Timings: 5:30pm to 2:30pm
JOB SUMMARY
The Vulnerability Management Lead will own and manage end-to-end vulnerability management operations across enterprise environments. This role is responsible for leading vulnerability discovery, risk prioritization, remediation governance, SLA tracking, executive reporting, and coordination with IT, infrastructure, application, IAM, endpoint, and patch management teams. The Lead will manage engineers, review vulnerability data quality, ensure accurate risk classification, and drive closure of high-risk findings using tools such as Tenable, Rapid7, TruOps, Tanium, CyberArk, Okta, CrowdStrike, SentinelOne, and Cyberfusion.
OPERATIONAL RESPONSIBILITIES
- Lead the vulnerability management program across servers, endpoints, network devices, cloud assets, applications, identity platforms, and privileged access environments.
- Own vulnerability scanning strategy, scan schedules, authenticated scan coverage, exception handling, risk acceptance, and remediation governance.
- Review vulnerability findings from Tenable and Rapid7 and validate risk severity, asset criticality, exploitability, exposure, business impact, and remediation priority.
- Coordinate with patch management, infrastructure, endpoint security, IAM, application, and business teams to drive timely vulnerability remediation.
- Use TruOps or similar GRC/risk platforms to track risks, exceptions, remediation plans, risk acceptance, and compliance evidence.
- Partner with patch teams using Tanium and legacy/transition tools such as Automox to Tanium to align remediation execution with vulnerability priorities.
- Track remediation SLAs for critical, high, medium, and low vulnerabilities and escalate overdue items to stakeholders.
- Develop dashboards, reports, and metrics for leadership, including vulnerability aging, SLA compliance, risk trends, asset coverage,
recurring findings, and remediation performance.
- Review vulnerabilities related to privileged access and identity systems such as CyberArk and Okta, ensuring privileged and identity-related risks are prioritized appropriately.
- Collaborate with endpoint security teams using CrowdStrike and SentinelOne to correlate endpoint exposure, threat activity, and remediation priority.
- Define and improve vulnerability management processes, playbooks, operational runbooks, exception workflows, and reporting templates.
- Lead weekly/monthly vulnerability review meetings with internal stakeholders and client teams during USA hours.
- Mentor vulnerability management engineers and review their analysis, reports, ticket updates, and remediation recommendations.
- Ensure vulnerability processes align with security frameworks such as ISO 27001, NIST, CIS Controls, PCI-DSS, and internal risk requirements.
-
EDUCATIONAL REQUIREMENTS, TOOLS & CERTIFICATIONS
Education: Diploma/bachelors degree in computer science, Information Technology or equivalent experience.
Experience:
- 6 to10 years of cybersecurity experience, with robust hands-on experience in vulnerability management, risk-based remediation, security operations, or infrastructure security.
- At least 2 years in a lead, senior analyst, or team coordination role.
- Experience working with US-based clients or stakeholders preferred.
Tools & Technologies:
- Primary VM Tools: Tenable, Rapid7 / InsightVM
- Patch / Remediation Tools: Tanium, Automox-to-Tanium transition exposure
- Risk & GRC: TruOps, Cyberfusion
- IAM / PAM: Okta, CyberArk
- Endpoint Security: CrowdStrike, SentinelOne
- Reporting: Power BI, Excel, dashboards, executive reporting, ticketing workflows
Certifications:
- CISSP, CISM, Security+, CySA+, CEH, GSEC, Tenable certification, Rapid7 certification, ITIL Foundation, or equivalent.
📌 Vulnerability Lead (Hyderabad)
🏢 Shi
📍 Hyderabad