Role Purpose
Owns and leads the unified vulnerability and patch management service across all organizational assets. Responsible for end-to-end delivery, governance, reporting, and KPI compliance in line with defined risk-management and regulatory frameworks.
Key Responsibilities
- Lead vulnerability lifecycle management using Qualys VMDR integrated with ServiceNow.
*
- Oversee asset discovery, scanning, prioritization, and remediation across servers, endpoints, and applications.
*
- Define and enforce patching strategy, ensuring CVSS-based remediation within SLA thresholds (7 / 14 / 30-day windows).
*
- Supervise manual patching of production systems, validate rollback plans, and coordinate maintenance windows.
*
- Generate weekly and monthly KPI dashboards, tracking open vulnerabilities, SLA compliance, and risk scores.
*
- Align with compliance standards — ISO 27001, NIST 800-40, CIS v8, PCI DSS — and prepare audit-ready evidence.
*
- Mentor and train the junior team on vulnerability analysis, patch deployment, and incident response.
*
- Coordinate escalations, change control, and documentation with Information Security and IT Governance teams.
*
- Contribute to continuous-improvement initiatives and regulatory reporting.
Qualifications & Skills
- Bachelor’s degree in Cybersecurity, Computer Science, or related field.
*
- 5+ years’ experience in vulnerability management and patch operations.
*
- Proven expertise with Qualys, ServiceNow, and enterprise patch-management tools (SCCM, Ansible, WSUS).
*
- Strong knowledge of CVSS scoring, threat intelligence correlation, and risk prioritization.
*
- Familiarity with ITIL change / incident processes.
*
- Certifications preferred: CISSP, CISM, CRISC, CompTIA Security+, or Qualys VMDR Specialist.
*
- Strong leadership, documentation, and stakeholder-communication skills.
Job Types: Full-time, Contract
Contract length: 12 months
Pay: BD1,200.000 - BD2,000.000 per month