Infra VM Analyst (Bengaluru)

Infra VM Analyst (Bengaluru)

16 Aug
|
Cyberpwn
|
Bengaluru

16 Aug

Cyberpwn

Bengaluru

ABOUT CYBERPWN

CyberPwn is a cybersecurity services and managed security provider (“Empowering Cyber Resilience”), ISO 27001 certified and AICPA SOC-attested, and a Great Place to Work-Certified™ organisation. CyberPwn is building a dedicated onsite security delivery team in Bangalore to run Infrastructure Vulnerability Management, Application Security and DevSecOps, Offensive Security and Red Teaming, Continuous Threat Exposure Management (CTEM), Cloud Security Posture Management, and on-demand security advisory.

ROLE OVERVIEW

Execute day-to-day infrastructure vulnerability management operations across servers, endpoints, and network devices, covering scan execution, finding triage, remediation coordination, and service level tracking. This is a hands-on delivery role within a CTEM-led exposure reduction programme, with structured progression toward Senior Analyst.

KEY RESPONSIBILITY AREAS (KRA)

- Configure, schedule, and execute credentialed and non-credentialed vulnerability scans across servers, endpoints, and network devices using Qualys VMDR and Microsoft Defender for Endpoint TVM.

- Validate scan coverage and scan health, and troubleshoot agent and scanner connectivity, credential failures, and authentication issues.

- Triage vulnerability findings, deduplicate and eliminate false positives, and enrich findings with exploitability, threat context, and asset criticality for risk scoring.

- Execute out-of-band and event-driven scans in response to zero-day disclosures, threat intelligence triggers, and Breach and Attack Simulation outcomes as directed.

- Coordinate remediation with server, network, and endpoint owners, covering ticket creation, ownership assignment, status follow-up, and escalation of at-risk items.





- Track remediation status against the severity-band SLA framework and maintain the central vulnerability and exception register.

- Support the exception lifecycle by preparing submissions, maintaining aging records, and evidencing compensating controls.

- Contribute to inherited backlog reduction campaigns against High and Medium severity findings.

- Maintain and update asset inventory and CMDB records to ensure accurate scan scoping, and onboard newly discovered or newly provisioned assets into vulnerability management scope.

- Coordinate scan windows with infrastructure teams to minimise business disruption.

- Investigate and close out scan exceptions such as offline assets, credential failures, and blocked ports within agreed timelines.

- Support monthly vulnerability governance reporting, patch compliance dashboards, and audit evidence collation.

- Participate in shadowing, reverse-shadowing, and assisted-operation phases of knowledge transfer during mobilisation and transition.

KEY PERFORMANCE INDICATORS (KPIs)

- Scan coverage rate, measured as the proportion of in-scope assets scanned within scheduled cadence.

- Turnaround time for triage of newly identified Critical and High severity vulnerabilities.

- Remediation SLA adherence across assigned severity bands.

- Reduction in false-positive rate quarter-on-quarter.





- New asset onboarding timeliness into scan coverage following CMDB entry.

- Scan and agent health incidents resolved within target time.

- Aging of open exceptions in the vulnerability register.

- Accuracy and timeliness of monthly vulnerability and patch-compliance reporting inputs.

REQUIRED TECHNICAL SKILLS & EXPERIENCE

- Hands-on experience with at least one enterprise vulnerability scanning platform, with Qualys VMDR strongly preferred and Microsoft Defender for Endpoint TVM an advantage.

- Working knowledge of CVSS v3.x scoring, CVE and NVD research, and awareness of EPSS and KEV as prioritisation inputs.

- OS-level patch management understanding across Windows and Linux.

- Basic scripting (PowerShell, Python, or Bash) for report automation and data reconciliation.

- Understanding of network segmentation, firewall and NAC basics, and asset inventory and CMDB concepts.

- Familiarity with IT service management and ticketing tools, with ServiceNow and Azure Boards preferred, for remediation tracking.

- Transparent written and verbal communication for coordinating with infrastructure and application owners.

WORKING ENVIRONMENT & CONDUCT

- Onsite presence at the client delivery centre in Bangalore five days per week is a mandatory condition of the role.

- Candidates must meet client-defined competency, certification, background verification, and conduct standards prior to onboarding.

PREFERRED / EXPECTED CERTIFICATIONS

- CompTIA Security

- Qualys VMDR certification (vendor-relevant, preferred)

- CEH (preferred, not mandatory)

EDUCATIONAL QUALIFICATION

Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).

📌 Infra VM Analyst (Bengaluru)
🏢 Cyberpwn
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: infra vm analyst (bengaluru) / bengaluru