Specialist, Posture & Exposure Management
Katowice, PL
Defend the Future of Sustainable Steel as a Cyber Security Specialist!
About Us
Outokumpu is accelerating the green transition as the global leader in sustainable stainless steel. Our business is rooted in the circular economy: our products are made from 95% recycled materials and are fully recyclable. Our stainless steel is used across society—from infrastructure and mobility to household appliances.
We are committed to the 1.5°C climate target and, with up to 75% lower carbon footprint than the industry average, we help our customers reduce their emissions.
Together, we are working towards a world that lasts forever. Outokumpu employs approximately 8,200 professionals in close to 30 countries, with headquarters in Helsinki, Finland, and shares listed on Nasdaq Helsinki. Learn more at www.outokumpu.com.
Your key responsibilities include:
- Defining and executing a comprehensive security posture strategy across both IT and OT environments, shifting the focus from simple vulnerability scanning to holistic exposure management.
- Managing end-to-end vulnerability lifecycle operations across IT infrastructure, OT systems, and web applications utilizing enterprise vulnerability management platforms and application security testing suites.
- Mapping and monitoring the attack surface (EASM & IASM) to identify external and internal blind spots, collaborating closely with threat hunting teams.
- Governing OT and supplier security postures, including hosting security governance meetings with unmonitored vendors and suppliers.
- Optimizing Cloud Security Posture Management (CSPM) by continuously monitoring and improving our security and compliance posture scores in the cloud.
- Validating security controls and exposures through continuous automated testing and breach simulation platforms to prove threat resilience.
- Mentoring and supporting team members, actively fostering a culture of knowledge sharing, continuous growth, and collective skill development across the security team.
What we expect from you:
- Suitable academic degree in Cybersecurity, Computer Science, or a related field, alongside several years of hands-on experience in vulnerability, exposure, or attack surface management.
- A highly curious and growth-oriented mindset, with a natural drive to continuously learn, experiment, and stay ahead of the rapidly evolving threat landscape.
- A collaborative team player with a positive, constructive attitude and a genuine desire to help others succeed and grow.
- Strong technical expertise with enterprise security tools, particularly vulnerability scanners, attack surface mapping tools, and cloud security suites.
- Solid understanding of OT security frameworks and experience with specialized industrial control systems (ICS/OT) monitoring tools.
- Experience in web application security testing, including familiarity with web application scanners and crowdsourced security/bug bounty models.
- Proven stakeholder management skills, with the ability to lead governance conversations with external suppliers and vendors.
- Strong analytical mindset with the ability to translate technical exposures into actionable remediation plans for IT and business teams.
Please note: Benefits may vary depending on your location and local employment terms.
📬 Application
Please send your CV in English.
We appreciate your interest in joining our team and thank all applicants for their submissions. Only selected candidates will be contacted. We look forward to receiving your application!