16 Aug
|
Cyberpwn
|
Bengaluru
16 Aug
Cyberpwn
Bengaluru
ROLE OVERVIEW
Own the Continuous Threat Exposure Management programme as the orchestration layer across infrastructure, application, cloud, offensive, and external attack surface inputs, translating raw finding data into a single prioritised view of enterprise exposure. This role owns the risk scoring model, the exposure reduction narrative to executive stakeholders, and the automation roadmap that makes continuous exposure management operationally viable.
KEY RESPONSIBILITY AREAS (KRA)
- Own the CTEM operating model end-to-end across surface discovery, exposure prioritisation, risk-orchestrated remediation, validation and control testing, and continuous feedback and measurement.
- Own the risk scoring and weighting model, defining the relative weighting applied to exploitability, asset criticality, active threat context, and control effectiveness, and tailoring it to the client workplace.
- Govern changes to scoring logic through agreed forums, and lead the periodic review of weighting against the evolving threat landscape, business criticality, and enterprise risk appetite.
- Consolidate inputs from infrastructure vulnerability management, application security, offensive security, and cloud posture into a unified prioritised exposure register.
- Own consumption and correlation of external attack surface data, asset visibility feeds covering operational technology, unmanaged and connected devices, cloud vulnerability and toxic combination data, and selected threat intelligence feeds.
- Own the zero-day and targeted threat operating model, covering relevance assessment against the estate, confirmation of client-specific exposure, and identification of mitigation or remediation pathway within defined response windows.
- Drive exposure prioritisation that reflects genuine exploitability and business risk rather than finding volume or severity score alone.
- Own the automation roadmap for the engagement, identifying opportunities across all towers and directing delivery to reduce triage effort, remediation delay, and exposure identification latency.
- Own asset and exposure correlation aligned to CMDB classifications and business criticality tiers, and drive improvement in reconciliation accuracy.
- Operate CTEM as a closed-loop process with the client and the defensive security team, incorporating joint review points that validate whether exposure reduction and defensive improvements have materially reduced exploitable risk.
- Own executive risk posture reporting and exposure trend analysis, translating technical exposure data into business-relevant risk narrative.
- Lead periodic CTEM maturity review and roadmap refresh, tracking capability progression against an agreed framework.
- Mentor and direct the Automation Engineer, owning work sequencing, quality review, and the automation agenda agreed with the client.
- Present exposure posture, top residual risks, validation outcomes, and automation impact to senior client leadership in monthly and quarterly governance forums.
KEY PERFORMANCE INDICATORS (KPIs)
- Exposure window reduction, measured as median time from discovery to validated closure across critical assets.
- Threat-to-exposure time, measured from external threat disclosure to confirmed client-specific exposure determination.
- Exploitability-contextualised triage coverage across Critical and High findings.
- Risk prioritisation accuracy, measured by the proportion of prioritised findings validated as genuinely exploitable.
- Validation rate, measured by the proportion of remediated findings confirmed through BAS, offensive testing, or targeted re-scan.
- Detection gap closure rate achieved in conjunction with the defensive security team.
- Discovered-to-CMDB asset alignment and reconciliation accuracy.
- Threat intelligence feed freshness and operational availability.
- Automation efficiency, measured by analyst hours saved, cycle time reduction, and exposure identification latency improvement.
- CTEM dashboard data freshness and reporting accuracy.
- CTEM maturity score progression measured against the agreed framework.
- Stakeholder satisfaction from governance forum and joint collaboration forum feedback.
REQUIRED TECHNICAL SKILLS & EXPERIENCE
- Deep experience designing or operating an exposure management, risk-based vulnerability management, or CTEM programme at enterprise scale.
- Strong command of vulnerability risk prioritisation methodology including CVSS, EPSS, KEV, threat actor context, and asset criticality weighting, with the ability to defend a scoring model to technical and executive audiences.
- Practical understanding of the full input set that feeds exposure management, covering infrastructure vulnerability data, application security findings, cloud posture and workload vulnerability data, external attack surface data, and offensive validation outcomes.
- Experience building and operating security data pipelines and dashboards, with strong Power BI capability and working knowledge of Azure Logic Apps and ServiceNow workflow integration.
- Hands-on automation and integration capability sufficient to direct engineering work credibly, including REST API integration and scripting in Python or PowerShell.
- Experience translating technical exposure data into executive risk narrative for Head of Cyber and CISO-level audiences.
- Working understanding of CMDB structure, asset criticality classification, and the practical data quality constraints of enterprise asset inventory.
WORKING ENVIRONMENT & CONDUCT
- Onsite presence at the client delivery centre in Bangalore five days per week is a mandatory condition of the role.
- Candidates must meet client-defined competency, certification, background verification, and conduct standards prior to onboarding.
PREFERRED / EXPECTED CERTIFICATIONS
- CISSP or CISM (or actively pursuing)
- Qualys VMDR or equivalent vulnerability platform certification (preferred)
- Azure certification relevant to Logic Apps, automation, or security (preferred)
- Power BI or data analytics certification (preferred)
EDUCATIONAL QUALIFICATION
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
📌 CTEM and Automation - Tower Lead (Bengaluru)
🏢 Cyberpwn
📍 Bengaluru