Security Consultant Vulnerability Intelligence & Asm H/F - Salutech
- Courbevoie - 92
- Freelance
- Télétravail accepté
- Salutech
Les missions du poste
What they need
Context
Within Group Digital & IT, the VOC team is responsible for continuously monitoring vulnerabilities in the Saint-Gobain environment as well as the Exposed Attack Surface across all business units and regions.
As a VOC Consultant, you will be responsible for delivering key projects around Vulnerability Intelligence (VI), Attack Surface Management (ASM), and the Patrowl platform.
You will play a key role in driving and coordinating strategic initiatives around VI and ASM. Reporting to the VOC Manager, you will act as a team leader and enabler across multiple workstreams, combining operational support, technical expertise, process governance, automation, and security analytics.
You will contribute to the continuous improvement of Saint-Gobain's vulnerability management capabilities by leading qualification activities, supporting remediation governance, optimizing ASM processes, and integrating data from multiple security and inventory sources.
Missions
- Support the qualification and risk assessment of newly published vulnerabilities (including PoC validation when required).
- Maintain a centralized database of qualified vulnerabilities enriched with EPSS, QVS, EUVD, and SG VI Score.
- Automate vulnerability qualification, exposure analysis, prioritization, and bulletin workflows.
- Support the VI team in vulnerability monitoring activities and ensure critical vulnerabilities are properly tracked.
- Follow the publication of vulnerability bulletins and support remediation tracking for highly critical findings.
- Define and improve processes leveraging available inventory tools (Qualys GAV, Loginventory, Recorded Future, Patrowl, SSCM, MobileIron, etc.) to identify impacted assets and proactively notify Asset and Application Managers.
- Contribute to documenting vulnerability assessment methodologies and CTI monitoring processes.
- Leverage Saint-Gobain tools to map and monitor the external digital attack surface.
- Support the ASM team in reviewing and improving ASM processes and deliverables.
- Define and document processes integrating ASM tools with CMDB, Minerva, inventory sources, acquisitions/divestitures, and domain management providers.
- Develop scripts for automated data extraction, enrichment, and correlation with internal data sources.
- Assist in building searchable datasets using banners, WHOIS, ASN, and threat intelligence data.
- Automate the use of ASM tools such as Shodan, Recorded Future, Patrowl, and SecurityScorecard.
- Help Vulnerability Management teams assess, challenge, and confirm outputs from Qualys, Patrowl, and other vulnerability/ASM tools.
Objectives and Deliverables
- Enhance Vulnerability Intelligence (VI) capabilities.
- Build Attack Surface Management (ASM).
- Provide operational support and enablement.
- Develop Offensive Cyber Threat Intelligence (CTI).
Working Conditions
- Saint-Gobain homeworking policy allows a maximum of 2 days of home office per week.
Le profil recherché
Profile wanted
- Expert level in cybersecurity
- Advanced skills in Pentest
- Confirmed experience in Vulnerability Intelligence (VI)
- Confirmed skills in Scripting
- Confirmed experience in Attack Surface Management (ASM)
- Confirmed knowledge of risk management
- Confirmed experience in vulnerability management