Czabán Tamás
@czaban_tamas
Vulnerability management analyst building security automation that turns slow triage into minutes-fast remediation.
What I'm looking for
I build security automation that cuts response time from hours to minutes, and I apply the same discipline to both internal vulnerability operations and public open vulnerability data. At Citi, I run vulnerability management end-to-end—covering triage, investigation, remediation tracking, and incident response on L0 GEM deadlines—while shipping the Python tooling the team uses daily.
I track vulnerabilities through closure across the enterprise asset estate and communicate risk findings to engineers and director-level stakeholders. I lead incident response when the clock is on, like parsing affected app versions with Python automation and clearing a 48-hour deadline without chase emails.
I focus heavily on operational impact: I built an automated per-app-manager Email Composer during an Apache Tika XXE L0 GEM and an Oracle HTTP Server RCE L0 GEM, replacing manual workflows (~4 hours) with a 12-minute pipeline. I also deliver data products such as the Firewall & Load Balancer Vulnerability Dashboard and the GEM Dashboard, using efficient caching and filter-aware reporting so daily operational view stays sharp.
Beyond incident execution, I ship maintainable pipelines to production environments—containerized Python/Streamlit workloads on OpenShift, wired into GitHub Actions and a Tekton pipeline with supply-chain gates. I’m energized by open-source-rooted collaboration, and I build public tools like CVE Feed Dashboard, Vulnerability Prioritization Scorer, and Advisory Composer that connect NVD API v2, EPSS, CISA KEV, and OSV.dev to help teams prioritize and act.
Experience
Work history, roles, and key accomplishments
Vulnerability Threat Management Analyst
Citi
Apr 2025 - Present (1 year 2 months)
Triaged, investigated, and tracked GEM vulnerability findings through closure across Citi’s enterprise asset estate, coordinating remediation with asset-owner teams. Led L0 GEM incident response for Apache Tika XXE and Oracle HTTP Server RCE—clearing 48-hour deadlines and automating notifications from ~4 hours to a 12-minute pipeline.
Cloud Support Engineer
Ericsson
Apr 2023 - Apr 2025 (2 years)
Investigated and resolved orchestration-level incidents for enterprise OpenStack environments, delivering structured RCA reports and sustaining 95% on-time resolution. Maintained 24/7 on-call coverage for business-critical cloud infrastructure while managing concurrent critical cases with ~90% queue utilization.
Reporting Analyst
BlackRock
Jan 2022 - Jan 2023 (1 year)
Optimized 200+ daily reporting deliverables with a 90% success rate while maintaining 99% timeliness and sub-24-hour responses to client tickets. Improved workflow responsiveness to consistently meet operational deadlines.
Education
Degrees, certifications, and relevant coursework
Coursera
Professional Certificate, Data Analytics
2023 -
Completed the Google Data Analytics Professional Certificate on Coursera in 2023.
Budapest Business School
Bachelor of Science, Business Information Technology
2021 -
BSc in Business Information Technology with a Banking IT track at Budapest Business School starting in 2021.
Availability
Location
Website
tamasczaban.github.ioPortfolio
vital-registry.comSocial media
Job categories
Skills
Interested in hiring Czabán?
You can contact Czabán and 90k+ other talented remote workers on Himalayas.
Message CzabánFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
