Flutter International

Vulnerability Manager - Flutter Functions, Hybrid

Flutter International · Cluj-Napoca, Romania

Entertainment Providers · 5,001-10,000 employees

19 h ago
Senior (5-10 yrs) Full-time Romania
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Lead the end-to-end vulnerability management lifecycle across AWS, OCI, and SaaS platforms to drive global security maturity. Partner with engineering and DevOps teams to prioritize remediation, implement automation, and foster a security-first culture.

What they look for

Vulnerability Management AWS OCI Wiz CrowdStrike Falcon Shield SSPM SAST SCA DevSecOps Risk-based Prioritisation Stakeholder Management Cloud Security Automation Threat Intelligence Security Training Incident Analysis SIEM

Requirements

Requires proven experience leading vulnerability programs in complex enterprise environments with deep expertise in Wiz and cloud-native security. Candidates should possess strong influence skills and technical knowledge of SAST, SCA, and risk-based prioritization.

Benefits

Hybrid & remote working options €1,000 per year for self-development Company share scheme 25 days of annual leave per year 20 days per year to work abroad 5 personal days/year Flexible benefits: travel, sports, hobbies Extended health, dental and travel insurances Customized well-being programmes Career growth sessions Udemy online courses Office events

Full description

Vulnerability Manager - Flutter Functions, Hybrid

Flutter is recruiting a Vulnerability Manager to drive the maturity and strategic direction of its vulnerability management programme across a global organisation. This role will take ownership of the end-to-end vulnerability management lifecycle — from identification and prioritisation through to remediation tracking and continuous improvement — while providing technical leadership to engineering, DevOps, and platform teams. The Lead will act as the primary point of contact for vulnerability management across AWS and OCI cloud environments, SaaS platforms, and application code, leveraging tooling including Wiz, Cato, CrowdStrike Falcon Shield SSPM, and code scanning platforms. They will champion a security-first culture by engaging directly with development teams, delivering enablement training, and building automation to scale programme effectiveness. The ideal candidate combines deep technical expertise with strong stakeholder influence skills — able to translate complex vulnerability data into actionable priorities for engineering teams and clear risk narratives for senior stakeholders.

About Betfair Romania Development​:

Betfair Romania Development is the largest technology hub of Flutter Entertainment, with over 2,000 people powering the world’s leading sports betting and iGaming brands. Exciting, immersive and safe experiences are delivered to over 18 million customers worldwide, from our office in Cluj-Napoca. Driven by relentless innovation and commitment to excellence, we operate our own unbeatable portfolio of diverse proprietary brands such as FanDuel, PokerStars, SportsBet, Betfair, Paddy Power, or Sky Betting & Gaming.

Our Values:

The values we share at Betfair Romania Development define what makes us unique as a team. They empower us by giving meaning to our contributions, and they ensure that we consistently strive for excellence in everything we do. We are looking for passionate individuals who align with our values and are committed to making a difference.

Win together | Raise the bar | Got your back | Own it | Positive impact

About Flutter Functions:

The Flutter Functions division is a key component of Flutter Entertainment, responsible for providing essential support and services across the organization. The division encompasses various corporate functions, including finance, legal, human resources, technology, and more, ensuring seamless operations and strategic alignment throughout the company.

Role Overview: Flutter is recruiting a Vulnerability Manager to drive the maturity and strategic direction of its vulnerability management programme across a global organisation. This role will take ownership of the end-to-end vulnerability management lifecycle — from identification and prioritisation through to remediation tracking and continuous improvement — while providing technical leadership to engineering, DevOps, and platform teams.

The Lead will act as the primary point of contact for vulnerability management across AWS and OCI cloud environments, SaaS platforms, and application code, leveraging tooling including Wiz, Cato, CrowdStrike Falcon Shield SSPM,  and code scanning platforms. They will champion a security-first culture by engaging directly with development teams, delivering enablement training, and building automation to scale programme effectiveness.

The ideal candidate combines deep technical expertise with strong stakeholder influence skills — able to translate complex vulnerability data into actionable priorities for engineering teams and clear risk narratives for senior stakeholders.  

Key Accountabilities & Responsibilities:

Leadership & Programme Ownership

  • Lead the vulnerability management programme, setting strategic direction, defining KPIs, and driving measurable remediation outcomes across Flutter globally.
  • Act as the primary liaison between the security team and engineering/DevOps teams, building trusted relationships that translate into tangible vulnerability closure rates.
  • Define and own vulnerability management policies, procedures, playbooks, and SLA frameworks, ensuring they are current, fit-for-purpose, and understood across the organisation.
  • Provide technical mentorship and guidance to junior analysts and wider engineering stakeholders on vulnerability triage, risk rating, and secure remediation approaches.

