Security Consultant Vulnerability Intelligence & Asm H/F

Saint-Gobain
Courbevoie, France
12 days ago
Apply on www.hellowork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Configuration Management Databases Databases Computer Telephony Integration Data Integration Data Mining Software Vulnerability Management Scripting Mobileiron Cyber Threat Analysis Banner Advertisement Qualys
+1 more
Vulnerability Analysis

Job description

Within Group Digital & IT, the VOC team is responsible for continuously monitoring vulnerabilities in the Saint-Gobain environment as well as the Exposed Attack Surface across all business units and regions.

As a VOC Consultant, you will be responsible for delivering key projects around Vulnerability Intelligence (VI), Attack Surface Management (ASM), and the Patrowl platform.

You will play a key role in driving and coordinating strategic initiatives around VI and ASM. Reporting to the VOC Manager, you will act as a team leader and enabler across multiple workstreams, combining operational support, technical expertise, process governance, automation, and security analytics.

You will contribute to the continuous improvement of Saint-Gobain’s vulnerability management capabilities by leading qualification activities, supporting remediation governance, optimizing ASM processes, and integrating data from multiple security and inventory sources.

Missions

  • Support the qualification and risk assessment of newly published vulnerabilities (including PoC validation when required).
  • Maintain a centralized database of qualified vulnerabilities enriched with EPSS, QVS, EUVD, and SG VI Score.
  • Automate vulnerability qualification, exposure analysis, prioritization, and bulletin workflows.
  • Support the VI team in vulnerability monitoring activities and ensure critical vulnerabilities are properly tracked.
  • Follow the publication of vulnerability bulletins and support remediation tracking for highly critical findings.
  • Define and improve processes leveraging available inventory tools (Qualys GAV, Loginventory, Recorded Future, Patrowl, SSCM, MobileIron, etc.) to identify impacted assets and proactively notify Asset and Application Managers.
  • Contribute to documenting vulnerability assessment methodologies and CTI monitoring processes.
  • Leverage Saint-Gobain tools to map and monitor the external digital attack surface.
  • Support the ASM team in reviewing and improving ASM processes and deliverables.
  • Define and document processes integrating ASM tools with CMDB, Minerva, inventory sources, acquisitions/divestitures, and domain management providers.
  • Develop scripts for automated data extraction, enrichment, and correlation with internal data sources.
  • Assist in building searchable datasets using banners, WHOIS, ASN, and threat intelligence data.
  • Automate the use of ASM tools such as Shodan, Recorded Future, Patrowl, and SecurityScorecard.
  • Help Vulnerability Management teams assess, challenge, and confirm outputs from Qualys, Patrowl, and other vulnerability/ASM tools.

Objectives and Deliverables

  • Enhance Vulnerability Intelligence (VI) capabilities.
  • Build Attack Surface Management (ASM).
  • Provide operational support and enablement.
  • Develop Offensive Cyber Threat Intelligence (CTI).

Requirements

Profile wantedExpert level in cybersecurityAdvanced skills in PentestConfirmed experience in Vulnerability Intelligence (VI)Confirmed skills in ScriptingConfirmed experience in Attack Surface Management (ASM)Confirmed knowledge of risk managementConfirmed experience in vulnerability management

Mais aussi…

Daily rate:Salary according to profile, 2. Advanced skills in Pentest

  1. Confirmed experience in Vulnerability Intelligence (VI)
  2. Confirmed skills in Scripting
  3. Confirmed experience in Attack Surface Management (ASM)
  4. Confirmed knowledge of risk management
  5. Confirmed experience in vulnerability management

Benefits & conditions

Saint-Gobain homeworking policy allows a maximum of 2 days of home office per week.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.hellowork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all