Jobs Companies Piraeus Bank Cyber Threat & Vulnerability Analyst

Sobre este puesto de Cyber Threat & Vulnerability Analyst en Piraeus Bank

Piraeus Bank · Presencial · Athens, Attica, Greece

About us

In Piraeus our purpose is to be a pillar of stability for the Greek economy, to fuel growth and to promote innovation. We aim our footprint in society to be positive and lasting, for the benefit of our customers, our people, our shareholders and society at large, fully reflecting our values. In this way we express in practice our will to: create value in all we do, challenge the frontiers, enthuse our customers and build relationships of trust.

Piraeus is the leading financial institution in Greece, in terms of domestic market shares in loans, deposits, and branch presence. The Group provides a comprehensive range of financial products and services to 4.5mn customers, with recognized leadership in SME banking, retail banking, digital banking, insurance and capital markets.

In 2026, Piraeus was recognized at the Euromoney Awards for Excellence as Europe’s Best Bank for Corporate Social Responsibility, Greece’s Best Bank for ESG, Greece’s Best Retail Bank and Greece’s Best Bank for Large Corporates, and by the Banker as the “Best Bank in Greece” for Growth and for Liquidity at the prestigious Bank of the Year Awards, reflecting our ongoing commitment to responsible banking and sustainability.

About the Job

We are looking for an experienced Cyber Security professional to take ownership of Threat & Vulnerability Management across the Group's technology estate. In this role you will drive the Bank's Threat & Vulnerability Management framework end to end, from the discovery of vulnerabilities and exposures through risk-based prioritisation, remediation governance and assurance, setting the methodology and standards that infrastructure, cloud and application teams follow. You will act as the technical reference point for vulnerability and offensive security testing matters, provide direction to engineers and external specialists working in the domain, and represent the function to senior management, internal audit and supervisory authorities.

Responsibilities:

  • Lead the continuous evolution of the Bank's Threat & Vulnerability Management framework, covering the identification, assessment, prioritization, remediation and monitoring of security exposures across infrastructure, cloud, applications, containers, databases and end-user platforms.
  • Coordinate the development and continuous enhancement of the risk-based prioritization methodology, combining technical severity (CVSS), exploitation likelihood (EPSS) and confirmed active exploitation (CISA KEV) with asset criticality and technical exposure, and maintain the scoring model, escalation rules and remediation SLAs.
  • Define and maintain the annual security testing and scanning plan, including scope, method (authenticated, unauthenticated, agent-based and continuous scanning) and frequency, ensuring full coverage of the ICT asset estate and the enhanced scanning cadence required for critical or important functions under DORA.
  • Analyze vulnerability intelligence, threat trends and exploit activity, assess the Bank's exposure to emerging and zero-day vulnerabilities, and recommend emergency escalations, priority overrides and interim mitigations where required.
  • Drive remediation with infrastructure, cloud, application and technology teams, consolidating findings into remediation campaigns with clear ownership, and monitor remediation performance against agreed SLAs and backlog reduction targets.
  • Govern the vulnerability exception process, assessing risk acceptance requests, compensating controls and expiry dates, and escalating residual risk to the appropriate governance bodies.
  • Drive the execution of Attack Surface Management (ASM/EASM) and Exposure Management initiatives to improve visibility of the internal and external attack surface and reduce cyber risk.
  • Coordinate the integration of security assessment results into the vulnerability lifecycle, including SAST, DAST, SCA, container scanning, red team and penetration testing findings, and validate exploitability and the effectiveness of remediation through hands-on verification and re-testing.
  • Manage the penetration testing programme and third-party security assessment providers, from scoping and quality review of deliverables through to findings management, retesting and periodic vendor rotation, and support threat-led penetration testing (TLPT) exercises.
  • Define the domain's metrics, KPIs and KRIs (open critical, high and KEV vulnerabilities, SLA compliance, mean time to remediate, overdue campaigns, active exceptions) and produce reporting for senior management and the Board.
  • Shape and drive the evolution of the tooling roadmap for vulnerability, exposure and attack surface management, including platform selection and rollout, integration with CMDB and ticketing, automation, and continuous improvement of asset coverage and data quality.
  • Ensure that ICT third-party providers apply vulnerability and patch management controls of an equivalent standard and drive ongoing assurance over their remediation performance.
  • Act as the domain point of contact for internal and external audits, regulatory inspections and supervisory requests, providing evidence and driving the closure of related findings.
  • Provide technical guidance and mentoring to engineers and external specialists working on vulnerability management activities and promote high-quality and consistent delivery across the domain.

