> Markdown version of [/jobs/ext/2812307-vulnerability-management-analyst-remediation-tracking-for-nato-with-security-clearance](https://www.wearedevelopers.com/jobs/ext/2812307-vulnerability-management-analyst-remediation-tracking-for-nato-with-security-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Management Analyst - Remediation Tracking for NATO with security clearance - **Company:** WLG - **Location:** Bergen, Belgium - **Contract:** Permanent contract - **Skills:** Cyber Security, Databases, Information Engineering, Python (Programming Language), PostgreSQL, Microsoft SQL Server, NumPy, Windows PowerShell, Power BI, SQL Databases, Software Vulnerability Management, Grafana, Pandas, Nessus, Qualys - **Published:** September 10, 2026 - **Apply:** https://www.adzuna.be/details/5877633929 ## About the Role * Substantial vulnerability management experience, current rather than historical, plus a track record of validating that delivered work meets its security requirements. * Practical familiarity with scanners and their output formats - Nessus, Qualys, OpenVAS. * A working grounding in security architecture: boundary protection, encryption, identity and access, monitoring and detection, incident response and risk. * Real SQL depth for modelling and querying large scan datasets, in PostgreSQL or SQL Server. * Advanced Power BI, including data modelling and DAX, or the Grafana equivalent against SQL and time-series sources. * Python with Pandas or NumPy, or PowerShell, for parsing scan output and removing manual steps. * Ownership: the motivation to carry a task to its end, alone or in a team, and the writing to show for it. * Nice to have: certifications such as CISSP, CISM or a GIAC, and a data or business intelligence certification such as PL-300. ## Description Most organisations can scan. Far fewer can say what the scans mean, who owns each finding and whether anything was fixed. A multinational defence organisation is looking for the analyst who closes that gap - half security assessment, half data engineering, and the coordination that turns a report into a repaired system. What you would be doing * Reading the weekly assessment results, interpreting the technical findings, and writing the remediation plan that goes to the right technical owner. * Judging technical impact so that remediation is prioritised on risk rather than on volume, and advising on hardening at operating system, database and network level. * Building and running the data side: a structured repository that aggregates raw scan output from several sources, and the pipeline that ingests it without manual handling. * Designing and maintaining live dashboards in Power BI or Grafana, and the metrics that make operational and management reporting meaningful. * Acting as the technical contact for site administrators and system owners, and keeping the remediation tracking honest and current. * Producing the weekly and monthly reporting, and chairing the coordination meetings where roadblocks get cleared. * Leaving behind documentation good enough that the platform can be maintained without you. ## Related Videos - [Vectorize all the things! Using linear algebra and NumPy to make your Python code lightning fast.](https://www.wearedevelopers.com/videos/562-vectorize-all-the-things-using-linear-algebra-and-numpy-to-make-your-python-code-lightning-fast) - [Advanced Typing in TypeScript](https://www.wearedevelopers.com/videos/496-advanced-typing-in-typescript) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to implement convenient Python bindings to C++](https://www.wearedevelopers.com/videos/618-how-to-implement-convenient-python-bindings-to-c) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)