Architect I - Information Security (Thiruvananthapuram)

Architect I - Information Security (Thiruvananthapuram)

14 Sep
|
UST
|
Thiruvananthapuram

14 Sep

UST

Thiruvananthapuram

Role Description

: Vulnerability Management &

- Cyber Threat Intelligence Engineer Position Overview We seek an experienced Vulnerability Management &
- Cyber Threat Intelligence (CTI) Engineer to lead vulnerability identification, risk assessment, remediation tracking, and threat intelligence integration. This role owns the vulnerability lifecycle, ensures timely remediation, and integrates threat intelligence to protect critical assets.

Key Responsibilities Vulnerability Identification, Aggregation &
- Normalization

- Ingest and normalize vulnerability data from CrowdStrike Spotlight and related scanners (endpoint, network, cloud, web app) into standardized formats (CVE IDs, severity, discovery dates)
- Deduplicate entries, cross-reference against asset inventory for owner/business unit assignment, and filter false positives
- Track newly published CVEs and zero-days relevant to the technology stack Risk-Based Prioritization &
- Triage
- Assess vulnerabilities via risk models, threat actor targeting, and organizational standards; assign risk tiers (Critical/High/Medium/Low) driving SLA and escalation
- Escalate urgent cases (zero-day exploitation, sensitive systems); document prioritization rationale and re-prioritize as new intel, PoCs, or patches emerge Vulnerability Register Management &
- Lifecycle Tracking
- Own and update the master vulnerability register (ServiceNow or equivalent); monitor aging and SLA compliance, flagging breaches to owners/management
- Coordinate and verify remediation/compensating controls; document escalations (incompatibility, vendor delays) and confirm closure only after verified mitigation Remediation Assignment &
- Stakeholder Engagement
- Create actionable ServiceNow tickets; communicate priorities and escalate high-risk/non-compliant items to owners and Cyber Security leadership
- Recommend remediation approaches (patch windows, testing, mitigations); collaborate on constraints and maintain audit trails of decisions Compensating Controls &
- Exception Management
- Assess and document compensating controls when patches aren't feasible, with implementation guidance and residual risk assessment
- Support formal exception processes and track control effectiveness/implementation gaps Cloud Security Posture Management (CSPM)
- Scan cloud environments via CSPM tools; categorize misconfigurations (open S3 buckets, permissive IAM, unencrypted DBs) and route to owners/DevOps via ServiceNow




- Support CI/CD security scanning to prevent drift; identify systemic posture patterns across regions/teams Vulnerability Reporting &
- Governance
- Report month-on-month vulnerability volumes, High/Critical trends, and average time-to-remediation by severity/owner
- Identify systemic/recurrent issues with root cause analysis; provide industry/peer benchmarking where available Cyber Threat Intelligence Integration
- Analyze CTI feeds (CISA KEV, vendor advisories) to accelerate remediation for actively exploited vulnerabilities; cross-reference threat actor capabilities for exploitation likelihood
- Provide early warning on emerging/zero-day threats; support IR investigations; brief leadership and re-prioritize based on recent intelligence Threat Intelligence Consumption and Analysis
- Monitor CrowdStrike CAO Premium intelligence; identify threat actors, campaigns, and malware relevant to sector, geography, and technology estate (M365, Entra ID, CrowdStrike, Cloudflare, CyberArk, cloud, critical apps)
- Produce actionable assessments for Security Operations and technical stakeholders Threat Actor Tracking
- Maintain financial-sector threat actor profiles; track TTPs and map to MITRE ATT&CK;
- Identify adversary behavior changes/risk; provide periodic threat landscape updates to leadership Priority Intelligence Requirements (PIRs)
- Develop and maintain Priority Intelligence Requirements aligned to business risk, covering: financially motivated threats, BEC, identity-based attacks, insider threats, supply-chain/third-party concentration risks, and cloud threats
- Continuously assess whether intelligence requirements are being met Intelligence Driven Detection Engineering
- Convert CrowdStrike CAO intelligence into detection use cases; work with SIEM/SOAR Engineer to tune detections to adversary tradecraft
- Recommend monitoring use cases from threat actor TTPs; validate coverage against relevant MITRE ATT&CK; techniques IOC Management
- Collect, validate, enrich, and manage IOCs; distribute across CrowdStrike, SIEM, SOAR, email security, and other platforms
- Maintain IOC lifecycle (ingestion, validation, expiration, retirement) and measure operational effectiveness Threat Hunting Support




- Produce threat hunting hypotheses from intelligence reporting; develop hunting packages (TTPs, indicators, detection logic, methodology)
- Support investigations resulting from hunting activities Required Qualifications
- 10+ years of experience in vulnerability management, security operations, or related cybersecurity disciplines
- Demonstrated expertise with vulnerability management platforms (ServiceNow, Qualys, Tenable Nessus, Rapid7, or equivalent)
- Strong understanding of CVSS scoring, CVE databases, and vulnerability classification frameworks
- Proficiency with SIEM platforms and log aggregation systems
- Experience with threat intelligence platforms and CTI feed integration
- Knowledge of common vulnerability scanning tools (CrowdStrike Spotlight, Nessus, OpenVAS, Qualys, etc.)
- Strong written and verbal communication skills with ability to explain technical concepts to non-technical stakeholders
- Excellent project management and organizational skills with ability to manage multiple priorities
- Experience creating metrics-driven vulnerability reports and dashboards Preferred Qualifications
- Relevant certifications (CEH, CISSP, GIAC GEVA, GIAC GCIH, or equivalent)
- Experience with Cloud Security Posture Management (CSPM) tools such as Prisma Cloud, Wiz, or Lacework
- Familiarity with DevSecOps practices and CI/CD pipeline security integration
- Knowledge of compliance frameworks (PCI-DSS, SOC 2, ISO 27001, NIST, etc.)
- Experience with incident response and breach investigation
- Background in threat actor profiling and threat campaign analysis
- Proficiency in scripting or programming (Python, PowerShell, Bash) for automation and data processing
- Experience with multiple cloud platforms (AWS, Azure, GCP) Technical Skills &
- Tools
- Vulnerability Management Platforms: ServiceNow, Qualys, Tenable, Rapid7, Fortify
- Security &
- Threat Intelligence: CISA KEV, Shodan, Mitre ATT&CK;, Recorded Future, Flashpoint
- Cloud Security Tools: CrowdStrike Spotlight, Wiz, Prisma Cloud, Lacework, Qualys CSPM
- SIEM Platforms: Splunk, ELK Stack, Microsoft Sentinel
- Scanning Tools: Nessus, OpenVAS, Acunetix, Fortify SCA
- Data Analysis: Excel, Power BI, Splunk dashboards, data visualization tools
- Scripting/Automation: Python, PowerShell, Bash (preferred but not required)
- Operating Systems: Windows, Linux, cloud-native environments

Skills Threat Intelligence, Vulnerability Management, CSPM, Microsoft Azure, Python

📌 Architect I - Information Security (Thiruvananthapuram)
🏢 UST
📍 Thiruvananthapuram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: architect i - information security (thiruvananthapuram) / thiruvananthapuram

Subscribe to this job alert:

Get the latest job offers by email for: architect i - information security (thiruvananthapuram) / thiruvananthapuram