Cyber Exposure Management Expert (m/w/d)
On-siteFrankfurt am MainEUR 70kprofessional / experienced
- Posted
- today
- Source
- Arbeitnow
- Field
- Security
Skills
SecurityRoadmappingNext.jsAI
Description
It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks. This means we offer cyber security services to private and governmental organizations to help them better prepare for, prevent, detect and respond to cyber security incidents. All of this is built on four fundamental values that define who we are: We are Proud, We Break Barriers, We Care and No BS!
Tasks
As Cyber Exposure Management Expert (m/w/d) located in Germany, you will be the technical lead for developing NVISO's Cyber Exposure offering. You will define how Vulnerability Management, Asset Management, hardening, Patch Management, reporting and remediation work together through clear processes and responsibilities, and guide the technical decisions that make the service work for our clients.
You will be the expert clients and colleagues turn to for the complete picture: which assets matter, where they are exposed, who needs to act and whether remediation has worked. You will design the processes, integrations and reporting that connect these questions, lead complex customer engagements and help other consultants deliver the service. You will advise on hardening and help clients establish ownership, remediation targets and a process that fits their IT operations.
You will also shape what we build next. Starting from our existing Vulnerability Management capabilities, you will develop the technical roadmap towards Continuous Threat Exposure Management (CTEM) and assess where Attack Surface analysis, exposure validation and Quantum Readiness belong in the offering. This gives you room to propose solutions, build prototypes and test them with clients before turning them into repeatable services.
Typical responsibilities include:
- Defining the technical architecture and delivery approach for the Cyber Exposure offering, connecting Vulnerability Management, Asset Management, hardening, Patch Management, reporting and remediation, with clear roles and governance;
- Leading technical delivery on customer engagements, advising on remediation and hardening, resolving design and integration problems and reviewing the quality of our work;
- Linking vulnerability findings to asset inventories, CMDBs, cloud environments, business services and owners, and resolving gaps in coverage and data quality;
- Designing remediation processes with owners, priorities, SLAs, escalation, risk acceptance and closure checks, aligned with Change Management and supported by ITSM, Patch Management and other remediation solutions;
- Building reporting that shows clients their exposure and remediation progress, with clear priorities for technical teams and reliable measures of coverage, ageing, SLA performance and accepted risk for management;
- Advising on secure configurations and hardening baselines for infrastructure and cloud environments, reducing unnecessary exposure and proposing compensating controls when patching is not immediately possible;
- Keeping up with developments in Exposure Management and evaluating AI and agentic solutions through targeted pilots to improve existing approaches to prioritization, remediation guidance and reporting. You will test accuracy and usefulness, protect client data and define human oversight, including approval before AI recommendations trigger remediation actions;
- Turning client needs into service packages, technical standards and delivery methods, coaching consultants and providing technical input for proposals and scoping;
- Developing the service roadmap and evaluating new capabilities through pilots, including CTEM, Attack Surface analysis and cryptographic discovery, Crypto Agility and Post Quantum Cryptography migration planning. You will help decide which capabilities are ready to become services and what we need to deliver them well.
Requirements
- You hold citizenship in one of the 32 NATO member states or the Austrian citizenship;
- Bachelor's or Master's degree in a relevant field, or equivalent professional experience;
- Strong practical experience in Vulnerability Management, including scanning platforms, prioritization based on asset criticality and exploitability, and remediation processes, with the ability to guide technical decisions on customer engagements;
- Understanding of enterprise infrastructure, networking and cloud environments, with practical experience advising on secure configurations, hardening baselines and compensating controls;
- Experience connecting security findings with asset inventories, CMDBs or Asset Management platforms, including ownership mapping and improving data quality;
- Experience designing security dashboards and management reports that make priorities, progress and data limitations clear;
- Experience designing remediation processes across security and IT teams, including ownership, SLAs, exceptions and Change Management. Familiarity with ITSM and remediation platforms is expected; scripting and API skills are an advantage;
- Ability to design a solution across several tools and processes, explain the technical choices and guide colleagues through implementation. Experience developing a consulting service is an advantage;
- Interest in developing CTEM and Quantum Readiness services and testing AI applications in security operations. Experience evaluating AI or agentic solutions is an advantage. Experience with Attack Surface analysis, Crypto Agility or Post Quantum Cryptography is welcome; you do not need to be an expert in every area on day one;
- Fluent business English and professional fluency in the relevant local language(s).
Benefits
- Working and learning from the best people in the European cyber security industry. We have multiple SANS Instructors working at NVISO, our staff has presented at popular hacking conferences (BlackHat, BruCON, OWASP, etc) and all of our technical staff can acquire deep technical security certifications (GSE, GXPN, GREM, GCFA, OSCP, etc);
- Generous training budget of 10.000 EUR + 10 man days for attending lectures rolling over 2 years;
- Base salary range (depending on experience and skillset): 70.000 EUR p.a. – 100.000 EUR p.a.;
- Regular team-building and fun events;
- Our commitment to coach and counsel you and help you grow; each employee receives a personal coach within the team, whose role is to ensure your well-being and helps you grow in your career!
- Flexible working hours and home office possibilities (incl. working abroad weeks within the EU);
- Business Bike Leasing;
- BahnCard 50 1st class + public transfer ticket or EGYM WellPass;
- 30 holidays;
- Company Pension Scheme;
- Cool offices in the center of Frankfurt, Munich and Vienna (with BBQ, kicker table, table tennis, playstations, etc.).
Disclaimer on the Use of AI Tools in the Application Process
Please be aware that the creation and submission of application documents (e.g. CV, cover letter, case studies, etc.) using AI-powered tools is only permitted to a limited extent.
Our expectations:
- Application documents must authentically reflect your own qualifications, personality, and motivation.
- The use of AI for supportive purposes (e.g. spell-checking, improving wording) is acceptable.
- Fully generated application documents created by AI without personal adaptation or review are not permitted.
- Under no circumstances may NVISO information, data, or documents be uploaded to or processed by external AI tools.
We reserve the right to exclude applications from the selection and interview process that are clearly created primarily or exclusively by AI and show no recognizable personal input.
The purpose of this policy is to ensure a fair and transparent recruitment process and to obtain an authentic impression of our applicants.
Find Jobs in Germany on Arbeitnow
JobMatch aggregates public listings. Always apply through the original posting.