About this Vulnerability Response Specialist role at Two95 International Inc.
Key Responsibilities
Vulnerability Response Management
• Assume operational ownership of notable vulnerabilities following VA assessment and prioritisation.
• Drive end-to-end response activities for zero-day, out-of-band (OOB), actively exploited, and other high-profile vulnerabilities.
• Coordinate cross-functional stakeholders to execute mitigation and remediation activities.
• Establish and lead vulnerability response bridges, action tracking, and escalation activities.
• Drive execution of vulnerability response playbooks and response procedures
• Maintain continuous oversight of vulnerability response activities until risk mitigation or remediation is completed.
Incident Management & Stakeholder Coordination
• Leverage Incident Management processes to accelerate remediation and stakeholder mobilisation.
• Coordinate Cyber Defence, Platform Teams, Asset Owners, Technology SMEs, and Incident Management teams during vulnerability events.
• Drive stakeholder communications, executive updates, situation reporting, and escalation activities.
• Escalate critical risks, blockers, and delayed remediation activities through appropriate governance channels.
• Support post-incident reviews and continuous improvement initiatives.
Remediation Oversight
• Drive remediation activities through to closure, ensuring accountability and timely execution.
• Track remediation commitments, milestones, dependencies, and residual risks.
• Challenge and escalate overdue actions where required.
• Validate completion of agreed mitigation and remediation actions.
• Support management reporting on remediation progress and risk reduction outcomes.
24x7 Vulnerability Response Coverage
• Participate in on-call, weekend, after-hours, and follow-the-sun support arrangements.
• Provide operational coordination during high-severity vulnerability events outside standard business hours.
• Support continuous vulnerability response coverage for critical cyber threats.
• Ensure timely stakeholder mobilisation during active exploitation and major vulnerability incidents.
Key Skills & Experience
Vulnerability Management
• Strong understanding of vulnerability management concepts, CVE, CVSS, exploitability assessment, threat intelligence, and cyber risk management.
• Ability to understand vulnerability assessments and translate risk into actionable remediation plans.
• Knowledge of vulnerability prioritisation, attack surface exposure, and threat landscape trends.
Incident & Crisis Management
• Experience coordinating Major Incident, Cyber Incident, or Technology Incident response activities.
• Strong understanding of escalation management, crisis communications, and stakeholder coordination.
• Experience leading bridge calls, action tracking, executive reporting, and operational response activities
Remediation Governance & Oversight
• Experience driving remediation activities across multiple technology and infrastructure teams.
• Understanding of remediation governance, risk reduction strategies, compensating controls, and risk treatment plans.
• Ability to influence stakeholders and drive accountability for remediation outcomes.
Professional Competencies
• Strong problem-solving skills with the ability to analyse complex cyber risk scenarios, identify response strategies, and drive issues to resolution.
• Excellent communication and stakeholder management skills with the ability to engage technical teams,
senior management, and incident stakeholders during high-pressure situations.
• Strong analytical capability with experience interpreting and correlating large volumes of vulnerability, threat intelligence, asset inventory, remediation, and operational data to support risk-based decision making.
• Ability to translate technical vulnerability information into clear business risk, operational impact, and remediation priorities.
• Up-to-date knowledge of vulnerability management practices, emerging threats, vulnerability intelligence, exploit trends, and cyber threat landscape developments.
• Self-driven, proactive, and capable of operating independently within a fast-paced 24x7 response
environment.
• Strong execution focus with the ability to coordinate multiple stakeholders and drive timely remediation outcomes.
• Ability to remain calm under pressure and make sound decisions during critical cyber events.
• Comfortable working in ambiguous situations and making risk-based decisions with incomplete
information.
• Highly collaborative with a strong sense of ownership and accountability.
Preferred Experience
• 5–8 years of experience in Vulnerability Management, Security Operations, Incident Response,
Technology Risk, Cyber Defence, or related cyber security disciplines.
• Experience supporting 24x7 security operations, on-call rotations, or major incident management
activities.
• Experience managing critical cyber incidents, zero-day vulnerabilities, and actively exploited threats.
• Experience working within a highly regulated environment such as financial services.
