Über diese Senior IT Security Analyst Stelle bei Wolters Kluwer
About the Role:
As a Senior IT Security Analyst, you will engage in advanced cybersecurity tasks with a high level of autonomy. Your contributions will be crucial for maintaining a secure IT environment and anticipating potential threats. You'll exercise thorough security measures and guide less experienced team members.
Key Responsibilities
Support vulnerability management activities across cloud, infrastructure, containers, Kubernetes, and application environments.
Review and analyze findings from security tools such as CSPM, vulnerability scanners, container security tools, and application security platforms.
Work with infrastructure, cloud, application, and DevOps teams to drive remediation of identified security issues.
Support cloud security posture management across AWS, Azure, or GCP environments.
Manage EDR and XDR platforms: Deploy, configure, and optimize security tools to monitor endpoints, integrate cross-layered telemetry (cloud, network, and email), and eliminate security silos.
Detect and respond to threats: Analyze advanced multi-vector alerts, hunt for hidden attackers, and orchestrate automated playbooks to rapidly isolate compromised systems and minimize response times.
Review cloud misconfigurations, exposed resources, identity risks, network security gaps, and compliance issues.
Assist in container and Kubernetes security reviews, including image vulnerabilities, runtime exposure, cluster configuration, and workload security.
Support vulnerability prioritization based on severity, exploitability, exposure, asset criticality, and business impact.
Help maintain dashboards, reports, trackers, and metrics for vulnerability remediation and security posture.
Contribute to automation of repetitive security tasks, reporting, data enrichment, and remediation workflows.
Support basic application security and shift-left activities, including SAST, DAST, SCA, dependency risks, and secure development awareness.
Assist with basic forensic analysis, incident triage, log review, and evidence collection when required.
Contribute to emerging AI security initiatives, including understanding risks around AI agents, connectors, cloud-hosted AI workloads, data exposure, and infrastructure security.
Coordinate with multiple stakeholders to track remediation progress, exceptions, risk acceptance, and closure.
Required Skills and Experience
5–6 years of experience in cybersecurity, vulnerability management, cloud security, infrastructure security, or related domains.
Good understanding of cloud security concepts across AWS, Azure, or GCP.
Hands-on or working knowledge of CSPM tools such as Orca, Wiz, Prisma Cloud, Defender for Cloud, Lacework, or similar.
Understanding of vulnerability management processes, including detection, prioritization, remediation tracking, SLA monitoring, and reporting.
Familiarity with vulnerability scanners such as Rapid7, Qualys, Tenable, or similar.
Good understanding of infrastructure security, including servers, operating systems, patching, network exposure, identity, and access controls.
Basic understanding of containers and Kubernetes security, including container images, registries, clusters, namespaces, workloads, secrets, and runtime risks.
Basic understanding of application security and shift-left practices, including SAST, DAST, SCA, CI/CD security, and secure coding concepts.
Understanding of AI security concepts such as AI agents, connectors, data access, prompt injection, excessive permissions, and secure integration with enterprise tools.
Ability to analyze security findings and translate them into clear remediation actions.
Experience working with dashboards, Excel, Power BI, ServiceNow, Jira, or similar reporting and tracking tools.
Basic scripting or automation experience using Python, PowerShell, Bash, KQL, SQL, or APIs.
Strong communication skills with the ability to work with cloud, infrastructure, application, DevOps, and leadership teams.
Good to Have
Exposure to Kubernetes security tools, container scanning, runtime security, or CNAPP platforms.
Experience with ServiceNow Vulnerability Response, Jira, Power BI, Snowflake, or similar enterprise reporting platforms.
Familiarity with MITRE ATT&CK, MITRE ATLAS, OWASP Top 10, OWASP LLM Top 10, CIS Benchmarks, NIST, or cloud security frameworks.
Understanding of forensic basics such as log analysis, endpoint artifacts, timeline review, and incident evidence handling.
Experience with automation of vulnerability reporting, data cleanup, ticket enrichment, or remediation workflows.
Exposure to AI security, GenAI governance, MCP/connectors, agentic workflows, or AI infrastructure security.
Our Interview Practices
To maintain a fair and genuine hiring process, we kindly ask that all candidates participate in interviews without the assistance of AI tools or external prompts. Our interview process is designed to assess your individual skills, experiences, and communication style. We value authenticity and want to ensure we’re getting to know you—not a digital assistant. To help maintain this integrity, we ask to remove virtual backgrounds and include in-person interviews in our hiring process. Please note that use of AI-generated responses or third-party support during interviews will be grounds for disqualification from the recruitment process.
Applicants may be required to appear onsite at a Wolters Kluwer office as part of the recruitment process.