22 Aug
|
Trekrecruit India.
|
Hyderabad
22 Aug
Trekrecruit India.
Hyderabad
Threat & Vulnerability Management Lead
Role Summary
The Threat & Vulnerability Management Lead will lead the organizations end-to-end vulnerability management and threat intelligence programs. This role will be responsible for proactively identifying, assessing, prioritizing, and driving the remediation of security vulnerabilities across infrastructure, applications, cloud environments, and third-party ecosystems.
The role requires a strong risk-based approach, deep knowledge of the evolving cyber threat landscape, and the ability to translate technical vulnerabilities and threat intelligence into actionable business risk. The incumbent will work closely with SOC, Incident Response, IT, Engineering, Cloud, DevSecOps, Risk, Compliance, and business stakeholders to strengthen the organization’s overall security posture.
Key Responsibilities
1. Vulnerability Management Program Leadership
- Lead the design, implementation, and continuous maturity of the enterprise-wide Vulnerability Management Program in alignment with the organization’s risk appetite.
- Establish standardized processes for vulnerability identification, assessment, prioritization, remediation, validation, and reporting.
- Define and enforce risk-based remediation SLAs based on asset criticality, vulnerability severity, exploitability, exposure, and business impact.
- Oversee vulnerability assessment and scanning across networks, endpoints, databases, applications, APIs, containers, and cloud environments.
- Ensure comprehensive vulnerability coverage across internal assets, internet-facing systems, and third-party integrations.
- Drive automation and process improvements to increase vulnerability discovery, remediation efficiency, and overall program effectiveness.
2. Threat Intelligence & Threat Management
- Establish and operationalize a Threat Intelligence capability focused on emerging threats, attack vectors, vulnerabilities, and adversary tactics, techniques, and procedures (TTPs).
- Correlate external threat intelligence with internal vulnerability and asset data to identify vulnerabilities that pose an immediate or elevated risk.
- Monitor emerging threats, including ransomware, zero-day vulnerabilities, supply-chain attacks, and targeted campaigns, and assess organizational exposure.
- Provide actionable threat intelligence and risk insights to SOC, Incident Response, Vulnerability Management, and senior leadership teams.
- Support proactive identification of threats and vulnerabilities that could impact critical business services.
3. Risk-Based Prioritization & Remediation Governance
- Establish and drive risk-based vulnerability prioritization using CVSS, exploitability, threat intelligence, asset criticality, exposure, and business impact.
- Integrate vulnerability information with enterprise risk registers and GRC platforms.
- Partner with IT, Engineering, DevOps, Cloud,
and Application teams to ensure timely remediation of security weaknesses.
- Monitor remediation progress, overdue vulnerabilities, exceptions, risk acceptances, and compensating controls.
- Establish governance mechanisms and regular review forums to assess vulnerability posture and drive accountability.
- Escalate significant or unresolved security risks to appropriate stakeholders and leadership.
4. Application & Cloud Security Integration
- Partner with DevSecOps and engineering teams to embed vulnerability management throughout the software development lifecycle and CI/CD pipelines.
- Oversee the effective use of SAST, DAST, SCA, container security, API security, and infrastructure-as-code scanning capabilities.
- Drive cloud-native vulnerability management across Azure and other IaaS, PaaS, and SaaS environments.
- Support secure configuration baselines, continuous security posture management, and remediation of cloud security exposures.
- Promote shift-left security practices while maintaining effective enterprise-level vulnerability governance.
5. Metrics, Reporting & Continuous Improvement
- Define, monitor, and report key vulnerability and threat management metrics, including:
- Vulnerability aging
- Remediation SLA compliance
- Critical and high-risk vulnerability exposure
- Exploitability trends
- Internet-facing exposure
- Risk reduction
- Remediation effectiveness
- Develop executive dashboards and management reports that provide clear visibility into the organization’s security posture.
- Provide periodic reporting and risk insights to senior leadership and relevant governance committees.
- Conduct regular program maturity assessments and benchmark capabilities against industry standards and leading practices.
- Continuously improve tools, processes, automation, and operating models to enhance program efficiency and effectiveness.
6. Red Teaming, Threat Modeling & Proactive Security Testing
- Lead and coordinate periodic penetration testing, red teaming, adversary simulation, and security validation exercises.
- Conduct and facilitate threat modeling for critical applications, systems, infrastructure, and strategic technology initiatives.
- Validate the effectiveness of security controls against realistic attack scenarios.
- Use findings from penetration testing, red teaming, and threat modeling to strengthen vulnerability prioritization and remediation strategies.
7. Stakeholder Management & Collaboration
- Partner closely with IT, Engineering, Cloud, DevSecOps, SOC, Incident Response, Risk, Compliance,
and business teams to align security priorities with business objectives.
- Serve as the subject matter expert for enterprise vulnerability and threat management.
- Translate complex technical vulnerabilities and cyber threats into clear business risks and actionable recommendations.
- Support internal and external audits, regulatory assessments, compliance requirements, and third-party risk assessments.
- Drive a culture of accountability and continuous improvement across technology and security teams.
Required Experience & Qualifications
- 8–12+ years of experience in cybersecurity, with significant experience in vulnerability management, threat intelligence, security risk management, or related domains.
- Proven experience leading or managing an enterprise-wide Vulnerability Management Program.
- Strong hands-on experience with vulnerability management platforms such as Qualys, Tenable, Rapid7, or equivalent solutions.
- Strong understanding of enterprise infrastructure, network security, endpoint security, application security, and cloud security.
- Experience with Azure cloud security and cloud-native vulnerability management.
- Strong understanding of application security practices, including SAST, DAST, SCA, container security, and API security.
- Experience with threat intelligence, vulnerability intelligence, threat modeling, penetration testing, or red team activities.
- Strong understanding of risk-based vulnerability prioritization and remediation governance.
- Experience integrating vulnerability and security data with GRC, SIEM, SOC, or enterprise risk management processes.
- Experience working with cross-functional technology and business teams in large enterprise environments.
- Experience in the BFSI/Insurance sector is preferred.
- Familiarity with regulatory and security frameworks, including IRDAI, RBI, ISO 27001, NIST CSF, and related cybersecurity requirements.
Preferred Certifications
- CISSP / CISM / CRISC
- CEH / OSCP — preferred for robust technical depth
- GIAC certifications, such as GPEN, GWAPT, or GCIH
- ISO 27001 Lead Auditor / Lead Implementer
Key Competencies
- Strong risk-based decision-making and prioritization skills
- Deep understanding of the cyber threat landscape and modern attack methodologies
- Strong analytical, problem-solving, and security assessment capabilities
- Ability to translate complex technical risks into clear business impact and actionable recommendations
- Strong stakeholder management, communication, negotiation, and influencing skills
- Strong understanding of enterprise security architecture and risk management
- High level of ownership, accountability, and execution focus
- Ability to operate effectively in a complex, fast-paced enterprise environment
- Strong leadership skills with the ability to influence teams without direct authority
- Continuous improvement and automation mindset
📌 Threat Vulnerability Manager (Hyderabad)
🏢 Trekrecruit India.
📍 Hyderabad