Vulnerability and Patch Management Engineer (Pune)

Vulnerability and Patch Management Engineer (Pune)

24 Sep
|
Cywarden
|
Pune

24 Sep

Cywarden

Pune

Vulnerability and Patch Management Engineer

Department: Vulnerability Management

Location: Pune/Mohali

Employment Type: Full-time

Experience: 8 years

Shift: General shift, with on-call availability for critical/zero-day escalations in a 24x7 operations model

Role Overview

We are hiring a Senior Lead – Patch & Vulnerability Management to architect and operationalize our enterprise-wide remediation program across Azure-first hybrid environments. This is a strategic, hands-on leadership role owning the full lifecycle—discovery, risk-based prioritization, patch engineering, automation, verification, and executive reporting. You will define SLAs, lead zero-day response, and mentor a team of engineers.

- Key Responsibilities
- Highly technical Vulnerability Management Lead responsible for designing, operating, and continuously improving the organization's enterprise vulnerability management across Microsoft Azure infrastructure.
- The candidate must have deep hands-on experience with the Microsoft Defender XDR ecosystem, including Microsoft Defender for Cloud, Microsoft Defender Vulnerability Management (TVM), Microsoft Defender for Endpoint (MDE), Microsoft Intune, Azure Arc, Azure Update Manager, Microsoft Entra ID, Azure Resource Graph, Azure Policy, and Kusto Query Language (KQL).
- The role will own the complete vulnerability lifecycle from asset discovery and inventory → vulnerability detection → exposure analysis → risk-based prioritization → remediation orchestration → patch validation → revalidation → reporting and risk governance.
- should be capable of independently investigating vulnerabilities at the host, software, cloud-resource, identity, network, and application layers and translating technical findings into actionable remediation requirements.
- Identify gaps between the CMDB/asset inventory, Intune inventory, Defender inventory, Azure inventory, and actual deployed infrastructure.
- Identify unmanaged/unonboarded assets.
- Establish vulnerability coverage KPIs for the entire environment.




- Strong practical knowledge of Microsoft Defender Vulnerability Management / Threat & Vulnerability Management (TVM) is mandatory.
- Lead technical response for zero-day vulnerabilities: impact assessment, emergency patching, compensating controls, and post-incident review.
- Patch Management & Remediation Architecture
- Architect scalable patching infrastructure using SCCM/MECM, Azure Update Manager, WSUS, Microsoft Intune, and Patch My PC.
- Engineer automated remediation pipelines integrating patching tools with vulnerability scanners and ServiceNow.
- Design ring-based rollouts, maintenance windows, and canary deployments balancing security velocity with operational stability.
- Lead remediation across Azure-first hybrid environments using Azure Update Manager, Microsoft Defender for Cloud, Azure Policy, and Azure Automation.
- Extend capabilities to AWS and GCP workloads via cross-cloud integration (AWS Inspector, GCP Security Command Center).
- Run SLA-driven operations through ServiceNow—incident, problem, change management, CAB coordination, API integration, and executive dashboards.
- Define and track SLAs, KPIs, and MTTR; present metrics to senior leadership.
- Build automation pipelines using PowerShell, Azure Automation, and Ansible/AWX integrating SCCM/Intune/Update Manager with ServiceNow for seamless change management.
- Evaluate and integrate AI-assisted prioritization and remediation platforms.
- Mentor and lead VM analysts and remediation engineers; partner with infrastructure, cloud, DevOps, and CAB teams.

Required Skills & Experience

- Experience: 8 years in Vulnerability/Patch Management, with 3–4 years in a Lead or Architect role.
- Vulnerability Management: End-to-end VM lifecycle management, including discovery, assessment, prioritization, remediation, validation, and reporting.




- Microsoft Security: Solid hands-on experience with Defender XDR, Defender for Cloud, Defender TVM, MDE, Intune, Azure Arc, Azure Update Manager, Entra ID, Azure Policy, and KQL.
- Patch Management: Expertise in SCCM/MECM, Azure Update Manager, WSUS, Intune, and Patch My PC.
- Cloud Security: Experience managing vulnerabilities across Azure and hybrid environments. AWS/GCP exposure is preferred.
- Automation: Strong PowerShell, Python, or Bash skills. Ansible/AWX and Azure Automation are an advantage.
- ServiceNow: Strong experience with incident, change, problem, CAB, API integration, SLA, and reporting processes.
- Zero-Day Response: Experience with impact assessment, emergency patching, compensating controls, and vulnerability revalidation.
- Asset Management: Ability to identify gaps across CMDB, Intune, Defender, Azure, and actual infrastructure.
- Risk & Governance: Experience managing SLAs, KPIs, MTTR, vulnerability coverage, and executive reporting.
- Leadership: Experience leading VM/remediation teams and coordinating with Infrastructure, Cloud, DevOps, and Security teams.
- Certifications: AZ-104, AZ-500, CISSP, CISM, or ITIL are preferred.

Good to Have

- SOAR/orchestration platform experience; AI/LLM-assisted security workflows
- Regulated environments (financial services, healthcare) with compliance mapping (NIST, CIS, ISO 27001, PCI-DSS)
- CMDB/asset-inventory hygiene, dependency mapping
- Container security (Kubernetes, Docker) and IaC scanning (Checkov, Terrascan)
- Certifications (Preferred, Not Mandatory)
- Microsoft: AZ-104, AZ-500, MD-102
- CISSP, CISM, CCSP
- Qualys/Tenable Certified Specialist
- ITIL Foundation

What We Offer

- Strategic ownership of an enterprise-scale, automation-driven remediation program
- Opportunity to design AI-assisted workflows—not just operate legacy processes
- Clear growth path to Architect and Program-Lead roles
- Certification sponsorship and continuous learning support
- Competitive compensation

Pay: ₹1,500,000.00 - ₹2,000,000.00 per year

Work Location: In person

📌 Vulnerability and Patch Management Engineer (Pune)
🏢 Cywarden
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: vulnerability and patch management engineer (pune) / pune

Subscribe to this job alert:

Get the latest job offers by email for: vulnerability and patch management engineer (pune) / pune