This role owns the operational side of the Vulnerability Detection & Response (VDR) program, focusing on the response discipline that ensures vulnerabilities are evaluated, remediated, and verified within strict SLA timeframes-as little as 12 hours for the most critical exploitable, internet-reachable findings.
The Security Engineer will design and implement response playbooks, build on-call and emergency-patch processes, execute them during a parallel-run period, and train internal security and platform teams to operate them post-cutover.
The role requires close coordination with engineering teams to drive real findings through the full lifecycle from triage to verified closure while also establishing SLA telemetry, drift alerting, and operator-quality documentation for long-term program sustainability.
Key Responsibilities
- Develop the runbook library for vulnerability response, including:
- Triage and evaluation runbooks
- Standard remediation workflows per finding type (container image, host, dependency, code)
- Emergency-patch runbooks for PAIN-5 LEV+IRV findings (12-hour to 2-day SLAs)
- Verification and closure procedures
- Design and implement the on-call and escalation model, including PagerDuty alerting rules tied to PAIN/LEV/IRV thresholds.
- Operate the response process during the parallel-run and cutover period by driving real findings through:
ensuring fixes are confirmed in the deployed environment-not just in rebuilt images-before findings are closed.
- Define SLA telemetry and drift alerting through dashboards and alerts that identify findings approaching or breaching SLA targets.
- Coordinate remediation with engineering teams by providing:
- Conduct tabletop exercises for emergency-patch scenarios and continuously improve runbooks.
- Train internal security and platform teams and produce operator-quality documentation for handoff.
Required Skills
- 5+ years of experience in:
- Security Operations
- Vulnerability Management Operations
- Detection & Response
- Hands-on remediation experience, including:
- Patching campaigns
- Container image updates
- Dependency upgrades across engineering teams
- Experience writing operational runbooks and incident/response procedures.
- Working knowledge of exploit intelligence and prioritization, including:
- CISA KEV
- EPSS
- Vendor advisories
- Experience with alerting and on-call tools such as PagerDuty and SLA-driven workflows.
- Robust cloud and container knowledge, especially understanding how fixes move through:
- Experience in FedRAMP or other regulated environments where remediation timelines are compliance requirements.
- Familiarity with DefectDojo or similar vulnerability management platforms.
- Incident Response experience, especially emergency patching.
- Experience conducting tabletop exercises and operational readiness reviews.
📌 Security Engineer — Detection & Response Operations (India)
🏢 Sparix Global
📍 India
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.