11 Sep
|
Version 1
|
Bengaluru
11 Sep
Version 1
Bengaluru
Job Description
Senior technical lead to own strategy and drive maturity across attack surface management, vulnerability management, and cloud security posture using a continuous threat exposure management (CTEM) approach.
Accountable for programme delivery quality, tooling strategy, and governance. Requires deep technical expertise combined with the ability to lead and coach a team, shape a capability roadmap, and influence senior stakeholders without direct supervision.
Key Responsibilities
Strategy & Programme Direction
- Own function strategy aligned to business risk appetite and security frameworks.
- Drive continuous improvement across all CTEM programme phases.
- Establish governance and standards across vulnerability management, ASM, CSPM, and secure development.
- Own the exposure management roadmap; present evidence-based investment cases to senior stakeholders.
Tool Selection & Capability Development
- Own toolchain selection for EASM/CAASM, vulnerability management, CSPM, and exposure correlation.
- Integrate exposure management platforms with SIEM, SOAR, and DevSecOps pipelines.
- Monitor emerging tooling and AI-augmented triage; recommend capability investments.
- Define coverage requirements and onboarding standards for new assets and workloads.
Attack Surface Management (ASM / EASM)
- Run continuous discovery and attribution of all Internet-facing assets, shadow IT, and third-party exposure.
- Enrich findings with threat intelligence, KEV data, and active exploitation trends.
- Maintain an accurate inventory as the authoritative basis for prioritisation.
- Continuously improve coverage, reduce noise, and sharpen the prioritisation model.
Vulnerability Management
- Own the vulnerability management programme end to end: triage, remediation,
SLA governance, and closure.
- Maintain risk-based scoring incorporating CVSS, EPSS, business criticality, and threat context.
- Hold remediation teams to SLAs; resolve systemic blockers across functions.
Cloud Security Posture Management (CSPM)
- Own CSPM strategy across AWS, Azure, and OCI; keep visibility current with estate growth.
- Partner with cloud platform and architecture teams to embed security posture requirements into platform design and IaC standards.
- Eliminate recurring misconfigurations through root cause analysis; don't accept repeat findings.
Pentest & Purple Team Oversight
- Commission and manage penetration testing and purple team engagements; QA external deliverables.
- Translate findings into prioritised remediation and track to closure.
- Use validation outputs to improve controls and update the exposure model.
Secure SDLC
- Integrate security requirements, threat modelling, and code review into the SDLC.
- Drive secure-by-design principles with engineering and architecture teams.
- Measure secure development maturity and set improvement targets.
Leadership, Reporting & Stakeholder Engagement
- Deliver executive dashboards translating technical risk into business impact; represent the function in ISO 27001, Cyber Essentials Plus, SOC 1, and MSP audit cycles.
- Build credibility with senior stakeholders, client security teams, and third-party assessors.
- Lead, coach, and develop the team; set explicit goals, resolve conflicts, and create growth opportunities.
- Foster a culture of learning and delivery excellence; act as escalation point for complex technical decisions.
- Coordinate remediation owners, platform teams, and external parties; keep all stakeholders aligned on plans and blockers.
📌 Cyber Threat Exposure Management – Lead (Bengaluru)
🏢 Version 1
📍 Bengaluru