Cyber Exposure Management Expert (m/w/d)
Nviso · 🌍 Frankfurt am Main
Sponsorship verdict
No sponsorship evidence yet
No government record and no wording either way. Not a refusal — ask the recruiter.
- No government sponsor record hereThis employer posted directly and does not match a government sponsor register.
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- Can’t check pay against the visa rulesNo salary stated. Germany EU Blue Card needs at least €50,700 a year (shortage-occupation / recent-graduate: €45,934). Source: https://www.make-it-in-germany.com/en/visa-residence/types/eu-blue-card, rules effective 2026-01-01.
- Confirmed live todayWhen a source last listed this job as open.
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Why not apply?
No register record and no sponsorship wording in the posting. Worth asking the employer before investing significant time.
SponsorApply flags time-wasters so your applications go where they can land. These come from the posting's own wording — read the original listing to confirm. See better-fit alternatives →
Sponsor Radar — Nviso
This employer posted directly and does not match a government sponsor register.
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Nviso →
About the role
It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks. This means we offer cyber security services to private and governmental organizations to help them better prepare for, prevent, detect and respond to cyber security incidents. All of this is built on four fundamental values that define who we are: We are Proud, We Break Barriers, We Care and No BS! Tasks As Cyber Exposure Management Expert (m/w/d) located in Germany, you will be the technical lead for developing NVISO's Cyber Exposure offering. You will define how Vulnerability Management, Asset Management, hardening, Patch Management, reporting and remediation work together through clear processes and responsibilities, and guide the technical decisions that make the service work for our clients. You will be the expert clients and colleagues turn to for the complete picture: which assets matter, where they are exposed, who needs to act and whether remediation has worked. You will design the processes, integrations and reporting that connect these questions, lead complex customer engagements and help other consultants deliver the service. You will advise on hardening and help clients establish ownership, remediation targets and a process that fits their IT operations. You will also shape what we build next. Starting from our existing Vulnerability Management capabilities, you will develop the technical roadmap towards Continuous Threat Exposure Management (CTEM) and assess where Attack Surface analysis, exposure validation and Quantum Readiness belong in the offering. This gives you room to propose solutions, build prototypes and test them with clients before turning them into repeatable services. Typical responsibilities include: • Defining the technical architecture and delivery approach for the Cyber Exposure offering, connecting Vulnerability Management, Asset Management, hardening, Patch Management, reporting and remediation, with clear roles and governance; • Leading technical delivery on customer engagements, advising on remediation and hardening, resolving design and integration problems and reviewing the quality of our work; • Linking vulnerability findings to asset inventories, CMDBs, cloud environments, business services and owners, and resolving gaps in coverage and data quality; • Designing remediation processes with owners, priorities, SLAs, escalation, risk acceptance and closure checks, aligned with Change Management and supported by ITSM, Patch Management and other remediation solutions; • Building reporting that shows clients their exposure and remediation progress, with clear priorities for technical teams and reliable measures of coverage, ageing, SLA performance and accepted risk for management; • Advising on secure configurations and hardening baselines for infrastructure and cloud environments, reducing unnecessary exposure and proposing compensating controls when patching is not immediately possible; • Keeping up with developments in Exposure Management and evaluating AI and agentic solutions through targeted pilots to improve existing approaches to prioritization, remediation guidance and reporting. You will test accuracy and usefulness, protect client data and define human oversight, including approval before AI recommendations trigger remediation actions; • Turning client needs into service packages, technical standards and delivery methods, coaching consultants and providing technical input for proposals and scoping; • Developing the service roadmap and evaluating new capabilities through pilots, including CTEM, Attack Surface analysis and cryptographic discovery, Crypto Agility and Post Quantum Cryptography migration planning. You will help decide which capabilities are rea