Time: 5:30pm to 2:30pm
JOB SUMMARY
The Vulnerability Management Engineer will support daily vulnerability management operations, including scan execution, findings analysis, vulnerability validation, ticket creation, remediation tracking, reporting, and coordination with patching and infrastructure teams. The role will work with tools such as Tenable, Rapid7, Tanium, TruOps, CyberArk, Okta, CrowdStrike, SentinelOne, and Cyberfusion.
OPERATIONAL RESPONSIBILITIES
- Execute scheduled and ad-hoc vulnerability scans using Tenable and Rapid7.
- Review scan results, remove false positives where applicable, validate findings, and categorize vulnerabilities by severity and remediation priority.
- Create, update, and track remediation tickets with accurate vulnerability details, affected assets, CVE references, risk ratings, and remediation guidance.
- Work with patch management teams using Tanium and legacy Automox-to-Tanium workflows to support remediation execution.
- Track open vulnerabilities, aging items, SLA breaches, recurring vulnerabilities, and remediation status.
- Support risk and exception tracking in TruOps or similar GRC platforms.
- Assist in correlating vulnerabilities with endpoint security data from CrowdStrike and SentinelOne.
- Support review of identity and privileged-access-related vulnerabilities involving Okta and CyberArk.
- Prepare operational reports,
scan summaries, weekly status updates, and vulnerability closure evidence.
- Re-scan or validate remediated vulnerabilities and update closure status.
- Escalate critical/high-risk vulnerabilities to the Vulnerability Management Lead.
- Maintain accurate documentation, asset lists, scan coverage records, exception logs, and remediation evidence.
- Participate in client/internal vulnerability review calls during USA hours.
- EDUCATIONAL REQUIREMENTS, TOOLS & CERTIFICATIONS
Education: Diploma/bachelors degree in computer science, Information Technology or equivalent experience.
Experience:
- 2 to 5 years of experience in vulnerability management, security operations, infrastructure security, or cybersecurity support.
- Hands-on exposure to vulnerability scanning and remediation tracking tools.
- Experience working with global or US-based teams preferred.
Tools & Technologies:
- Primary VM Tools: Tenable, Rapid7 / InsightVM
- Patch / Remediation Tools: Tanium, Automox
- Risk & GRC: TruOps, Cyberfusion
- IAM / PAM: Okta, CyberArk
- Endpoint Security: CrowdStrike, SentinelOne
- Ticket/Reporting Tools: ServiceNow,Jira,Power BI, Excel, dashboards
Certifications:
- Security+, CEH, CySA+, Tenable certification, Rapid7 certification, ITIL Foundation, or equivalent.
📌 Vulnerability Analyst (Hyderabad)
🏢 Shi
📍 Hyderabad