application owners.

Send daily or weekly follow-up emails/reminders to responsible parties.

Help stakeholders understand processes, vulnerability severity, business impact, and recommended remediation actions.

Ensure vulnerabilities are routed to the correct asset owners and tracked through agreed workflows.

Monitor ageing, SLA breaches, exceptions, and blockers, and drive timely resolution.

Prioritise remediation based on severity, exploitability, asset criticality, exposure, and business impact.

Distinguish between false positives, accepted risks, compensating controls, and genuine remediation needs.

Advisory & Support

Respond to queries from IT teams and business units regarding vulnerabilities and remediation orchestration.

Support IT teams and business units with vulnerability trend analysis and related insights.

Support patching cycles by correlating vulnerabilities to available patches or configuration fixes.

Documentation & Process Management

Document the remediation orchestration and related processes.

Track vulnerabilities through their lifecycle stages: identified, validated, assigned, remediated, exceptioned, risk accepted, and closed.

Ensure evidence of remediation or exception approval is captured and maintained.

Maintain clear audit trails for vulnerability decisions and remediation status.

Create team- and tribe-level dashboards for personalised reporting and security posture management.

Translate vulnerability findings into actionable tickets, tasks, or remediation campaigns.

Stakeholder Engagement

Participate in daily, weekly, and monthly security orchestration and governance calls with multiple business units, senior management, and stakeholders.

Liaise with infrastructure, development, and risk teams to ensure alignment on remediation priorities.

Escalate unresolved or critical issues to relevant senior management stakeholders, including CISO and GTS, periodically and as needed.

Support governance routines, including weekly review boards, escalation forums, and monthly risk reporting.

Coordinate exception, deferral, and risk acceptance requests.

Ensure exceptions are time-bound, justified, approved, and periodically reviewed.

Track compensating controls and residual risk where immediate remediation is not possible.

Escalate expired or repeatedly extended exceptions.

Executive Reporting & Communication

Draft bullet points or slides for management reports and board updates (as needed).

Prepare quarterly metrics and summaries on the organisation’s security posture.

Produce and share executive dashboards to highlight risk reduction progress and key wins.

Requirements

Technical Skills:

Vulnerability scanner knowledge: experience with tools such as Rapid7, Tenable, Qualys, or similar platforms.

Data analysis and reporting: strong proficiency in Excel, including pivot tables, formulas, and macros, and Power BI.

Security knowledge: solid understanding of vulnerability types, CVSS, threat exposure, and patch management.

Process & Communication Skills:

Proven ability to track, escalate, and follow up on remediation tasks with multiple teams.

Skilled in explaining technical security issues to non-technical stakeholders.

Familiarity with risk-based prioritisation and remediation strategies.

Stakeholder Management:

Strong interpersonal skills to manage and maintain productive relationships with cross-functional stakeholders.

Ability to coordinate stakeholders and drive outcomes autonomously.

Experience with ITSM tools, such as ServiceNow, Jira, or Azure DevOps, for remediation workflows and ticketing.

Good to Have:

Experience with automated orchestration platforms, such as SOAR solutions.

Certifications such as CompTIA Security+, ISC2 CC, or CEH are a plus.

Exposure to governance and compliance frameworks (e.g., ISO 27001, NIST, PCI-DSS).

Experience in writing and presenting reports for senior leadership.

Soft Skills:

Excellent verbal and written communication skills.

Strong collaboration skills with both technical and non-technical stakeholders.

Ability to work in a fast-paced environment with multiple priorities and deadlines.

Strong operational discipline and the ability to manage large volumes of findings.

Comfortable working with ambiguity and driving clarity across teams.

Persistent, structured, and outcome-oriented in follow-up and escalation.

Ability to convert complex technical data into clear operational actions.

Please note that this is a permanent position, and we do not offer freelance/contract arrangement for the role.

#LI-AK1

Read the whole thing? Let's get you ready for it.

Morganson writes a cover letter against this exact ad, tailors your CV to it, and tells you the day roles like it open — three free credits when you join.