The analyst will coordinate product vulnerability management, security incident reporting, and cross-functional remediation efforts. They act as a central liaison between Product Security, DevSecOps, and product teams to ensure compliance with internal policies and regulatory requirements like the EU Cyber Resilience Act.
Role Summary
The Vulnerability & Incident Response Analyst will play a key role in supporting HBK's Product Security function by coordinating product vulnerability management activities, security incident reporting obligations, and cross-functional remediation efforts. The role acts as a central liaison between Product Security, Dev SecOps, and Product Teams to ensure vulnerabilities are effectively assessed, tracked, remediated, and reported in accordance with internal policies and regulatory requirements, including the EU Cyber Resilience Act (CRA).
Key Responsibilities
Vulnerability Triage & Analysis
Perform initial triage, validation, and analysis of product vulnerabilities identified through vulnerability disclosures, internal testing, security assessments, penetration testing, or automated scanning tools.
Assess vulnerability severity using CVSS, exploitability, product applicability, and business impact criteria.
Review vulnerability reports and collaborate with product teams to determine applicability, exploitability, and remediation requirements and help to prioritize the vulnerabilities that need to be addressed considering the Risk.
Maintain accurate vulnerability records, evidence, and audit trails to support governance and compliance requirements.
Incident & Regulatory Reporting Coordination
Support coordination of security incident and exploited vulnerability reporting activities in accordance with applicable regulatory obligations.
Prepare and maintain the information required for regulatory notifications, working closely with Product Security, Legal, and Product Teams.
Track incident reporting timelines and ensure escalation activities are completed within defined regulatory timeframes.
Support incident readiness exercises and reporting process validation activities.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”