ING
Vulnerability Management Engineer
The expected salary for this position: 7 100 pln – 15 000 pln
The financial ranges specified in the announcement are adjusted and may differ from the range specified in the remuneration regulations.
We are looking for you, if you:
- have at least 3 years of proven experience in vulnerability management, security testing, or cybersecurity operations
- have strong understanding of risk management principles, vulnerability prioritization, and remediation governance
- present ability to combine business context, asset criticality, severity, and remediation timelines into risk-based decision making
- have advanced analytical and data interpretation skills
- have strong Power BI knowledge, including Power Query, data modeling, DAX, KPI development, and dashboard design
- have excellent stakeholder management, communication, and coordination skills
- you have continuous improvement mindset with the ability to identify strategic opportunities to reduce organizational security risk
You'll get extra points for:
- have knowledge about vulnerabilities (i.e. OWASP top 10)
- ability to solve complex problems and their correlation, draw conclusions and propose corrective actions/improvements
- IT security related certification (like: CompTIA CySA+, CompTia Security+, CEH, CHFI, CISSP)
- IT related certification (like: RHCSA, MCSA, CCNA)
Your responsibilities:
- manage complex follow-up cases related to vulnerability scanning, penetration testing, secret scanning, Red Team exercises, and security baseline validation findings
- identify and challenge ownership of findings and coordinate remediation activities across multiple stakeholders
- drive overdue findings towards remediation, mitigation, or formal risk registration
- perform root cause analysis and identify systemic issues that contribute to recurring findings
- design and maintain management reporting, KPIs, and Power BI dashboards
- recommend and implement process improvements to reduce recurring vulnerabilities and improve remediation outcomes
- prepare executive-level reports and present security risk insights to stakeholders
Information about the squad:
As the Vulnerability Management Response Team, we ensure that identified vulnerabilities are effectively managed and remediated before they can be exploited by malicious actors. Our ambition is to eliminate security weaknesses and reduce the organization's exposure to cyber threats. We support ING from a global perspective, working closely with stakeholders across the organization to drive timely and effective remediation.
At ING Hubs Poland, we embrace Agile ways of working and use frameworks such as Scrum and Kanban to deliver value efficiently and continuously improve our processes.
We are an innovative team built on trust, collaboration, and empowerment. The high level of autonomy given to our employees fosters motivation, accountability, and creativity, enabling us to adapt quickly to evolving business needs and deliver meaningful impact for our stakeholders.
The role naming convention in the global ING job architecture will be “Engineer II”.