> Markdown version of [/jobs/ext/1284477-manager-it-security-vulnerability-management-pentesting](https://www.wearedevelopers.com/jobs/ext/1284477-manager-it-security-vulnerability-management-pentesting). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager IT- Security - Vulnerability Management & Pentesting - **Company:** ista SE - **Location:** Essen, Germany - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Software System Penetration Testing, Burp Suite, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, Information Technology Operations, Nmap, Secure Coding, Software Engineering, Software Vulnerability Management, Cloud Platform System, Information Technology, Nessus - **Published:** July 16, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=ca655ddfee36fba6 ## About the Role * Several years of experience in IT Security, ideally with a focus on Vulnerability Management, Exposure Management, Cloud Security, or Security Operations, form the foundation of your profile * A solid understanding of modern IT and cloud architectures, identity and access management, software development, and operational IT processes enables you to navigate complex security environments with confidence * Hands-on experience with industry-leading security tools such as Tenable, Burp Suite, Nmap, Nessus, or OWASP ZAP allows you to transform security data into meaningful analyses, reports, and actionable recommendations * Technical, regulatory, and internal security requirements are translated into pragmatic processes, effective controls, and sustainable security measures * In-depth knowledge of common attack techniques, vulnerabilities, and corresponding countermeasures, combined with practical experience in conducting web, API, cloud, and infrastructure penetration tests, rounds out your technical expertise * A structured, analytical, and solution-oriented mindset, paired with the ability to communicate complex topics clearly and effectively to different audiences, distinguishes your way of working * Strong initiative, consulting skills, and a collaborative mindset enable you to thrive in an international environment. Professional fluency in English is essential, while German language skills are considered an advantage ## Description * You drive the continuous development of our technical Vulnerability and Exposure Management capabilities and contribute to the sustainable reduction of security risks across the organization * You operate, optimize, and further enhance our Tenable-based security tool landscape, including dashboards, reporting, training initiatives, and KPI-driven analytics * Through the analysis of vulnerabilities, misconfigurations, and security risks across IT systems, applications, cloud environments, and infrastructure, you derive effective remediation strategies and risk mitigation measures * You lead the planning and coordination of penetration testing activities across web, API, cloud, mobile, and infrastructure environments, helping to proactively identify and mitigate security vulnerabilities * Close collaboration with Tribes, Squads, Product Owners, and IT Operations teams enables you to support risk prioritization, SLA compliance, and the sustainable implementation of remediation measures * You manage and optimize processes related to security exceptions, risk acceptances, and compensating controls, while embedding security requirements early into development and operational processes, particularly in areas such as Secure Development Lifecycle, third-party components, container security, and cloud security * Working closely with internal and external stakeholders, you prepare management-ready security insights and represent IT Security in projects, technical discussions, and cross-functional initiatives ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)