Role description
c
Position Summary
We are seeking a skilled Vulnerability Management Engineer to support the identification, assessment, prioritization, coordination, and remediation of security vulnerabilities across enterprise applications, infrastructure, operating systems, networks, and configurations.
The role focuses on vulnerability analysis, remediation coordination, validation, tracking, and reporting. The engineer will work closely with application owners, infrastructure and platform teams, security teams, and external vendors to ensure vulnerabilities are addressed within defined security policies and SLA timelines. This is not a software development or application code remediation role.
Key Responsibilities
- Analyze and interpret vulnerability scan results from tools such as Qualys, Tenable, Rapid7, and Nessus.
- Review, validate, and classify vulnerabilities across:
- - Applications
- Servers and operating systems
- Infrastructure
- Network components
- Middleware
- Security configurations
- Security tools and platforms
- Analyze CVE, CVSS scores, exploitability, business impact, and risk to support appropriate vulnerability prioritization.
- Identify whether application vulnerabilities relate to COTS products, vendor-supported applications, open-source software, or internally developed applications.
- Research available remediation options and validate recommended fixes or compensating controls.
- Coordinate with application owners, infrastructure teams, system administrators, product teams, and external vendors to drive remediation activities.
- Work with Windows and Linux administration teams to address operating system, server, middleware,
and configuration vulnerabilities.
- Validate remediation activities through rescans, evidence review, configuration checks, or other appropriate testing methods.
- Track vulnerability remediation progress and ensure findings are resolved within defined SLA and compliance timelines.
- Perform root-cause analysis for recurring or complex vulnerabilities and recommend sustainable remediation approaches.
- Support change and release management activities related to vulnerability remediation.
- Prepare vulnerability assessment reports, remediation plans, exception requests, dashboards, and management reports.
- Provide regular vulnerability trends, SLA compliance, aging, and risk metrics to security and compliance stakeholders.
- Support security audits, compliance reviews, and enterprise vulnerability management initiatives.
Required Skills
- Strong experience in Vulnerability Management and Remediation.
- Hands-on experience analyzing security assessment and vulnerability scan reports.
- Good understanding of CVE, CVSS, vulnerability severity, exploitability, and risk prioritization.
- Experience with vulnerability management tools such as Qualys, Tenable, Rapid7, or Nessus.
- Positive understanding of Windows and Linux server security.
- Knowledge of system configuration, security hardening, and remediation practices.
- Understanding of application security fundamentals and common vulnerability types.
- Knowledge of OWASP, CIS Benchmarks, NIST, and security compliance principles.
- Experience coordinating remediation activities across application, infrastructure, and security teams.
- Strong troubleshooting and root-cause analysis skills.
- Understanding of change and release management processes.
- Strong documentation, communication, reporting, and stakeholder management skills.
Preferred Qualifications
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field.
- Experience working within an enterprise-level vulnerability management program.
- Experience with vulnerability remediation SLAs, risk acceptance, and exception management.
- Security certifications such as Security+, CEH, GSEC, or equivalent are preferred.
Skills
Vulnerability Management, Application Security, Infrastructure Security, Vulnerability Assessment, Linux, Risk Management, Issue Analysis, Production Support
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.
📌 Vulnerability Management Engineer (India)
🏢 UST
📍 India