Vulnerability Management Specialist (m/f/d)
Barcelona, B, ES, 08022
Syntax is a leading Managed Cloud Provider for Mission Critical Enterprise Applications and has been providing comprehensive technology solutions to businesses of all sizes since 1972. Syntax has undisputed strength to implement and manage ERP deployments (Oracle, SAP) in a secure and resilient private, public or hybrid cloud. With strong technical and functional consulting services, and world-class monitoring and automation, Syntax serves some of North America’s largest corporations across a diverse range of industries. Syntax has offices worldwide, and partners with Oracle, SAP, AWS, Microsoft, IBM and other global technology leaders.
POSITION SUMMARY
As an Exposure Management Specialist, you will be at the forefront of protecting Syntax and its customers by identifying, assessing, and reducing vulnerabilities across on-premises and cloud environments. You will operate work closely with the SOC, IT teams, and customers to remediate security gaps and enhance our overall risk posture.
Responsibilities
· Operate and maintain vulnerability scanning platforms for internal and customer environments.
· Analyse vulnerability data, prioritise findings based on threat intelligence, exploitability, and business risk.
· Work with system owners and developers to validate findings and track remediation to completion.
· Monitor and assess multi-cloud environments for misconfigurations, compliance gaps, and security risks.
· Advise on configuration best practices for AWS, Azure, and other managed cloud services.
· Partner with the SOC to correlate vulnerability data with active threat and incident information.
· Collaborate with internal IT, network, and application and customers teams to plan and implement secure solutions.
· Liaise with customer security teams, presenting findings and supporting agreed-upon remediation plans.
· Produce metrics and trend reports for leadership and customer stakeholders.
· Contribute to vulnerability management policies, standards, and operational playbooks.
· Coordinate and support the penetration testing programme.
· Understanding of Secure Software Development, including IAST, SAST and DAST.
Required Skills and Experience
· 3+ years in related role.
· Analytical skills, problem solving and critical thinking with a desire and eagerness to acquire new knowledge and constantly learn.
· Resourceful, self-motivated and someone who shines as an individual and as part of a team.
· Solid understanding of CVSS scoring, vulnerability lifecycle management, and remediation workflows.
· Experience with cloud service provider security (AWS, Azure, GCP) and associated compliance frameworks.
· Proficiency in interpreting scan results and translating them into actionable remediation plans.
· Familiarity with scripting (Python, PowerShell) for automation of scanning and reporting tasks.
· Understanding of networking, OS hardening, patch management, and CI/CD security considerations.
Key Technologies
· Qualys VMDR and CSPM
· Burp Suite
· Shodan.io
· Crowdstrike Spotlight
· Microsoft Defender for Vulnerability
Mandatory Requirements:
Nationality or Work Authorization: Spanish or Portuguese nationality, or alternatively a permanent work permit/VISA for Spain or Portugal.
Language Proficiency: Advanced level of Spanish and English (both written and spoken).
Why Syntax?
Become a part of our success story and work in a company with exciting innovation projects that are causing a stir across the industry. We recently launched one of the world's most advanced manufacturing facilities based on SAP S/4HANA Cloud and SAP Digital Manufacturing Cloud for Execution - for Smart Press Shop, a pioneering joint venture between Porsche and forming specialist Schuler.
- Competitive, above-average compensation
- Global tourist: With us, you can also work from abroad from time to time
- Flexible working time models, home office
- Attractive benefits, e.g. various health offers
- A modern environment in which the "you" is part of it
- Open feedback culture, flat hierarchies and a motivated team
- Individual career planning with continuous training and coaching on the job
You see a personal challenge in this responsible task? Apply now - and become part of the SYNTAX team!