Cyber Vulnerability Management Analyst (1 Year Project Based)
Henkel
Metro Manila, Philippines
Posted on Mar 6, 2026
About this Position The Cyber Vulnerability Management Analyst plays a key role in strengthening Henkel’s global cyber resilience by helping ensure that security vulnerabilities across our IT, OT, and Cloud environments are identified, understood, and resolved on time. This position supports the full vulnerability management lifecycle and helps safeguard the systems that enable Henkel’s digital operations worldwide. In this role, you’ll gain hands-on experience across multiple technology domains, contributing to real-time risk reduction and supporting critical decisions during high‑priority security events. This is an excellent opportunity for early-career cybersecurity professionals who want exposure to diverse environments, clear responsibilities, and the chance to make a visible impact on Henkel’s security posture.
What You´ll Do
What You´ll Do
- Conduct regular vulnerability scanning and validate results across IT, OT, and Cloud environments, ensuring accuracy of impacted systems, severity, and recommended fixes
- Support assessment of vulnerability criticality using CVSS, exploit intelligence, and internal risk scoring methods
- Coordinate with infrastructure, OT engineering, cloud, DevOps, and application teams to drive timely remediation, patching, and hardening
- Track vulnerability remediation progress, monitor SLA deadlines, escalate overdue items, and document risk acceptances
- Prepare vulnerability dashboards, metrics reports (e.g., scan coverage, aging, overdue items), and compliance/audit-related documentation
- Maintain up‑to‑date vulnerability management procedures, scanning scope, and remediation workflows, contributing to playbooks and knowledge bases
- Assist with communication of high‑priority or emergency patch requirements and translate technical findings into clear business‑friendly language
- Bachelor's Degree in Computer Science, IT, Engineering, or related courses
- Minimum of three (3) years of experience in IT, cybersecurity, application support, or software‑related roles; experience working with global or regional stakeholders is a plus
- Foundational understanding on common security concepts (e.g. CIA, vulnerability, threat, risk), vulnerability management, and typical application security weaknesses
- Must have a strong foundation in IT, OT, and Cloud security, with hands‑on experience using vulnerability assessment tools and interpreting scan results; Experience in ITIL Foundation, CEH/ISSP, and SIEM tools
- Excellent communication, collaboration, and coordination skills, with the ability to work effectively with technical and non‑technical stakeholders
- High level awareness on OWASP Top 10 and common languages (e.g., Java, JavaScript, Python)
- Amenable to report on a mid-shift schedule (11:00 AM to 8:00 PM) and hybrid set-up in Ayala Avenue, Makati City
- A thriving career with the Top 15 Best Workplaces in the Philippines by Great Place to Work and the Top GBS Employer in the Philippines by the Everest Group for 4 consecutive years!
- Flexible work scheme with flexible hours, hybrid work model, and work from anywhere policy for up to 30 days per year
- Diverse national and international growth opportunities
- Global wellbeing standards with health and preventive care programs
- Gender-neutral parental leave for a minimum of 8 weeks