Requirements

  • BSc degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • MSc degree in a relevant discipline will be considered an asset.
  • 5-8 years of working experience in Cyber Security, Vulnerability Management, Offensive Security, Security Operations or Security Engineering, including demonstrable experience acting as technical owner of a security domain.
  • Deep hands-on experience with enterprise vulnerability management platforms such as Qualys, Tenable, Rapid7 or Microsoft Defender Vulnerability Management, including deployment, tuning, authenticated scanning and asset coverage management.
  • Strong understanding of enterprise infrastructure, networking, operating systems, virtualization, and cloud technologies.
  • Proven experience designing and operating Risk-Based Vulnerability Management, including scoring models, prioritisation logic, remediation SLAs and exception governance.
  • Strong command of CVEs, CVSS, EPSS, MITRE ATT&CK, CISA KEV, threat intelligence and exposure management concepts, and the ability to translate them into defensible prioritisation decisions.
  • Hands-on experience across Windows, Linux, cloud environments (preferably Microsoft Azure), databases, containers, Kubernetes and network technologies.
  • Understanding of Secure SDLC and application security practices, including OWASP Top 10 and OWASP ASVS.
  • Familiarity with regulatory and security frameworks such as DORA, NIS2, ISO 27001, PCI DSS, CIS Benchmarks and NIST CSF, and experience operating under regulatory and audit scrutiny.
  • Experience with Exposure Management platforms (Qualys ETM, Kenna, XM Cyber, Brinqa, Nucleus, Cisco Vulnerability Management), will be appreciated.
  • Experience with Attack Surface Management (ASM/EASM), will be appreciated.
  • Knowledge of Threat Intelligence, SIEM, and SOAR platforms, will be appreciated.
  • Professional certifications such as CISSP, CISM, GSEC, GCIH, GCIA or vendor certifications (e.g. Qualys), will be appreciated.
  • Hands-on offensive security experience, such as penetration testing, exploit validation, red teaming or purple teaming, together with the ability to challenge and quality-review third-party test results, will be strongly appreciated.
  • Offensive security certifications such as OSCP, OSEP, OSWE, GPEN, GXPN or CRTO, will be strongly appreciated.
  • Experience with scripting and automation (Python, PowerShell) and with reporting or BI tooling for security metrics, will be appreciated.
  • Strong stakeholder management and communication skills, with the ability to present technical risk to senior management and to challenge technology teams constructively.
  • Experience in guiding, mentoring or coordinating technical teams and external providers, will be appreciated.

Benefits

In our bank it is a top priority to provide a modern work environment, where all our employees can perform and grow. As an employee of Piraeus Bank, you will be part of an organization that:

  • Holds a leading position in the Greek economy and maintains a robust presence in the community
  • Instills a workplace culture that embraces open communication, respect, inclusion and equal opportunities
  • Offers a competitive remuneration package, private health insurance program and other benefits for both employees and their families
  • Provides a challenging working environment that values accountability and celebrates high performance by implementing appropriate incentives
  • Empowers personal & career development and continuous learning while encouraging creative thinking and innovation
  • Provides an all-bank wellbeing program, fostering initiatives that enhance physical, mental & emotional health
  • Provides digital technologies and tools that fully support new ways of working and flexible working options, while communicate regularly and effectively

All applications will be treated with confidentiality.

