Vulnerability Response Senior SME

Mindbox Sp. z o.o. KRAKÓW 2026-09-22



  • Minimum 5 years of experience in IT Security or a similar role

  • Proven experience reviewing and assessing critical/high-severity vulnerabilities from sources such as NIST/NVD and vendor advisories, translating findings into clear business impact

  • Strong understanding of common vulnerability types and attack techniques (e.g., remote code execution, privilege escalation, authentication bypass)

  • Experience with vulnerability scanning tools, including Tenable, and application security testing (SAST, DAST)

  • Solid technical foundation across networking and application delivery, including WAFs, load balancers, and TLS/certificates

  • Experience working across on-prem and cloud environments

  • Practical knowledge of remediation approaches: patching, upgrades, configuration hardening, and compensating controls

  • Strong stakeholder management skills – able to partner with service owners, platform teams, and governance stakeholders to drive actions to closure

  • Excellent written communication skills


Nice to have


  • Good understanding of the CI/CD lifecycle and how security testing integrates into build and release pipelines

  • Background in Cyber Security Operations, Risk Management, or Governance within a mid-to-large enterprise





Joining this project you’ll become part of Mindbox – a tech-driven company where consulting, engineering, and talent meet to build meaningful digital solutions. We’ll back you up every step of the way, accelerate your development, and ensure your skills make a difference. 



At Mindbox we connect top IT talents with technology projects for leading enterprises across Europe. 




Join our client's team, where you'll play a key role in shaping the Vulnerability Management Response & Remediation function at one of the world's leading international banks. Your contribution will help deliver high-impact solutions in cybersecurity – protecting a global financial institution's technology estate across on-premise, cloud, and third-party environments.



Sounds like your kind of challenge? 


Hybrid: 6x/msc from the office in Kraków



What you get in return


  • Flexible cooperation model – choose the form that suits you best
    (B2B, employment contract, etc.)

  • Hybrid work setup – Hybrid: 6x/msc from the office in Kraków

  • Collaborative team culture – work alongside experienced professionals eager to share knowledge 

  • Continuous development – access to training platforms and growth opportunities 

  • Comprehensive benefits – including Interpolska Health Care, Multisport card, Warta Insurance, and more 

  • High quality equipment – laptop and essential software provided 


,[Assess and Review Vulnerabilities: Analyze critical and high-severity vulnerabilities (NIST/NVD, vendor advisories), determine exposure and impact on our environment., Validate and Map Risks: Confirm findings, validate exposure, and map vulnerabilities to assets through CMDB and inventory collaboration., Define Mitigation Strategies: Recommend remediation and mitigation approaches such as patching, upgrades, hardening, and compensating controls., Drive Execution & Governance: Coordinate remediation progress, ensure timely delivery, and provide high-quality technical and governance reports., Verify Effectiveness: Oversee validation testing and confirm closure of remediation activities., Regulatory & Audit Support: Provide data and commentary for regulatory, audit, and governance reporting (Risk Maps, KCIs, KRIs).] Requirements: Security, NIST, Testing, SAST, DAST, Networking, TLS, Cloud, Stakeholder management