09 Oct
|
Achieve Cybersecurity Solutions
|
Hyderabad
09 Oct
Achieve Cybersecurity Solutions
Hyderabad
Role & responsibilities
Job Summary
We are looking for a Vulnerability Management Analyst with 2-3 years of experience to support and independently drive day-to-day vulnerability management activities. The ideal candidate should have a solid understanding of vulnerability management, remediation coordination, and security best practices, along with strong communication and organizational skills. The candidate will work closely with infrastructure, application, cloud, and security teams to ensure timely remediation of vulnerabilities while helping improve the overall vulnerability management program.
This role requires someone who can work independently, lead daily operational activities, support onboarding of new security tools, and contribute to process improvements across the team.
Key Responsibilities
- Perform vulnerability assessment reviews using Qualys, Nessus, or equivalent vulnerability management platforms.
- Analyze vulnerability scan results and validate findings to identify true risk and remediation priorities.
- Coordinate with infrastructure, application, cloud, and endpoint teams to drive remediation within defined SLAs.
- Track remediation progress and follow up with asset owners until vulnerabilities are resolved.
- Review vulnerabilities using CVSS scoring, exploitability, business criticality, and threat intelligence to support risk-based prioritization.
- Monitor patch compliance and remediation effectiveness across Windows, Linux, network, and cloud assets.
- Prepare operational dashboards, reports, and executive summaries for management.
- Maintain accurate documentation of vulnerability findings, remediation activities, exceptions, and risk acceptances.
- Support onboarding, testing, and operationalization of new vulnerability management and security tools.
- Identify opportunities to improve processes, workflows, reporting, and automation.
- Work independently to organize daily team activities and help improve operational efficiency.
- Collaborate with Security Operations, Incident Response, Cloud Security, Infrastructure, and Application teams on vulnerability-related investigations.
- Participate in vulnerability review meetings and communicate technical findings to both technical and non-technical stakeholders.
Preferred candidate profile
- 2-3 years of experience in Vulnerability Management, Security Operations, or Cybersecurity.
- Good understanding of vulnerabilities, CVEs, CVSS scoring, and risk prioritization.
- Hands-on experience with vulnerability scanning tools such as:
- Qualys
- Nessus
- Tenable
- Good understanding of:
- Windows Server
- Linux
- Networking fundamentals
- Servers and endpoints
- Understanding of patch management lifecycle and remediation tracking.
- Knowledge of IT infrastructure and asset management.
- Good understanding of OWASP Top 10, including:
- SQL Injection
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Broken Access Control
- Authentication & Authorization issues
- Security Misconfiguration
- Vulnerable Components
- Server-Side Request Forgery (SSRF)
- Experience working with ServiceNow or similar ticketing platforms.
- Valuable analytical and troubleshooting skills.
- Ability to work independently with minimal supervision.
Leadership & Soft Skills
- Excellent verbal and written communication skills.
- Strong stakeholder management and coordination skills.
- Ability to independently lead remediation discussions with technical teams.
- Good organizational and planning skills.
- Ability to manage multiple priorities and meet deadlines.
- Project coordination skills with the ability to support new security tool onboarding and process improvements.
- Self-driven with a continuous improvement mindset.
- Comfortable mentoring junior analysts and sharing knowledge within the team.
📌 Security Analyst (Hyderabad)
🏢 Achieve Cybersecurity Solutions
📍 Hyderabad