Manager-IT & Information Security
IN
We are looking for a highly experienced Senior Vulnerability Management Consultant (9+ years) to lead and mature our vulnerability management program. This role requires a deep understanding of cybersecurity risks, vulnerability assessment methodologies, and enterprise-scale risk prioritization. You will work cross-functionally with IT, cloud, application, and third-party teams to drive measurable improvements in our security posture
Key Responsibilities:
- Lead the enterprise-wide vulnerability management function, including strategy, tooling, and execution.
- Perform advanced vulnerability assessments across infrastructure, cloud, endpoints, and applications.
- Correlate vulnerability data with asset criticality, threat intelligence, and exploitability to drive risk-based prioritization.
- Work with stakeholders to define remediation SLAs and ensure timely issue resolution.
- Oversee the integration of scanning tools (e.g., Tenable, Qualys, Rapid7) into CI/CD pipelines, cloud platforms, and enterprise systems.
- Regularly produce executive-level dashboards and technical reports with trends, KPIs, and risk heatmaps.
- Advise on security architecture and control enhancements to prevent recurring vulnerabilities.
- Partner with GRC teams to ensure compliance with standards (ISO 27001, NIST, PCI-DSS, etc.).
- Evaluate and implement emerging technologies and AI-driven solutions to optimize the program.
- Mentor junior consultants and lead cross-team security improvement initiatives.
Required Skills & Experience:
- 9+ years of experience in cybersecurity, with at least 5+ years focused on vulnerability management.
- In-depth knowledge of CVSS scoring, threat intelligence integration, and vulnerability lifecycle management.
- Expertise with tools like Qualys, Tenable, Nessus, Nexpose, Burp Suite, or similar.
- Strong experience with cloud platforms (AWS, Azure, GCP) and container security (Docker, Kubernetes).
- Proficient in scripting (Python, PowerShell, or Bash) for automation of scanning and reporting tasks.
- Familiarity with enterprise IT environments: servers, endpoints, networks, firewalls, web apps.
- Solid understanding of patch management, asset inventory, secure configuration, and remediation governance.
- Effective communication and stakeholder management skills, from technical teams to executive leadership.
- Hands-on experience with security frameworks (e.g., NIST CSF, MITRE ATT&CK, OWASP).
- Experience managing third-party assessments and coordinating with external vendors.
Soft Skill:
• Good experience working with numerous external teams to track and deliver solutions.
• Strong detail-oriented individual able to efficiently analyze and resolve problems.
• Strong verbal, communication, and diplomacy skills with all levels of the business.
• Must be self-motivated, able to work independently, and multi-task effectively.
Preferred Certifications:
- CISSP, OSCP, CISM, GIAC (GCIH, GSEC), CEH, or equivalent.
Your benefits
· We offer a hybrid work model which recognizes the value of striking a balance between in-person collaboration and remote working incl. up to 25 days per year working from abroa
· We believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location
· From career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostere
· Flexible working, health and wellbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teachAbout Allianz Technology
Allianz Technology is the global IT service provider for Allianz and delivers IT solutions that drive the digitalization of the Group. With more than 13,000 employees located in 22 countries around the globe, Allianz Technology works together with other Allianz entities in pioneering the digitalization of the financial services industry.We oversee the full digitalization spectrum – from one of the industry’s largest IT infrastructure projects that includes data centers, networking and security, to application platforms that span from workplace services to digital interaction. In short, we deliver full-scale, end-to-end IT solutions for Allianz in the digital age
D&I statement
Allianz Technology is proud to be an equal opportunity employer encouraging diversity in the working environment. We are interested in your strengths and experience. We welcome all applications from all people regardless of gender identity and/or expression, sexual orientation, race or ethnicity, age, nationality, religion, disability, or philosophy of life
Join us. Let´s care for tomorrow
You. IT