Threat and Vulnerability Management Specialist
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Threat and Vulnerability Management Specialists to identify, assess, prioritise and manage cybersecurity threats and vulnerabilities across complex enterprise IT environments.
The successful candidates will play a critical role in strengthening organisational security by proactively identifying vulnerabilities, evaluating potential threats, coordinating remediation activities and implementing effective vulnerability management processes.
This position requires strong hands-on experience with vulnerability assessment tools, threat intelligence, security risk analysis and enterprise cybersecurity technologies.
Key Responsibilities
- Conduct regular vulnerability assessments across servers, networks, endpoints, applications, databases and cloud environments.
- Identify, analyse and prioritise security vulnerabilities based on severity, exploitability, asset criticality and business impact.
- Implement and maintain enterprise vulnerability management programmes, processes and procedures.
- Operate and administer vulnerability scanning and assessment tools.
- Analyse vulnerability scan results and distinguish genuine security risks from false positives.
- Monitor emerging cyber threats, vulnerabilities, exploits and security advisories.
- Correlate threat intelligence with identified vulnerabilities to determine potential organisational exposure.
- Coordinate vulnerability remediation activities with infrastructure, networking, cloud, application and security teams.
- Track remediation progress and ensure vulnerabilities are addressed within agreed service-level targets.
- Conduct risk assessments and recommend appropriate mitigation or compensating controls.
- Support patch management activities and verify successful remediation.
- Perform vulnerability assessments on internal and external infrastructure.
- Assist with identifying security weaknesses in cloud-based and hybrid environments.
- Develop vulnerability management dashboards, reports and risk metrics for technical teams and management.
- Maintain accurate vulnerability registers, remediation records and risk documentation.
- Support cybersecurity incident response and threat investigation activities when required.
- Ensure vulnerability management practices align with relevant information security frameworks and regulatory requirements.
- Recommend continuous improvements to vulnerability identification, prioritisation and remediation processes.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security or a related discipline.
- Typically 3–5 years of relevant experience in vulnerability management, cybersecurity operations, threat management or information security.
- Proven hands-on experience conducting vulnerability assessments in enterprise IT environments.
- Practical experience using enterprise vulnerability scanning and assessment tools.
- Strong understanding of common vulnerabilities, attack vectors, exploitation techniques and cybersecurity threats.
- Experience analysing vulnerability scan results and developing remediation recommendations.
- Knowledge of the Common Vulnerabilities and Exposures (CVE) system and Common Vulnerability Scoring System (CVSS).
- Understanding of patch management, vulnerability remediation and security risk management processes.
- Familiarity with threat intelligence sources and vulnerability advisories.
- Experience working with Windows, Linux, network infrastructure and enterprise applications.
- Understanding of cloud security vulnerabilities and associated security controls.
- Knowledge of recognised cybersecurity frameworks such as ISO 27001, NIST and CIS Controls.
- Strong analytical, troubleshooting and technical reporting abilities.
Technical Skills and Competencies
Vulnerability Assessment and Management
- Tenable Nessus / Tenable Vulnerability Management
- Qualys VMDR
- Rapid7 InsightVM / Nexpose
- Microsoft Defender Vulnerability Management
- OpenVAS / Greenbone
- Vulnerability scanning, analysis, prioritisation and remediation tracking
Threat Intelligence and Risk Analysis
- CVE and CVSS
- CISA Known Exploited Vulnerabilities (KEV) Catalogue
- MITRE ATT&CK Framework
- Threat intelligence feeds and security advisories
- Exploitability analysis and risk-based vulnerability prioritisation
Infrastructure and Network Security
- Windows Server and Linux environments
- TCP/IP networking and network security fundamentals
- Firewalls, intrusion detection and prevention systems
- Endpoint protection and security configuration management
- Network vulnerability identification and remediation
Cloud and Enterprise Security
- Microsoft Azure and/or AWS security fundamentals
- Cloud vulnerability assessment and remediation
- Hybrid infrastructure security
- Enterprise asset discovery and inventory management
Security Operations and Reporting
- SIEM platforms such as Microsoft Sentinel, Splunk or IBM QRadar
- Security incident management processes
- Vulnerability dashboards and technical reporting
- Security risk registers and remediation tracking
- ServiceNow, Jira or equivalent ticketing and workflow platforms
Security Frameworks and Standards
- ISO/IEC 27001
- NIST Cybersecurity Framework
- NIST SP 800-40
- CIS Critical Security Controls
- Relevant information security policies and compliance requirements
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- CompTIA Security+
- CompTIA CySA+
- Certified Ethical Hacker (CEH)
- Certified Information Systems Security Professional (CISSP)
- GIAC Certified Vulnerability Assessor (GCVA)
- GIAC Continuous Monitoring Certification (GMON)
- GIAC Security Essentials (GSEC)
- Tenable Certified Specialist or relevant Tenable certifications
- Qualys Vulnerability Management certifications
- Microsoft Certified: Security Operations Analyst Associate
- Relevant cloud security certifications
Key Personal Attributes
- Strong analytical and investigative thinking.
- Excellent attention to detail and technical accuracy.
- Ability to assess cybersecurity risks and prioritise remediation activities.
- Strong problem-solving and troubleshooting capabilities.
- Ability to communicate complex technical findings clearly.
- Effective collaboration with infrastructure, security and application teams.
- Proactive approach to identifying emerging cybersecurity threats.
- Ability to manage multiple vulnerability assessments and remediation activities.
- Strong organisational and technical documentation skills.
- High standards of confidentiality, integrity and professional ethics.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their relevant threat and vulnerability management experience, together with copies of applicable technical qualifications and professional certifications.
Applications should demonstrate practical experience with vulnerability management tools, security assessment methodologies, threat intelligence and enterprise vulnerability remediation processes.
Candidates are encouraged to specify the technologies, platforms and security tools they have worked with, including the size and complexity of the environments they have supported.
Please note: Specific project requirements, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.