02 Aug
|
Tata Consultancy Services
|
Hyderabad
02 Aug
Tata Consultancy Services
Hyderabad
Role : Vulnerability Management_GRC SME Experience : 8 to 15 years Location : Pan India
Keywords : GRC SME, Vulnerability Management, Cyber Risk, Archer, ServiceNow IRM, Qualys, Tenable, Rapid7, CVSS, EPSS, ISO 27001, NIST CSF, AI prioritization Desired Competencies (Technical/Behavioral Competency)
Must-Have
Deep expertise in GRC frameworks, enterprise risk lifecycle, control design, compliance mapping, risk acceptance and assurance practices.
Strong experience in vulnerability management, threat exposure management, security operations and remediation governance across infrastructure, cloud and applications.
Hands-on familiarity with Archer, ServiceNow GRC/IRM or MetricStream and vulnerability platforms such as Qualys, Tenable, Rapid7 or Microsoft Defender VM.
Ability to define risk taxonomy, control libraries, vulnerability SLA models, contextual risk scoring, exception handling and executive dashboard requirements.
Knowledge of AI-based vulnerability prioritization, ITSM/SOAR automation, cloud security, DevSecOps integration, audit readiness and regulatory reporting.
Good-to-Have
Experience in BFSI or other highly regulated industries with robust understanding of audit, compliance and evidence requirements.
Knowledge of exploitability intelligence, EPSS, threat intelligence enrichment, attack surface management, SAST/DAST/SCA and container/IaC scanning.
Exposure to AI/ML governance, responsible AI, model risk and AI-based cyber-risk analytics with executive reporting capability. SN
Role descriptions / Expectations from the Role
1
Define and govern enterprise GRC and vulnerability operating models, including risk assessment, control assurance, issue management and executive reporting.
2
Design risk taxonomy, control frameworks and compliance mappings across ISO 27001, ISO/IEC 42001, NIST CSF, NIST AI RMF, SOC2, GDPR, CIS and OWASP.
3
Own vulnerability lifecycle design covering asset discovery, scan scheduling, validation, triage, prioritization, assignment, remediation, exceptions and closure.
4
Design AI-led vulnerability prioritization models using CVSS, EPSS, threat signals, asset criticality, exposure, compensating controls and remediation complexity.
5
Oversee scanner-to-CMDB/ITSM/GRC integrations, dashboards, SLA reporting, audit evidence, risk posture reporting and mentoring of delivery teams.
📌 Vulnerability Management_GRC SME (Hyderabad)
🏢 Tata Consultancy Services
📍 Hyderabad