We are looking for Vulnerability Management Lead to be responsible for driving the end-to-end vulnerability management lifecycle at IT Management premises in Bahrain. This role will oversee Qualys scan coverage, risk-based prioritization, remediation governance, and technical reporting, while coordinating closely with offshore patch engineering teams. Acting as the central authority for vulnerability operations, the Lead will ensure timely identification, classification, and remediation of vulnerabilities, track closure and exceptions, validate patch deployments, and deliver executive-level reporting.
Key Responsibilities
-
Own the vulnerability management lifecycle across discovery, scan coverage, triage, prioritization, remediation tracking, validation and reporting.
-
Administer and operate Qualys reporting and dashboards based on IT MGMT.-provided tools and access.
-
Identify newly applicable patches and classify them by Emergency, Critical, High, Medium and Low risk categories.
-
Prioritize vulnerabilities based on criticality, CVSS, exploitability, asset criticality and business impact.
-
Coordinate remediation actions with patch engineers and IT MGMT. teams, including patching, configuration recommendations, cleanup/removal actions and compensating control follow-up where applicable.
-
Track vulnerability closure, ageing, exceptions, risk acceptance and remediation blockers through the agreed tracking solution.
-
Validate patch deployment on target servers and endpoints using available tools and evidence from operational checks.
-
Prepare weekly and monthly technical and management reports covering vulnerability posture, patch compliance and AV patch status.
-
Support audits, compliance activities, service reviews and continuous improvement initiatives.
-
Escalate items requiring SME advice, vendor support, application validation, local hands support or out-of-scope troubleshooting to the appropriate IT MGMT. owner.
Qualifications
-
Bachelor’s degree in computer science, Information Security, or related field.
-
7+ years of experience in vulnerability management, IT security, or infrastructure security roles.
-
Hands-on experience with Qualys VMDR or equivalent vulnerability management platforms.
-
Strong understanding of CVSS scoring, exploitability analysis, and risk-based prioritization.
-
Proven ability to manage remediation governance in regulated environments.
-
Excellent communication and reporting skills for both technical and executive audiences.
Key Skills
-
Qualys VMDR / Vulnerability Reporting
-
Vulnerability Management Lifecycle
-
CVSS and Risk-Based Prioritization
-
Windows and Linux Security
-
Patch Compliance Reporting
-
Threat and Exploitability Awareness
-
Risk Acceptance and Exception Tracking
-
Audit and Compliance Support