Welcome to the team:
Senior Vulnerability Analyst (m/f/diverse)

    Your tasks

    • Serving as subject-matter expert in vulnerability management with deep expertise in at least one technology domain (e.g. infrastructure, workplace, networks, applications);
    • Analysing and interpreting vulnerability and configuration scan results in depth;
    • Deriving risk-based recommendations and prioritisation for remediation
    • Guiding technical teams towards sustainable remediation and hardening measures;
    • Working closely with infrastructure and application owners, Cyber Hygiene Governance and Security Problem Management;
    • Supporting the design and continuous improvement of treatment patterns, security baselines and KPIs;
    • Playing a key role in major remediation initiatives and emergency patch activities;
    • Contributing to improving the bank’s cyber hygiene and reducing overall cyber risk through strong technical expertise, structured analysis and clear communication.

    Your profile

    • 5+ years of relevant professional experience in vulnerability management, cyber security or closely related IT security roles, ideally in regulated environments (banking, financial services or critical infrastructure).
    • Deep understanding of vulnerabilities, exploitation techniques and defensive measures, ideally aligned with frameworks such as MITRE ATT&CK.
    • Strong expertise in at least one major technology domain (e.g. infrastructure, endpoints, network or applications) and practical experience with cloud and container environments (e.g. AWS/Azure/GCP, security groups, Kubernetes, Docker image vulnerabilities).
    • Excellent analytical, conceptual and strategic thinking skills; ability to quickly understand complex technical situations and derive clear, risk-based actions.
    • Strong communication skills, including the ability to explain complex technical topics in a clear and understandable way to non-technical stakeholders and senior management.
    • High customer- and service-orientation, strong ownership mentality and persistence in driving remediation measures to completion.
    • Proven experience in cross-functional collaboration with IT operations, application teams, security functions, governance and risk management.
    • Very good English skills (spoken and written); German is a plus but not mandatory;

    In return, we offer:

    • Good work-life balance, including 25 days annual paid leave (increasing with 1 day per year up to 31 in total), flexible working hours, work-from-home and work from abroad opportunities;
    • Luxury package of additional health and dental insurance;
    • Food vouchers in the amount of EUR 80 monthly;
    • 6 additional annual days off for exceptional circumstances
    • Employee assistance program for psychological, financial and legal consultations;
    • Multisport card;
    • Annual contribution of EUR 153.39 net per child for a summer camp/school/kindergarten for children up to age of 15;
    • Possibilities for building career-advancing skills by covering training/certification courses and conferences based on individual learning and development needs, access to an online learning platform;
    • Opportunities for long-term professional development in a stable, 150-year-old company while contributing to the vision of a new, just starting Digital Technology Center;
    • Friendly and supportive multicultural environment, open to new opinions and ideas.

    Commerzbank is proud to be an equal opportunity employer, committed to creating a diverse environment. All qualified applicants will receive consideration for employment without regard to gender, race, color, national origin, religion, gender identity or expression, sexual orientation, genetics, disability, age, or any other characteristics.

    Our Benefits

    • Work internationally
    • Work-life balance
    • Health& Dental Insurance
    • Multisport Card
    • 25 up to 31 annual paid leave
    • 6 Exceptional Days Off
    • Food vouchers
    • Employee assistance program
    • Children Summer Camp Contribution
    • Learning Platforms

    Work internationally; Work-life balance; Health& Dental Insurance; Multisport Card; 25 up to 31 annual paid leave; 6 Exceptional Days Off; Food vouchers; Employee assistance program; Children Summer Camp Contribution; Learning Platforms

    The company

    Commerzbank is a leading international commercial bank with branches and offices in almost 50 countries. The world is changing, becoming digital, and so are we. We are leaving the traditional bank behind us and we are choosing to move forward as a digital enterprise.

    As part of this strategy, Commerzbank continues the expansion of its Digital Technology Center in Sofia, Bulgaria. We need motivated people who will join us on this journey and we are looking for a Vulnerability Analyst in our Cyber Defense and Base Services team.

    Cluster Cyber Defense & Base services provides 1. LoD activities within the Commerzbank Cyber Security Organization. In addition, to these operational topics the cluster also develops and operates a variety of security tools which are used by the operational units SOC and Threat Intelligence.

    In the Cluster Organization, business analysts, engineers and product owners work together as a team. The agile methods support the team members in performing their functions by facilitating a rapid and flexible response to changing conditions and customer needs through an iterative approach and the continual development of new solutions resulting into better products, higher quality, and more efficient processes.

    The team works together to ensure that valuable functionalities are provided to customers and that existing products, processes and services are developed and improved in line with customer needs. To achieve this, the team members organize their own activities, working autonomously and with full accountability. Open communication and feedback are key to adopt a fail-fast approach – recognize mistakes and move forward in the right direction.

    Contact

    Apply now with your up-to-date CV in English!

    Due to the high volume of applications, we contact only the candidates who best match the role requirements. If you do not hear from us within 14 days, please consider that we won't proceed with your application at this stage.