Vulnerability Identification & Prioritisation

  • Own the end-to-end findings lifecycle using Wiz for cloud vulnerability and misconfiguration identification across AWS and OCI environments.
  • Manage SaaS application misconfiguration and vulnerability findings using CrowdStrike Falcon Shield SSPM, ensuring timely triage and remediation.
  • Analyse findings from code scanning tools (SAST, SCA) and partner with development teams to drive secure-by-design practices within DevSecOps pipelines.
  • Apply risk-based prioritisation using threat intelligence, asset criticality, business context, and exploitability data to focus remediation effort where it matters most.

Remediation Engagement & Enablement

  • Lead direct engagement with development, platform, and DevOps teams to drive vulnerability remediation — providing clear, actionable guidance on fixes, mitigating controls, and configuration changes.
  • Design and deliver targeted security training and awareness sessions for engineering teams, tailored to the vulnerability patterns and tooling relevant to their platforms.
  • Develop and maintain practical remediation runbooks and self-service resources to empower teams to resolve common findings independently.
  • Track patching SLAs, escalate blockers proactively, and report on remediation velocity and trends to senior stakeholders.

Automation & Process Improvement

  • Identify and implement automation opportunities across the vulnerability management lifecycle — including alerting, ticketing, prioritisation workflows, and reporting — to scale programme capability.
  • Continuously improve vulnerability management workflows, tooling integrations (Wiz, Falcon SSPM, SAST/SCA platforms), and prioritisation logic as the programme matures.
  • Build dashboards and reporting mechanisms that provide real-time visibility of vulnerability posture to engineering leads and senior leadership.

Skills, Capabilities & Experience Required:

  • Leadership & Influence: Able to lead without direct authority — building momentum, driving accountability, and influencing engineering and business teams to prioritise security outcomes.
  • Collaborative: Partners effectively with DevOps, engineering, and platform teams across Flutter's global brands, fostering a shared ownership model for security.
  • Strategic Thinking: Connects vulnerability management activities to broader business risk and organisational strategy; able to communicate programme value to executive stakeholders.
  • Adaptable: Navigates complex, fast-moving environments across multiple cloud platforms, toolsets, and organisational structures with confidence.
  • Strategic Communication: Translates technical vulnerability data into clear risk narratives for diverse audiences — from developers to C-suite — and actively listens to understand team constraints and priorities.
  • Objective & Impartial: Applies consistent, data-driven prioritisation criteria; free from bias in risk assessment and escalation decisions.
  • Proven experience leading or owning a vulnerability management programme in a large, complex enterprise environment.
  • Hands-on expertise with Wiz for cloud security posture and vulnerability management across AWS and OCI.
  • Experience with CrowdStrike Falcon Shield SSPM or equivalent SaaS security posture management tooling.
  • Strong track record of engaging directly with development and engineering teams to drive remediation outcomes — including delivering training and producing enablement materials.
  • Experience designing and implementing automation within vulnerability management workflows (e.g., auto-ticketing, prioritisation pipelines, reporting dashboards).
  • Deep understanding of cloud-native vulnerabilities, misconfigurations, and secure architecture patterns (AWS, OCI).
  • Strong working knowledge of SAST, SCA, and DevSecOps pipeline security.
  • Experience with risk-based vulnerability prioritisation using threat intelligence and business context.
  • Familiarity with additional scanning platforms such as Tenable, Qualys, Snyk, or AWS Inspector.
  • Hands-on security incident analysis experience, preferably with Splunk or equivalent SIEM.
  • Knowledge of OWASP tools, methodologies, and secure development frameworks.
  • Experience in regulated or large-scale gaming/fintech environments.
  • Relevant certifications: CISSP, CISM, AWS Security Specialty, or equivalent.

Benefits:

  • Hybrid & remote working options
  • €1,000 per year for self-development
  • Company share scheme
  • 25 days of annual leave per year
  • 20 days per year to work abroad
  • 5 personal days/year
  • Flexible benefits: travel, sports, hobbies
  • Extended health, dental and travel insurances
  • Customized well-being programmes
  • Career growth sessions
  • Thousands of online courses through Udemy
  • A variety of engaging office events

Disclaimer:

We are an inclusive employer. By embracing diverse experiences and perspectives, we create a lasting, positive impact for our employees, customers, and the communities we’re part of. You don't have to meet all the requirements listed to apply for this role. If you need any adjustments to make this role work for you, let us know, and we’ll see how we can accommodate them.

We thank all applicants for their interest; however, only the candidates who best meet the job requirements will be contacted for an interview.

By submitting your application online, you agree that your details will be used to progress your application for employment. If your application is successful, your details will be used to administer your personnel record. If your application is unsuccessful, we will retain your details for a period no longer than three years, to consider you for prospective roles within the company.