09 Sep
|
Clifyx
|
Bengaluru
Core Responsibilities
- Vulnerability Lifecycle Management: Operate vulnerability scanning tools to detect risks, analyze impact, prioritize threats, and track remediation metrics.
- Risk Prioritization: Analyze vulnerabilities based on severity, exploitability, and business impact using risk frameworks like the Common Vulnerability Scoring System (CVSS)
- Windows & AD Hardening: Remediate operating system vulnerabilities, configure Group Policy Objects (GPOs), and fix Active Directory security flaws and weak protocols.
- Linux Patching & Remediation: Apply security patches, update packages, and perform system hardening across enterprise Linux environments via command-line.
- SSL/TLS & PKI Management: Identify and remediate weak cryptographic ciphers, expired certificates, and misconfigured public/private key infrastructure.
- Collaboration & Remediation: Work closely with system administrators, developers, and IT operations teams to provide technical guidance and verify the implementation of patches and security controls
Required Technical Skills
- Vulnerability Tooling: Hands-on experience interpreting and managing scans from enterprise platforms (e.g., Qualys,
Tenable/Nessus, Rapid7 InsightVM).
- Windows Server Administration: Solid expertise in Windows Server (2016/2019/2022), system registries, patch deployment, and event log troubleshooting.
- Active Directory (AD): Deep understanding of AD structures, domain controller security, Kerberos/NTLM hardening, and identity access management.
- Linux Systems Administration: Command-line proficiency in enterprise distributions (RHEL, Ubuntu, CentOS) with experience in package managers (yum/apt) and configuration files.
- SSL/TLS & Certificates: Solid understanding of asymmetric encryption, certificate signing requests (CSRs), certificate authorities (CAs), and secure protocol configurations.
Preferred Qualifications
- Experience using automation tools or scripting languages (PowerShell, Bash, or Ansible) to deploy bulk remediation fixes.
- Relevant industry certifications: CompTIA Security+, CEH, Microsoft Certified: Windows Server Hybrid Administrator, or Red Hat Certified System Administrator (RHCSA).
📌 Vulnerability management (Bengaluru)
🏢 Clifyx
📍 Bengaluru