05 Aug
|
Carnera Technologies
|
Karnataka
05 Aug
Carnera Technologies
Karnataka
Senior Endpoint Vulnerability Management Engineer
Experience: 7+ yrs of overall experience
Primary Skills(Must-Have): Endpoint Vulnerability Management (Microsoft Defender/Qualys/Rapid7), Patch Management (Automox/PatchMyPC/NinjaOne), JAMF, Intune, Scripting (PowerShell/Bash/Python), Windows, Mac
Secondary Skills (Good-to-Have): Linux, AWS
Location: Bengaluru (Hybrid)
Shift: Afternoon IST Shift (02:00 PM to 10:00 PM)
About the Role:
We are seeking a Senior Endpoint Vulnerability Management Engineer to serve as the technical and strategic authority for our organisation's endpoint vulnerability management program. This is a senior individual contributor role responsible for setting the long-term vision, architecture, and standards for vulnerability management across a large, heterogeneous fleet of macOS and Windows endpoints. You will operate at the intersection of security strategy, engineering, and executive risk reporting, driving program maturity, mentoring senior engineers, and directly influencing enterprise-wide risk posture. This role carries significant autonomy and is expected to lead cross-organisational initiatives without close oversight.
Key Responsibilities:
- Own the enterprise vulnerability management strategy and roadmap for endpoints, aligning with overall security architecture and business risk tolerance.
- Define and evolve organisational SLAs, risk-scoring methodology, and prioritisation frameworks (CVSS, EPSS, exploit intelligence, asset criticality) at the policy level.
- Establish the long-term toolchain strategy, evaluate, select, and architect vulnerability scanning and endpoint management platforms (Qualys, Rapid7, Microsoft Defender, Jamf, Intune)
to scale with organisational growth.
- Act as the final escalation point and decision-maker for high-risk exceptions, complex remediation conflicts, and cross-team prioritisation disputes.
- Manage operating system and application patching across Windows, macOS, virtual machines, cloud platforms, firmware, and third-party software.
- Coordinate emergency patch deployments for zero-day vulnerabilities and critical or high-security incidents.
- Lead root-cause analysis for systemic or recurring vulnerability trends across the endpoint fleet (e.g., patch failures, EOL software sprawl, configuration drift) and drive engineering-level fixes.
- Define technical standards, playbooks, and reference architectures for endpoint vulnerability management, patch orchestration, and exception governance.
- Partner with Infrastructure, Cloud, Platform Engineering, and Application teams to reduce remediation timelines.
- Design and implement automated patch deployment pipelines using scripting and configuration management tools.
- Monitor patch compliance, remediation SLAs, and vulnerability trends through dashboards and executive reporting.
- Support audits and regulatory compliance requirements including ISO 27001, SOC 2, PCI DSS, HIPAA, NIST, Cyber Essentials Plus and CIS Controls.
- Mentor engineers and provide technical leadership across the organisation.
Required Qualifications:
- Bachelor's degree in Computer Science, Information Security, Information Technology, or related field.
- 7-10 years of experience in Infrastructure, Systems Engineering, Cybersecurity, or Vulnerability Management.
- 5+ years leading enterprise patch management programs.
- Deep knowledge of Windows Client OS, Linux, VMware, cloud platforms (AWS, Azure, GCP), and enterprise endpoint management.
- Experience with vulnerability management tools such as: (Any 1 experience in Ok to consider) = Qualys/Rapid7 Microsoft Defender
- Experience with enterprise patch management solutions such as:
- Microsoft Intune (Mandatory) with any one of the below = Automox/PatchMyPC/NinjaOne
- Robust scripting skills using PowerShell, Python, Bash.
- Experience automating operational processes using Infrastructure as Code and configuration management tools.
- Solid understanding of vulnerability scoring (CVSS), MITRE ATT&CK;, and threat intelligence.
- Experience supporting large-scale enterprise environments with thousands of endpoints.
Technical Skills:
- Vulnerability Management
- Patch Management
- Microsoft Intune
- JAMF
- PowerShell
- Python
- Bash
- Azure Active Directory
- Microsoft Defender
- Qualys
- Rapid7
- Automation
- Risk Management
Key Competencies:
- Technical Leadership
- Strategic Planning
- Risk Assessment
- Problem Solving
- Cross-functional Collaboration
- Incident Response Support
- Process Improvement
- Communication and Executive Reporting
- Decision Making
- Mentoring and Coaching
📌 Senior Endpoint Vulnerability Management Engineer (Karnataka)
🏢 Carnera Technologies
📍 Karnataka