Base Career helps you apply smarter for this job.
Key skills for this role
The Vulnerability & Incident Response Analyst will play a key role in supporting HBK's Product Security function by coordinating product vulnerability management activities, security incident reporting obligations, and cross-functional remediation efforts. The role acts as a central liaison between Product Security, Dev SecOps, and Product Teams to ensure vulnerabilities are effectively assessed, tracked, remediated, and reported in accordance with internal policies and regulatory requirements, including the EU Cyber Resilience Act (CRA).
The Vulnerability & Incident Response Analyst will play a key role in supporting HBK's Product Security function by coordinating product vulnerability management activities, security incident reporting obligations, and cross-functional remediation efforts. The role acts as a central liaison between Product Security, Dev SecOps, and Product Teams to ensure vulnerabilities are effectively assessed, tracked, remediated, and reported in accordance with internal policies and regulatory requirements, including the EU Cyber Resilience Act (CRA).
Perform initial triage, validation, and analysis of product vulnerabilities identified through vulnerability disclosures, internal testing, security assessments, penetration testing, or automated scanning tools.
Assess vulnerability severity using CVSS, exploitability, product applicability, and business impact criteria.
Review vulnerability reports and collaborate with product teams to determine applicability, exploitability, and remediation requirements and help to prioritize the vulnerabilities that need to be addressed considering the Risk.
Maintain accurate vulnerability records, evidence, and audit trails to support governance and compliance requirements.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Great Malvern, GBR
Great Malvern, GBR
Mumbai, IND
Chennai, IND
, IND
Bengaluru, IND
, IND
Chennai, IND
Support coordination of security incident and exploited vulnerability reporting activities in accordance with applicable regulatory obligations.
Prepare and maintain the information required for regulatory notifications, working closely with Product Security, Legal, and Product Teams.
Track incident reporting timelines and ensure escalation activities are completed within defined regulatory timeframes.
Support incident readiness exercises and reporting process validation activities.
Monitor vulnerability disclosure channels, PSIRT mailboxes, public vulnerability disclosures, security advisories, and relevant threat intelligence feeds.
Identify vulnerabilities and emerging threats that may impact HBK products and coordinate investigations with relevant stakeholders.
Track Known Exploited Vulnerabilities (KEVs), industry alerts, and security advisories relevant to HBK products and technologies.
Maintain awareness of evolving cybersecurity threats, attacker techniques, and regulatory developments.
Prior experience of Bug bounty portals will be an added advantage.
Coordinate remediation activities with Product Teams, Dev Secops, and Product Security stakeholders.
Track vulnerability remediation progress against defined remediation targets and service level objectives.
Support review of proposed security updates, patches, and mitigation plans.
Produce vulnerability status reports, metrics, and management updates to support governance forums and programme tracking.
Serve as the operational liaison between Product Security, Dev SecOps, Customer Support, Legal, and Product Teams.
Facilitate communication and issue resolution across stakeholders involved in vulnerability management and incident response activities.
Support the implementation and continual improvement of vulnerability management and coordinated vulnerability disclosure processes.
Contribute to regulatory readiness initiatives associated with the EU Cyber Resilience Act and related cybersecurity requirements.
Bachelor’s or master’s degree in cyber security, Computer Science, Information Security, Software Engineering, or a related technical discipline.
Experience working within a Product Security Incident Response Team (PSIRT).
Exposure to regulatory reporting obligations and coordinated vulnerability disclosure programmes.
Experience with vulnerability management automation, DevSecOps pipelines (SAST, DAST integration), SBOM tooling, or software composition analysis platforms.
Familiarity with cloud, desktop, SaaS, embedded, or industrial control system products.
Knowhow on Penetration testing
Private UK precision-measurement company supplying high-tech instruments, test equipment and software to demanding industrial customers.
Visit company websiteJobs and hiring trendsFull-time
Mid
Remote
Apply faster on company sites with our extension.