Vulnerability Management Engineer (Romania)
Romania
Full Time
1 hour ago
Senior LevelWorldwide
$40K - $80K

USD per year

Job Description

About Us

Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure-play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. In addition to MDR and other services, Sophos’ complete portfolio includes industry-leading endpoint, network, email, and cloud security that interoperate and adapt to defend through the Sophos Central platform. Secureworks provides the innovative, market-leading Taegis XDR/MDR, identity threat detection and response (ITDR), next-gen SIEM capabilities, managed risk, and a comprehensive set of advisory services. Sophos sells all these solutions through reseller partners, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) worldwide, defending more than 600,000 organizations worldwide from phishing, ransomware, data theft, other every day and state-sponsored cybercrimes. The solutions are powered by historical and real-time threat intelligence from Sophos X-Ops and the newly added Counter Threat Unit (CTU). Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.

Role Summary

The Senior Threat Analyst plays a critical role in supporting and enhancing the organisation’s vulnerability management and threat detection capabilities. This role is responsible for monitoring and responding to security support requests, collaborating closely with cross-functional teams, and providing expert guidance to customers on strengthening their vulnerability management strategies. As a trusted technical advisor, the Senior Threat Analyst translates complex security and technical risks into actionable insights for both internal stakeholders and customers, driving improvements in security posture and operational efficiency. The role also contributes to root cause analyses, develops technical recommendations, and ensures high-quality documentation and knowledge sharing.

What You Will Do

  • Responsible for understanding, reviewing, and interpreting assessment and scanning results, reducing false positive findings and acting as a trusted security advisor to the customer
  • Learn and adapt to customer’s culture, security strategies, security goals, security objectives, and security capabilities
  • Maintain knowledge of outstanding vulnerability management issues as it pertains to the Customer Vulnerability Management Service and communicate updates as appropriate
  • Collaborate with program management and Customer teams to create both tactical and strategic plans(establish and communicate a clear vision and ensure short term issues do not overtake strategic goals)
  • Serve as an escalation point for all Customer technical issues requiring support within the Vulnerability Management offering
  • Providing Vulnerability Assessment Scanning and guidance, False Positive Validation, Attestation Signing, Compliance Scanning and policy creation using the QualysGuard Policy Compliance Suite and Web Application Scanning using the Qualys WAS Suite

What You Will Bring

  • 5+ years of experience in technical security support role
  • 3+ years of experience in a vulnerability management role
  • Strong network engineering experience with Linux/Unix, Windows, and network infrastructure administration
  • Experience with Vulnerability Management platforms such as QualysGuard, Nessus, Rapid 7
  • Provide guidance and support for Vulnerability remediation scenarios
  • Strong technical, analytical, and interpersonal skills; ability to interact with stakeholders like customer support or executive leadership teams, vendors, etc.
  • Provide guidance in developing, maturing and implementing a Vulnerability Management security program
  • One or more of the following certifications: CISSP, GPEN, GCIH, CEH are desired, or equivalent Security Certification
How to Apply
About Sophos

ophos is a leading global security services, software, and hardware company, driven by a vision to make powerful cybersecurity accessible to practically anyone.

View Company Profile
Vulnerability Management Engineer (Romania) at Sophos - RemoteTips