Application Deadline : 24/08/2026

 

¿Listo para postularte en Piraeus Bank?
Postúlate en Piraeus Bank

Sobre Piraeus Bank

WHAT WE DO

Headquartered in Athens and with approximately 11.1 thousand employees, Piraeus Bank offers a full range of financial products and services to 5.5mn customers in Greece. The Group's total assets stood at €61.2bn on 31.12.2019.

Piraeus Bank leads a group of companies covering all financial activities in the Greek market.

Today, we rank first in business financing, with a market share of 32% and balances of c.€30bn. Piraeus Bank possesses particular expertise in the areas of medium-sized and small enterprises, agricultural banking, consumer and mortgage credit, green banking, capital markets and investment banking, as well as leasing and factoring.

These services are offered through a nation-wide network of 527 branches and 1,913 ATMs of the Bank in Greece, as well as through its innovative digital banking platform, winbank.

Piraeus Bank strives to differentiate itself with the provision of superior standards of customer service by adopting the most modern international innovations and technological solutions. In this context, an automated electronic branch, known as "e-branch", was set up and has been operating since 2016. This is a completely new concept for the Greek market. Piraeus Bank currently operates 10 e-branches in which transactions are carried out with speed, convenience and security.

WHAT WE STAND FOR

Piraeus Bank has established a unified culture based on the principles of accountability, meritocracy and transparency, aiming to be a pillar of stability for the Greek economy, to fuel growth and to promote innovation. Focusing on having a positive and lasting footprint in society, with benefits for our customers, our people, our shareholders and society, Piraeus Bank is committed to constantly create value, to challenge the frontiers, to enthuse its customers and to build relationships of trust.

As Piraeus Bank acknowledges the basic role held by human resources in the achievement of its corporate strategic goals and the management of challenges, it invests in the creation of strong relations with its employees, constantly improving the working environment and minimizing risks. It works towards a modern working environment that promotes open communication, high performance, and personal development for its people. At the same time, the Group makes sure to establish and implement policies that promote issues of ethics, trust, devotion, team spirit and acceptance of diversity in the workplace. Piraeus Bank employs approximately 11,100 employees, being one of the largest employers in Greece.

Piraeus Bank is committed to including social, environmental, and cultural aspects into its business practices and assumes initiatives over and above the legal obligations with the aim of enhancing social welfare and sustainable development.

In the framework of its activities and operations, the Group promotes regular communication with stakeholders, in order to fulfill their needs and expectations and to promptly and effectively respond to issues concerning them. The protection of their personal data, the use of new technologies to better serve their needs, the respect for human rights, the accessibility to financial services and the respect for the environment and culture as factors contributing to sustainable development, as well as issues related to corporate culture and corporate governance, value creation for the society and risk management, are strategic priorities for the Group.

Piraeus Bank is the only Greek bank to actively participate in the shaping of the global Principles for Responsible Banking, along with other 29 banks from around the world, members of the United Nations Environment Programme Finance Initiative – UNEP FI. The Principles set the global standard for what it means to be a responsible bank and will ensure that banks create value for both their shareholders and society. They provide the first global framework that guides the integration of sustainability across all business areas of a bank, from strategy to product portfolio management and transactions.

The goals for sustainable development, social contribution, and responsible banking behavior are fundamental components of Piraeus’ strategy, and resonate well with its business model and shared values of accountability, meritocracy and transparency.

CANDIDATES

We aim to attract and retain high qualified workforce that share Piraeus Bank Group’s Vision and Values. We select people in whom we see the ability to develop and significantly contribute to the Group’s growth and development.

In Piraeus Bank Group, we rate as successful the selection of candidates, characterized by team spirit, initiative, and respect, great sense of responsibility, ethos and professionalism. Recruiting and Selection is based on the Principle of equal opportunities regardless of sex, race, age, religion, color, nationality, sexual orientation or physical ability.

Ver todos los empleos en Piraeus Bank →

Empleos similares

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Piraeus Bank

Ver todos los empleos en Piraeus Bank →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis