Architect I - Information Security

UST

Thiruvananthapuram

On-site

INR 1,500,000 - 2,100,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

UST in India seeks an experienced Vulnerability Management & Cyber Threat Intelligence Engineer to lead vulnerability identification, risk assessment, remediation tracking, and threat intelligence integration across endpoints, cloud, and apps.

You will own the vulnerability lifecycle, coordinate remediation with owners, and produce metrics-driven reports to Security leadership. Strong experience with ServiceNow, Qualys, Nessus, CrowdStrike Spotlight, and CSPM tools is required.

Qualifications

  • 10+ years of experience in vulnerability management, security operations, or related cybersecurity disciplines.
  • Expertise with vulnerability management platforms (ServiceNow, Qualys, Tenable Nessus, Rapid7, or equivalent).
  • Strong understanding of CVSS scoring, CVE databases, and vulnerability classification frameworks.
  • Proficiency with SIEM platforms and log aggregation systems; CTI feed integration.

Responsibilities

  • Lead vulnerability identification, aggregation, and normalization across endpoints, network, cloud, and web apps.
  • Assess vulnerabilities using risk models; assign risk tiers and drive SLA/escalation.
  • Own and update the master vulnerability register; monitor aging and SLA compliance.
  • Coordinate remediation and compensating controls; document escalations and verify closure.
  • Create actionable ServiceNow tickets; communicate priorities to owners and leadership.
  • Analyze CTI feeds to accelerate remediation and provide early warnings on threats.
  • Produce monthly vulnerability reports highlighting trends by severity and owner.
  • Develop and maintain threat intelligence requirements aligned to business risk.

Skills

Threat Intelligence
Vulnerability Management
CSPM
Microsoft Azure
Python

Tools

ServiceNow
Qualys
Nessus
Rapid7
Fortify
CrowdStrike Spotlight
Prisma Cloud

Job description

Role DescriptionJob Description: Vulnerability Management & Cyber Threat Intelligence Engineer Position Overview We seek an experienced Vulnerability Management & Cyber Threat Intelligence (CTI) Engineer to lead vulnerability identification, risk assessment, remediation tracking, and threat intelligence integration. This role owns the vulnerability lifecycle, ensures timely remediation, and integrates threat intelligence to protect critical assets. Key Responsibilities Vulnerability Identification, Aggregation & Normalization

  • Ingest and normalize vulnerability data from CrowdStrike Spotlight and related scanners (endpoint, network, cloud, web app) into standardized formats (CVE IDs, severity, discovery dates)
  • Deduplicate entries, cross-reference against asset inventory for owner/business unit assignment, and filter false positives
  • Track newly published CVEs and zero-days relevant to the technology stack Risk-Based Prioritization & Triage
  • Assess vulnerabilities via risk models, threat actor targeting, and organizational standards; assign risk tiers (Critical/High/Medium/Low) driving SLA and escalation
  • Escalate urgent cases (zero-day exploitation, sensitive systems); document prioritization rationale and re-prioritize as new intel, PoCs, or patches emerge Vulnerability Register Management & Lifecycle Tracking
  • Own and update the master vulnerability register (ServiceNow or equivalent); monitor aging and SLA compliance, flagging breaches to owners/management
  • Coordinate and verify remediation/compensating controls; document escalations (incompatibility, vendor delays) and confirm closure only after verified mitigation Remediation Assignment & Stakeholder Engagement
  • Create actionable ServiceNow tickets; communicate priorities and elevate high-risk/non-compliant items to owners and Cyber Security leadership
  • Recommend remediation approaches (patch windows, testing, mitigations); collaborate on constraints and maintain audit trails of decisions Compensating Controls & Exception Management
  • Assess and document compensating controls when patches aren't feasible, with implementation guidance and residual risk assessment
  • Support formal exception processes and track control effectiveness/implementation gaps Cloud Security Posture Management (CSPM)
  • Scan cloud environments via CSPM tools; categorize misconfigurations (open S3 buckets, permissive IAM, unencrypted DBs) and route to owners/DevOps via ServiceNow
  • Support CI/CD security scanning to prevent drift; identify systemic posture patterns across regions/teams Vulnerability Reporting & Governance
  • Report month-on-month vulnerability volumes, High/Critical trends, and average time-to-remediation by severity/owner
  • Identify systemic/recurrent issues with root cause analysis; provide industry/peer benchmarking where available Cyber Threat Intelligence Integration
  • Analyze CTI feeds (CISA KEV, vendor advisories) to accelerate remediation for actively exploited vulnerabilities; cross-reference threat actor capabilities for exploitation likelihood
  • Provide early warning on emerging/zero-day threats; support IR investigations; brief leadership and re-prioritize based on new intelligence Threat Intelligence Consumption and Analysis
  • Monitor CrowdStrike CAO Premium intelligence; identify threat actors, campaigns, and malware relevant to sector, geography, and technology estate (M365, Entra ID, CrowdStrike, Cloudflare, CyberArk, cloud, critical apps)
  • Produce actionable assessments for Security Operations and technical stakeholders Threat Actor Tracking
  • Maintain financial-sector threat actor profiles; track TTPs and map to MITRE ATT&CK
  • Identify adversary behavior changes/risk; provide periodic threat landscape updates to leadership Priority Intelligence Requirements (PIRs)
  • Develop and maintain Priority Intelligence Requirements aligned to business risk, covering: financially motivated threats, BEC, identity-based attacks, insider threats, supply-chain/third-party concentration risks, and cloud threats
  • Continuously assess whether intelligence requirements are being met Intelligence Driven Detection Engineering
  • Convert CrowdStrike CAO intelligence into detection use cases; work with SIEM/SOAR Engineer to tune detections to adversary tradecraft
  • Recommend monitoring use cases from threat actor TTPs; validate coverage against relevant MITRE ATT&CK techniques IOC Management
  • Collect, validate, enrich, and manage IOCs; distribute across CrowdStrike, SIEM, SOAR, email security, and other platforms
  • Maintain IOC lifecycle (ingestion, validation, expiration, retirement) and measure operational effectiveness Threat Hunting Support
  • Produce threat hunting hypotheses from intelligence reporting; develop hunting packages (TTPs, indicators, detection logic, methodology)
  • Support investigations resulting from hunting activities Required Qualifications
  • 10+ years of experience in vulnerability management, security operations, or related cybersecurity disciplines
  • Demonstrated expertise with vulnerability management platforms (ServiceNow, Qualys, Tenable Nessus, Rapid7, or equivalent)
  • Strong understanding of CVSS scoring, CVE databases, and vulnerability classification frameworks
  • Proficiency with SIEM platforms and log aggregation systems
  • Experience with threat intelligence platforms and CTI feed integration
  • Knowledge of common vulnerability scanning tools (CrowdStrike Spotlight, Nessus, OpenVAS, Qualys, etc.)
  • Strong written and verbal communication skills with ability to explain technical concepts to non-technical stakeholders
  • Excellent project management and organizational skills with ability to manage multiple priorities
  • Experience creating metrics-driven vulnerability reports and dashboards Preferred Qualifications
  • Relevant certifications (CEH, CISSP, GIAC GEVA, GIAC GCIH, or equivalent)
  • Experience with Cloud Security Posture Management (CSPM) tools such as Prisma Cloud, Wiz, or Lacework
  • Familiarity with DevSecOps practices and CI/CD pipeline security integration
  • Knowledge of compliance frameworks (PCI-DSS, SOC 2, ISO 27001, NIST, etc.)
  • Experience with incident response and breach investigation
  • Background in threat actor profiling and threat campaign analysis
  • Proficiency in scripting or programming (Python, PowerShell, Bash) for automation and data processing
  • Experience with multiple cloud platforms (AWS, Azure, GCP) Technical Skills & Tools
  • Vulnerability Management Platforms: ServiceNow, Qualys, Tenable, Rapid7, Fortify
  • Security & Threat Intelligence: CISA KEV, Shodan, Mitre ATT&CK, Recorded Future, Flashpoint
  • Cloud Security Tools: CrowdStrike Spotlight, Wiz, Prisma Cloud, Lacework, Qualys CSPM
  • SIEM Platforms: Splunk, ELK Stack, Microsoft Sentinel
  • Scripting/Automation: Python, PowerShell, Bash (preferred but not required)
  • Operating Systems: Windows, Linux, cloud-native environments
Role DescriptionJob Description: Vulnerability Management & Cyber Threat Intelligence Engineer Position Overview We seek an experienced Vulnerability Management & Cyber Threat Intelligence (CTI) Engineer to lead vulnerability identification, risk assessment, remediation tracking, and threat intelligence integration. This role owns the vulnerability lifecycle, ensures timely remediation, and integrates threat intelligence to protect critical assets. Key Responsibilities Vulnerability Identification, Aggregation & Normalization
  • Ingest and normalize vulnerability data from CrowdStrike Spotlight and related scanners (endpoint, network, cloud, web app) into standardized formats (CVE IDs, severity, discovery dates)
  • Deduplicate entries, cross-reference against asset inventory for owner/business unit assignment, and filter false positives
  • Track newly published CVEs and zero-days relevant to the technology stack Risk-Based Prioritization & Triage
  • Assess vulnerabilities via risk models, threat actor targeting, and organizational standards; assign risk tiers (Critical/High/Medium/Low) driving SLA and escalation
  • Escalate urgent cases (zero-day exploitation, sensitive systems); document prioritization rationale and re-prioritize as new intel, PoCs, or patches emerge Vulnerability Register Management & Lifecycle Tracking
  • Own and update the master vulnerability register (ServiceNow or equivalent); monitor aging and SLA compliance, flagging breaches to owners/management
  • Coordinate and verify remediation/compensating controls; document escalations (incompatibility, vendor delays) and confirm closure only after verified mitigation Remediation Assignment & Stakeholder Engagement
  • Create actionable ServiceNow tickets; communicate priorities and elevate high-risk/non-compliant items to owners and Cyber Security leadership
  • Recommend remediation approaches (patch windows, testing, mitigations); collaborate on constraints and maintain audit trails of decisions Compensating Controls & Exception Management
  • Assess and document compensating controls when patches aren't feasible, with implementation guidance and residual risk assessment
  • Support formal exception processes and track control effectiveness/implementation gaps Cloud Security Posture Management (CSPM)
  • Scan cloud environments via CSPM tools; categorize misconfigurations (open S3 buckets, permissive IAM, unencrypted DBs) and route to owners/DevOps via ServiceNow
  • Support CI/CD security scanning to prevent drift; identify systemic posture patterns across regions/teams Vulnerability Reporting & Governance
  • Report month-on-month vulnerability volumes, High/Critical trends, and average time-to-remediation by severity/owner
  • Identify systemic/recurrent issues with root cause analysis; provide industry/peer benchmarking where available Cyber Threat Intelligence Integration
  • Analyze CTI feeds (CISA KEV, vendor advisories) to accelerate remediation for actively exploited vulnerabilities; cross-reference threat actor capabilities for exploitation likelihood
  • Provide early warning on emerging/zero-day threats; support IR investigations; brief leadership and re-prioritize based on new intelligence Threat Intelligence Consumption and Analysis
