Senior Cybersecurity Engineer - Exposure Management (Hyderabad)

Senior Cybersecurity Engineer - Exposure Management (Hyderabad)

13 Aug
|
Syneos Health
|
Hyderabad

13 Aug

Syneos Health

Hyderabad

Job Summary

Senior Cybersecurity Engineer - Exposure Management.

Responsibilities

- CTEM Program Maturity Operating Model
- Help define, implement, and continuously improve the CTEM lifecycle across scoping, discovery, prioritization, validation, and mobilization.
- Translate exposure management strategy into repeatable operating processes, decision criteria, governance routines, and measurable outcomes.
- Identify maturity gaps across asset coverage, signal quality, prioritization, validation, remediation ownership, exception handling, and executive reporting.
- Partner with security, infrastructure, cloud, endpoint, identity, application, architecture, and business teams to establish shared accountability for exposure reduction.
- Drive structured exposure review cycles that move the organization from vulnerability reporting to validated, risk-based remediation and measurable risk reduction.
- Exposure Management Engineering
- Engineer and operate exposure management capabilities across infrastructure, cloud, endpoints, identity, applications, and third-party surfaces.
- Maintain and enhance tooling that aggregates vulnerability data, asset context, threat intelligence, and exploitability signals.
- Ensure accurate asset discovery, coverage validation, and telemetry quality across the enterprise attack surface.
- Risk-Based Prioritization
- Drive risk- and threat-informed prioritization beyond CVSS scoring.
- Incorporate exploit intelligence, threat actor activity, asset criticality, and compensating controls.
- Partner with technology and business owners to translate exposure into remediation priorities.
- Threat-Aligned Analysis
- Correlate exposure data with threat intelligence and adversary TTPs.
- Support zero-day and emerging threat response through rapid exposure analysis.
- Metrics, Reporting Insight
- Define and maintain CTEM outcome metrics, including exposure reduction, risk burndown, validated closure rate, SLA adherence, exception aging, reintroduced exposure rate, coverage gaps, telemetry freshness, owner assignment accuracy, and remediation cycle time.
- Build executive, operational, engineering, and audit views that clearly explain risk, accountability, trend, residual exposure, and progress against maturity goals.




- Convert technical findings into business-relevant narratives that support prioritization, funding, architecture decisions, and remediation mobilization.
- Identify recurring exposure patterns and recommend control, architecture, automation, or process improvements.
- Cross-Functional Leadership Mobilization
- Lead exposure reduction initiatives across teams without direct reporting authority, using data, risk rationale, business impact, and clear decision records to drive alignment.
- Facilitate remediation planning across infrastructure, cloud, endpoint, application, identity, SOC, GRC, and business stakeholders.
- Build consensus on ownership, prioritization, compensating controls, exception paths, and remediation timelines.
- Escalate systemic blockers with explicit options, residual risk framing, and recommended decisions.
- Mentor analysts and engineers while raising the overall maturity of exposure management practices.

Qualifications

Required Qualifications

- 7+ years of cybersecurity experience, including significant hands-on experience in vulnerability management, exposure management, threat-informed defense, cloud security, infrastructure security, or security operations engineering.
- Demonstrated experience operating or maturing a risk-based vulnerability management, exposure management, or CTEM-aligned program.
- Proven ability to lead cross-functional remediation initiatives without direct reporting authority.
- Strong understanding of CTEM lifecycle concepts: scoping, discovery, prioritization, validation, and mobilization.
- Experience correlating asset context, exploitability, threat intelligence, business criticality, control state, and remediation feasibility into defensible prioritization decisions.
- Hands-on experience with vulnerability/exposure platforms and related ecosystem tools, including scanners,



EDR/XDR, CMDB/CAASM, cloud/CNAPP/CSPM, identity/IAM, ASM/EASM, ITSM, SIEM/SOAR, and threat intelligence sources.
- Experience with SLA models, exception workflows, compensating controls, risk acceptance, residual risk reporting, and validated closure.
- Ability to communicate exposure and residual risk clearly to engineering, operations, security leadership, and non-technical stakeholders.
- Working knowledge of automation, APIs, scripting, or data analysis methods used to improve exposure management workflows.

Nice to Have / Preferred

- Experience implementing or significantly maturing a CTEM-style program in a large enterprise.
- Familiarity with EPSS, CISA KEV, SSVC-style decisioning, CVSS v4 environmental/threat context, exploit telemetry, ransomware intelligence, and threat actor TTP mapping.
- Experience with attack-path analysis, adversarial exposure validation, breach and attack simulation, red-team/pentest integration, or control validation.
- Experience applying AI or machine learning to exposure management, including summarization, deduplication, risk explanation, ticket enrichment, remediation recommendation drafting, or executive reporting.
- Knowledge of AI governance, human-in-the-loop controls, model/data protection, auditability, and safe automation design.
- Experience integrating exposure workflows with ServiceNow or equivalent ITSM platforms.
- Experience with cloud-native exposure management across AWS, Azure, GCP, containers, Kubernetes, IaC, SaaS, identity, and application security findings.
- Industry certifications such as CISSP, GIAC, OSCP, cloud security, or relevant offensive/defensive security credentials.
- Collaborate with SMEs to define mitigation strategies and/or compensating controls
- Provide leadership with clear, defensible views of exposure and residual risk.
- Provide operational guidance to and oversight of managed server provider technicians.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Senior Cybersecurity Engineer - Exposure Management (Hyderabad)
🏢 Syneos Health
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior cybersecurity engineer - exposure management (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: senior cybersecurity engineer - exposure management (hyderabad) / hyderabad