IC

Vulnerability Management Specialist - Assistant Vice President

iCapital
Lisbon, Portugalfull_timePosted 24 Jun 2026

About the role

<p> </p> <p>iCapital is looking for a AVP Engineer to join the Information Security team. This role will help establish and run Vulnerability and Exposure Management practices, build structured remediation processes, support application security activities, and continuously identify and reduce risk across iCapital technology. The ideal candidate is a hands-on individual contributor who can implement and improve processes, work directly with developers and drive remediation execution at scale.</p> <p><span data-teams="true"> </span></p> <p><strong>Responsibilities</strong></p> <ul> <li>Build and manage Vulnerability and Exposure Management processes, providing continuous monitoring, prioritisation, and resolution of vulnerabilities across the environment.</li> <li>Implement and drive remediation of vulnerabilities and security weaknesses.</li> <li>Collaborate with engineering teams to improve workflows, adopt best practices, and drive consistent remediation standards.</li> <li>Build automation capabilities to ingest, track and report vulnerabilities and exposures.</li> <li>Evolve and improve exposure management capabilities, including prioritization based on risk, attack paths, and business impact.</li> <li>Build processes and automation capabilities for application security workflows, including SAST, SCA, secrets and API security in collaboration with developers.</li> <li>Review and validate penetration testing findings and ensure effective remediation.</li> <li>Work directly with developers to explain vulnerabilities, agree remediation approaches, and validate fixes.</li> <li>Support threat modelling activities to identify risk earlier in the design phase.</li> <li>Assist the SOC in improving detection and alerting capabilities based on identified vulnerabilities and exposures.</li> <li>Develop workflows for vulnerability intake, triage, remediation tracking, and reporting across tools.</li> <li>Assist Risk and Governance teams with policies, procedures, standards, and audit evidence.</li> <li>Collaborate with cross-functional teams, including Engineering and Security, to deliver security improvements.</li> </ul> <p> </p> <p><strong>Qualifications</strong></p> <ul> <li>Experience in Vulnerability Management, Exposure Management, or Application Security.</li> <li>Strong understanding of web and API security risks.</li> <li>Experience reviewing and validating penetration testing findings.</li> <li>Experience working with developers.</li> <li>Experience with scripting and automation, preferably Python.</li> <li>Experience with development workflows, systems engineering a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Generate Application Kit

Free account required — sign up in 30s

Company

iCapital

View all open roles →