Sii Poland
Website:
sii.pl
Job details:
We are looking for a PSIRT & Product Security Specialist to support Product Security and Coordinated Vulnerability Disclosure (CVD) activities within a global environment.
The role focuses on coordinating the complete vulnerability handling and disclosure lifecycle for products, working closely with security researchers, customers, vendors, engineering teams, product management, legal, communications, and support functions.
Unlike traditional IT Vulnerability Management roles focused primarily on infrastructure scanning, patching, and remediation, this position is oriented toward Product Vulnerability Management and cybersecurity throughout the product lifecycle.
The successful candidate will coordinate vulnerability reports, assess and track disclosure activities, support remediation processes, prepare security communications, and ensure that vulnerabilities are handled according to defined processes and industry standards.
This is primarily a vulnerability management coordination and stakeholder-facing role rather than a deep technical vulnerability research position. The ideal candidate should be comfortable representing the PSIRT function independently and communicating professionally with external security researchers and customers.
Your tasks
- Coordinating vulnerability disclosures between security researchers, customers, vendors, and internal stakeholders
- Managing the end-to-end vulnerability handling process from initial report through remediation and disclosure
- Tracking multiple vulnerabilities and disclosure activities while ensuring timely follow-up and adherence to defined processes
- Looking for vulnerability assessment and classification using CVE, CVSS, and CWE frameworks
- Preparing and reviewing security advisories, vulnerability notifications, and technical communications
- Managing communication and collaboration with external researchers and customers throughout disclosure activities
- Handling CVE assignment and coordination activities, including interaction with relevant CNA processes where applicable
- Ensuring vulnerability handling activities align with ISO 29147, ISO 30111, and established PSIRT processes
- Reporting product security, governance, metrics, and vulnerability status tracking
- Maintaining accurate vulnerability records and documentation within tracking and workflow management tools
- Collaborating with legal, communications, support, and other business functions during coordinated disclosure activities
- Contributing to the continuous improvement of product vulnerability management and PSIRT processes
- Supporting cybersecurity activities across the product lifecycle and helping ensure vulnerabilities are appropriately addressed
Requirements
- At least 5 years of cybersecurity background with experience in Product Security, Vulnerability Management, PSIRT, CERT/CSIRT, or Incident Response
- Practical understanding of Coordinated Vulnerability Disclosure and vulnerability handling processes
- Knowledge of CVE, CVSS, CWE, and security vulnerability classification concepts
- Familiarity with industry standards such as ISO 29147 and ISO 30111
- Experience of coordinating activities across security, engineering, product, legal, communications, and support teams
- Proven ability to communicate professionally with external security researchers, customers, vendors, and internal stakeholders
- Ability to manage multiple vulnerabilities, stakeholders, and deadlines simultaneously
- Good understanding of software or product development processes and Secure Development Lifecycle principles
- Strong organizational and follow-up skills with a proactive approach to vulnerability remediation
- B2 level of English
Nice to have
- Good experience in Product Security or Product Vulnerability Management within manufacturing, industrial, automotive, energy, or other technology-driven product environments
- Knowledge of IEC 62443 and industrial cybersecurity practices
- Exposure to Open Source Software (OSS) security, OSS maintenance, or vulnerability management
- Familiarity with CVE Numbering Authority (CNA) processes
- Awareness about Software Bill of Materials (SBOM) and product cybersecurity compliance
- Understanding of product security requirements throughout the Secure Development Lifecycle
- Exposure to CISA advisories or other industry vulnerability disclosure ecosystems
- CERT/CSIRT or other security incident response functions
Job no. JOB-9DA23
Sii ensures that all hiring decisions are made solely on the basis of qualifications and competence. We are committed to equal and fair treatment of all, regardless of legally protected characteristics. At Sii, we promote a diverse and inclusive work environment, in full compliance with applicable anti-discrimination laws.
Benefits For You
- Diverse portfolio of clients
- Wide portfolio of technologies
- Employment stability
- Remote work opportunities
- Contracts with the biggest brands
- Great Place to Work Europe
- Many experts you can learn from
- Open and accessible management team
Click on Apply to know more.