Vulnerability Management (VM) Specialist
Key Skills
Job Description
Vulnerability Management (VM) Specialist, Amsterdam HBP (36 hours) Are you the go-to person for identifying risks and turning challenges into actionable solutions? Do you have a strong passion for Vulnerability Management, combined with a keen understanding of IT Security? If so, we have an exciting opportunity for you! We’re currently hiring for a Business Control Specialist IV. In this role, you’ll serve as a trusted advisor to internal stakeholders, assisting them with the validation of security design, code, and configuration of assets. You’ll be responsible for managing Vulnerability Management issues as well as translating complex Vulnerability Management risks into clear, actionable guidance that enables our DevOps teams to identify and mitigate risks effectively. You’ll operate as a First Line of Defence (1LoD) risk specialist, working closely with DevOps professionals, CISO and our 2LoD. Together, we keep ING ahead of the curve in risk management. Join us and help shape the future of IT risk & Security management! Ready to make an impact and enjoy the journey? The team As a Vulnerability Management Specialist you’ll be part of the IAM & Resilience chapter, which is part of the Reliability, IT Risk & Security (RIRS) Tribe at CTO. The IAM & Resilience chapter consists of risk & security experts who are supporting the Finance & Risk entity on IAM and Resilience (IAM, IT Resilience, Vulnerability Management & SDR) related Security topics. The IAM & Resilience chapter team, in close collaboration with the Change and Testing chapter and the DevOps teams focuses on the day-to-day management and execution of IT risk and security tasks. Furthermore, the team steers the execution of the Risk Opinion and First Line Monitoring improvement activities that coincide with the execution of IT security controls. The members are typically experienced, they have diverse interdisciplinary technical, IT risk and/or IT security backgrounds. Roles And Responsibilities The ideal candidate has Expertise in the overseeing the end to end vulnerability management lifecycle. This role ensures that identified vulnerabilities are properly assessed, prioritized, remediated, and monitored in alignment with risk appetite, compliance requirements, and business objectives. We are looking for someone with hands on experience with Security tools (GSOC, ServiceNow, Checkmarx, Qualys, Nessus, Cloud Atlas, APF) who is able to support DevOps teams with Vulnerability Management issues by providing expert guidance and consultancy. Knowledge of IT Risk processes and the ability to identify, assess and document the impact of security defects is a must. Your Responsibilities Will Be To Perform validation/triage, risk scoring, remediation tracking, and verification. Use CVSS, threat intel (exploitation in the wild), asset criticality, exposure, and compensating controls to drive risk-based remediation. Orchestration Remediation: Taking sessions, coordinate owners, and ensure fix validation (patch, config, version upgrade, or mitigation). Continuous improvement: Reduce noise (false positives/duplicates), tune scans, improve coverage, and drive automation. Monitor the risk score of Finance & Risk and support the entity to be within Risk Appetite. Participate in the Risk Opinion process for Vulnerability Management, ensuring a correct and complete assessment of Vulnerability Management metrics and controls. Review Vulnerability Management risk metrics and manage the remediation of issues resulting from the metrics How To Succeed We hire smart people like you for your potential. Our biggest expectation is that you’ll stay curious. Keep learning. Take on responsibility. In return, we’ll back you to develop into an even more awesome version of yourself. The following skillset and experience are required to succeed in this role: Strong knowledge of the end to end Vulnerability Management process. Expertise in vulnerability identification, analysis and remediation. Knowledge of and experience with common scanning and management tools (e.g. Nessus, Qualys, Tenable, Rapid7) and CVSS classification. Experience with Vulnerability Management risk metrics and risk governance frameworks. Familiarity with Vulnerability Management processes in complex, regulated environments. Excellent stakeholder management and communication skills. Certifications such as CISSP, OSCP, GCIH or similar are an advantage, but not a strict requirement. Natural motivation and drive to take end-to-end ownership. Rewards And Benefits We want to make sure that it’s possible for you to strike the right balance between your career and your private life. Find out more about our employment conditions. The Benefits Of Working With Us At ING Include 25-28 vacation days depending on contract Pension scheme 13th month salary 8% Holiday payment Hybrid working Personal growth and challenging work with endless possibilities An informal working environment with innovative colleagues About Us Curious about how ING empowers people and businesses to move forward? Discover what we do and what we can offer you. Questions? Please visit our Frequently Asked Questions section to find some answers on questions you might have. Contact the recruiter attached to the advertisement. Want to apply directly? Please upload your CV and motivation letter by clicking the ‘Apply’ button.
Core Responsibilities
Oversee the end-to-end vulnerability management lifecycle, including triage, risk scoring, remediation coordination, verification, and continuous improvement of scanning and automation. Advise DevOps and other stakeholders, monitor Finance & Risk against risk appetite, and contribute to risk opinions, control assessments, and remediation of issues identified through risk metrics.
Requirements
Candidates should have strong end-to-end vulnerability management expertise, experience with vulnerability scanning and management tools, and knowledge of CVSS, risk metrics, and governance in complex regulated environments. Excellent stakeholder management and communication skills, ownership, and drive are expected; CISSP, OSCP, GCIH, or similar certifications are advantageous but not required.
Benefits
- 25–28 Vacation Days
- Pension Scheme
- 13th Month Salary
- 8% Holiday Payment
- Hybrid Working
- Personal Growth
- Challenging Work
- Informal Working Environment
About ING Nederland
Industry: Banking
Company size: 10,001+ employees
ING is a global bank with a strong European base. With 14,500 employees in the Netherlands, we’re one of the biggest employers in the country. Our research tells us that we stand out here because of our great working culture, competitive benefits and interesting work. We believe in sustainable progress for all, not just for the few. We aim to support and contribute to economic, social and environmental progress. Because progress doesn’t start with perfection. It starts with people, their ideas and their drive to make things better. Collaborative and inclusive We’re proud of our diverse and multinational make-up. Joining the ING team means contributing to a collaborative and inclusive culture, having a hybrid way of working and being part of the positive impact that we strive to make on people and the planet. We don’t believe in one ‘perfect’ way of doing things. The best solutions emerge when people work together, stay curious and learn from each other. You’ll get responsibility from day one, along with the trust and freedom to make your own choices and contribute your perspective. Purpose ING’s purpose is empowering people to stay a step ahead in life and in business. This purpose guides us in everything we do. Rather than telling our people what to do, we trust them and encourage them to carve out their career in a way that works best for them. We want to enable people to grow in their own way, without being held down. Because doing great things starts by doing your thing. So, are we offering the perfect job? Maybe not. But you might find something better: a place where you can be yourself, keep growing and make an impact through the work you do.