  • Monitor CrowdStrike CAO Premium intelligence; identify threat actors, campaigns, and malware relevant to sector, geography, and technology estate (M365, Entra ID, CrowdStrike, Cloudflare, CyberArk, cloud, critical apps)
  • Produce actionable assessments for Security Operations and technical stakeholders Threat Actor Tracking
  • Maintain financial-sector threat actor profiles; track TTPs and map to MITRE ATT&CK
  • Identify adversary behavior changes/risk; provide periodic threat landscape updates to leadership Priority Intelligence Requirements (PIRs)
  • Develop and maintain Priority Intelligence Requirements aligned to business risk, covering: financially motivated threats, BEC, identity-based attacks, insider threats, supply-chain/third-party concentration risks, and cloud threats
  • Continuously assess whether intelligence requirements are being met Intelligence Driven Detection Engineering
  • Convert CrowdStrike CAO intelligence into detection use cases; work with SIEM/SOAR Engineer to tune detections to adversary tradecraft
  • Recommend monitoring use cases from threat actor TTPs; validate coverage against relevant MITRE ATT&CK techniques IOC Management
  • Collect, validate, enrich, and manage IOCs; distribute across CrowdStrike, SIEM, SOAR, email security, and other platforms
  • Maintain IOC lifecycle (ingestion, validation, expiration, retirement) and measure operational effectiveness Threat Hunting Support
  • Produce threat hunting hypotheses from intelligence reporting; develop hunting packages (TTPs, indicators, detection logic, methodology)
  • Support investigations resulting from hunting activities Required Qualifications
  • 10+ years of experience in vulnerability management, security operations, or related cybersecurity disciplines
  • Demonstrated expertise with vulnerability management platforms (ServiceNow, Qualys, Tenable Nessus, Rapid7, or equivalent)
  • Strong understanding of CVSS scoring, CVE databases, and vulnerability classification frameworks
  • Proficiency with SIEM platforms and log aggregation systems
  • Experience with threat intelligence platforms and CTI feed integration
  • Knowledge of common vulnerability scanning tools (CrowdStrike Spotlight, Nessus, OpenVAS, Qualys, etc.)
  • Strong written and verbal communication skills with ability to explain technical concepts to non-technical stakeholders
  • Excellent project management and organizational skills with ability to manage multiple priorities
  • Experience creating metrics-driven vulnerability reports and dashboards Preferred Qualifications
  • Relevant certifications (CEH, CISSP, GIAC GEVA, GIAC GCIH, or equivalent)
  • Experience with Cloud Security Posture Management (CSPM) tools such as Prisma Cloud, Wiz, or Lacework
  • Familiarity with DevSecOps practices and CI/CD pipeline security integration
  • Knowledge of compliance frameworks (PCI-DSS, SOC 2, ISO 27001, NIST, etc.)
  • Experience with incident response and breach investigation
  • Background in threat actor profiling and threat campaign analysis
  • Proficiency in scripting or programming (Python, PowerShell, Bash) for automation and data processing
  • Experience with multiple cloud platforms (AWS, Azure, GCP) Technical Skills & Tools
  • Vulnerability Management Platforms: ServiceNow, Qualys, Tenable, Rapid7, Fortify
  • Security & Threat Intelligence: CISA KEV, Shodan, Mitre ATT&CK, Recorded Future, Flashpoint
  • Cloud Security Tools: CrowdStrike Spotlight, Wiz, Prisma Cloud, Lacework, Qualys CSPM
  • SIEM Platforms: Splunk, ELK Stack, Microsoft Sentinel
  • Scripting/Automation: Python, PowerShell, Bash (preferred but not required)
  • Operating Systems: Windows, Linux, cloud-native environments
SkillsThreat Intelligence, Vulnerability Management, CSPM, Microsoft Azure, Python
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Vulnerability Analyst
Security Vulnerability Analyst

Experian Group • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

On-site
INR 1,500,000 - 2,100,000
Flexible/Remote work
Security Engineer
Security Engineer

AppViewX • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Neurealm • Chennai District

On-site
INR 2,800,000 - 6,000,000
Senior Security Administrator
Senior Security Administrator

Indecomm Global Services (India) • Bengaluru

On-site
INR 1,800,000 - 3,200,000
VAPT Security Engineer
VAPT Security Engineer

Zohorecruit • Hyderabad

Hybrid
INR 1,800,000 - 2,800,000
Vulnerability Analyst
Vulnerability Analyst

SHI • Hyderabad

On-site
INR 900,000 - 1,300,000
Vulnerability Lead
Vulnerability Lead

SHI • Hyderabad

On-site
INR 1,800,000 - 3,600,000
Penetration Testing Senior Consultant
Penetration Testing Senior Consultant

Alignity Solutions • Hyderabad

Hybrid
INR 1,800,000 - 3,000,000
Hybrid work
SENIOR SUPPORT ENGINEER - Cyber Security
SENIOR SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 2,400,000 - 4,200,000