28 Sep
|
SHI Solutions India
|
Hyderabad
28 Sep
SHI Solutions India
Hyderabad
Vulnerability Management Lead
Job Summary
We are seeking an experienced Vulnerability Management Lead with 6–10 years of cybersecurity experience to lead enterprise-wide vulnerability management operations. The role is responsible for driving vulnerability discovery, risk prioritisation, remediation governance, SLA management, executive reporting, and cross-functional coordination with infrastructure, application, IAM, endpoint security, and patch management teams. The ideal candidate will have solid hands-on expertise with Tenable, Rapid7/InsightVM, Tanium, TruOps, and related cybersecurity technologies, along with experience leading teams and supporting global customers.
Key Responsibilities
- Lead the end-to-end Vulnerability Management programme across servers, endpoints, networks, cloud environments, applications, IAM, and privileged access platforms.
- Define and manage vulnerability scanning strategies, authenticated scan coverage, remediation governance, and exception management.
- Analyse and validate vulnerability findings from Tenable and Rapid7/InsightVM, prioritising risks based on CVSS, exploitability, asset criticality, and business impact.
- Collaborate with infrastructure, patch management, application, endpoint security, and IAM teams to drive timely remediation.
- Track remediation SLAs, risk acceptance, and compliance using TruOps or similar GRC platforms.
- Partner with patch management teams using Tanium and Automox migration workflows to ensure effective remediation.
- Develop and present executive dashboards and reports covering vulnerability trends, ageing, SLA compliance, remediation performance, and asset coverage.
- Review identity and privileged access vulnerabilities involving Okta and CyberArk.
- Collaborate with endpoint security teams using CrowdStrike and SentinelOne to correlate vulnerability exposure with endpoint risks.
- Define and enhance vulnerability management processes, playbooks, operational runbooks, and reporting standards.
- Lead weekly and monthly vulnerability review meetings with internal stakeholders and US-based customers.
- Mentor Vulnerability Management Engineers and review technical assessments, remediation recommendations, and reporting.
- Ensure alignment with security frameworks such as NIST, CIS Controls, ISO 27001, and PCI-DSS.
Required Skills & Experience
- 6–10 years of experience in Cybersecurity, Vulnerability Management, Security Operations, or Infrastructure Security.
- Minimum 2 years of experience leading teams, coordinating security operations, or managing vulnerability programmes.
- Strong hands-on experience with Tenable, Rapid7/InsightVM, Tanium, vulnerability assessment, CVE/CVSS analysis, remediation governance, and SLA management.
- Experience in executive reporting, stakeholder management, and customer-facing engagements.
- Exposure to TruOps, Cyberfusion, Okta, CyberArk, CrowdStrike, and SentinelOne is highly preferred.
- Experience supporting US-based customers and working during US business hours is preferred.
Tools & Technologies
- Vulnerability Management: Tenable, Rapid7/InsightVM
- Patch Management: Tanium, Automox
- Risk & GRC: TruOps, Cyberfusion
- IAM/PAM: Okta, CyberArk
- Endpoint Security: CrowdStrike, SentinelOne
- Reporting & Ticketing: Power BI, Excel, ServiceNow, Jira
Education & Certifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline (or equivalent experience).
- Preferred certifications include CISSP, CISM, CompTIA Security+, CySA+, CEH, GSEC, Tenable, Rapid7, ITIL Foundation, or equivalent industry certifications.
📌 Senior Security Analyst (Hyderabad)
🏢 SHI Solutions India
📍 Hyderabad