Role & responsibilities :
Manage vulnerability intake, prioritisation, and remediation tracking end-to-end across client environments.
Manage numerous engagements, primarily focused on helping organisations identify, assess, and remediate vulnerabilities across their technology estate.
Define risk-based SLAs and produce remediation performance reporting for key stakeholders and leadership.
Coordinate scanning and tooling improvements to enhance vulnerability detection coverage and accuracy.
Oversee exception governance processes, ensuring risk acceptances are appropriately documented, approved, and reviewed.
Conduct vulnerability management maturity assessments against industry-leading frameworks (such as NIST CSF, ISO/IEC 27001, CVSS, etc.) to identify gaps and recommend improvements.
Collaborate with clients to understand their risk appetite and vulnerability management requirements, ensuring all engagements are delivered to the highest quality and skilled standards.
Stay informed about emerging threats, vulnerability trends, and scanning technologies,
and incorporate this knowledge into client recommendations.
Provide Subject Matter Expertise on vulnerability management programmes and best practices to clients across various sectors.
Required skills:
Minimum of 3 years of experience delivering threat and vulnerability management projects, including programme design, remediation governance, and risk reporting.
Proven track record of successfully executing complex projects within consulting or qualified services environments.
In-depth understanding of vulnerability management principles (such as asset discovery, vulnerability scoring, patch management, and risk-based prioritisation).
Robust knowledge of vulnerability scanning platforms and tools (such as Qualys, Tenable, Rapid7, or Microsoft Defender Vulnerability Management) is advantageous.
Familiarity with common vulnerability scoring systems (CVSS, EPSS) and threat intelligence integration is beneficial.
📌 Threat Vulnerability Telangana
🏢 PwC
📍 Telangana