Skip to main content

Specialist Information Security Engineer – Vulnerability Management Analyst

Two lab technicians smiling
Buscar Empleos

SEE ALL JOBS

Specialist Information Security Engineer – Vulnerability Management Analyst

Portugal - Lisbon APLICAR AHORA
ID de la oferta R-227688 País: Portugal - Lisbon Estado: Flex Commuter / Hybrid Fecha de publicación Oct. 24, 2025 CATEGORÍA DE EMPLEO: Information Systems

Join our team at AMGEN Capability Center Portugal, the #1 company in Best Workplaces™ (201–500 employees' category) in Portugal in 2024 by the Great Place to Work Institute. With over 500 talented individuals from more than 40 nationalities, our Lisbon center thrives at the intersection of innovation, excellence, and inspiration. This is your opportunity to explore the future of healthcare through technology and digital innovation, supporting our mission To Serve Patients.

Specialist Information Security Engineer – Vulnerability Management Analyst


LIVE

What will you do:


This role is focused on identifying, assessing, prioritizing, and tracking the remediation of vulnerabilities across the organization’s technology stack. The Vulnerability Management Analyst plays a key role in the security operations team by ensuring known vulnerabilities are managed through their lifecycle using structured processes and tools. The individual will analyze vulnerability scan data, correlate threat intelligence (e.g., KEV, EPSS), and work closely with infrastructure, application, and business teams to drive risk-based remediation.


Additional responsibilities:

  • Lead the analysis and validation of vulnerability scan results from enterprise tools such as Tenable.sc, Qualys VMDR, or Rapid7 InsightVM, ensuring false positives are triaged and risk assessed accurately.

  • Develop and refine vulnerability prioritization frameworks that integrate CVSS v3.1, KEV, EPSS, asset criticality, exploit availability, and environmental factors to focus remediation on the most critical risks.

  • Partner closely with infrastructure, DevOps, and application security teams to drive timely remediation and provide expert-level technical guidance on compensating controls, configuration hardening, and patch deployment strategies.

  • Integrate threat intelligence feeds and SIEM data to correlate vulnerabilities with real-world exploit trends and potential attack vectors in the environment.

  • Build and maintain executive dashboards and risk metrics that measure vulnerability exposure, remediation SLAs, and program maturity for leadership and compliance reporting.

  • Oversee cloud vulnerability management activities across AWS, Azure, and GCP using tools such as Prisma Cloud, AWS Inspector, or Microsoft Defender for Cloud.

  • Contribute to and enhance vulnerability management policies, standards, and operating procedures aligned with frameworks such as NIST CSF, ISO 27001, and CIS Controls.

  • Support audit readiness and provide evidence for internal and external audits (e.g., SOX, PCI DSS, ISO 27001).

  • Mentor junior analysts in best practices for vulnerability analysis, prioritization, and remediation coordination.

Win

What we expect from you

  • Bachelor’s degree with 1–2 years of experience in Cybersecurity, Information Systems, or related technical discipline
    OR

  • Bachelor’s degree with 4–6 years of experience in Cybersecurity, Information Systems, or related technical discipline
    OR

  • Diploma with 7–9 years of experience in vulnerability management, security operations, or threat and risk management

  • Strong hands-on experience with enterprise-grade VM tools (Tenable.sc, Qualys VMDR, or Rapid7 InsightVM)

  • Proven experience developing or managing vulnerability management programs across hybrid infrastructure (on-prem and cloud)


Functional Skills:

Must-Have Skills:

  • Advanced understanding of the vulnerability lifecycle, remediation workflows, and risk-based prioritization.

  • Expertise with CVSS, KEV, EPSS, and asset criticality modeling.

  • Strong understanding of network, OS, application, and cloud security architectures.

  • Ability to correlate vulnerabilities with threat intelligence and adversary tactics (MITRE ATT&CK framework).

Good-to-Have Skills:

  • Experience integrating vulnerability data with SIEM, CMDB, or GRC platforms (e.g., Splunk, ServiceNow, Archer).

  • Exposure to vulnerability risk quantification or attack surface management platforms.


Professional Certifications required:

  • CompTIA Security+ or CySA+

  • GIAC GSEC / GCIH

  • Qualys Vulnerability Management Specialist (QVMS)

  • Tenable Certified Nessus Auditor (TCNA)

  • AWS Certified Security – Specialty or Azure Security Engineer Associate


Soft Skills:

  • Leadership & Mentoring: Capable of guiding junior analysts and fostering a culture of proactive security improvement.

  • Analytical Thinking – Ability to interpret complex data sets and assess risk effectively

  • Attention to Detail – Precision in identifying and tracking vulnerabilities and remediation status

  • Communication Skills – Ability to communicate technical findings to both technical and non-technical audiences

  • Collaboration & Teamwork – Able to work across IT, DevOps, and security teams to drive resolution

  • Cross-Functional Influence: Strong collaboration across security, IT, DevOps, and compliance teams.

  • Curiosity & Continuous Learning – Willingness to stay current with evolving threats and technologies

  • Problem-Solving Mindset – Capability to identify solutions to security weaknesses in diverse environments

Thrive

What you can expect of us

As we work to develop treatments that take care of others, we also care deeply for our teammates’ well-being and growth.

  • Work That Matters – Build tech that accelerates scientific breakthroughs and helps patients worldwide.

  • Modern Tech Stack – Cloud-first, automation-focused, AI-powered.

  • Global Scale, Agile Mindset – Collaborate across continents while working in nimble, high-impact teams.

  • Continuous Learning – Access to certifications, trainings, mentorship, and career mobility.

  • AMGEN Total Rewards Plan – Comprehensive benefits in healthcare, finance, and well-being.

  • Flexibility – Hybrid work model with time split between our Lisbon office and remote work.

APPLY NOW FOR A CAREER THAT DEFIES IMAGINATION

In our quest to serve patients above all else, Amgen is the first to imagine, and the last to doubt. Join us.

CAREERS.AMGEN.COM

EQUAL OPPORTUNITY STATEMENT

Amgen is an Equal Opportunity employer and will consider you without regard to your race, colour, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

We will ensure that individuals with disabilities are provided a reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.

APLICAR AHORA
VIVE. GANA. PROSPERA.

Regístrate para recibir alertas de empleo

Mantente al día con las noticias y oportunidades de Amgen. Regístrate para recibir alertas sobre puestos que se adapten a tus habilidades e intereses profesionales.

Me interesa:Indique las primeras letras de una categoría y luego elija una a partir de las sugerencias. Después entre las primeras letras de un enlace y elija la opción que prefiera. Por último, haga clic en “Añadir” para crear su propia alerta.

Al enviar tu información, reconoces que has leído nuestra política de privacidad (este contenido se abre en una nueva ventana) y consientes recibir comunicaciones por correo electrónico de.