Assistant Vice President - Vulnerability Management

SBI Card

Gurugram District

On-site

INR 1,200,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SBI Card seeks an experienced Infrastructure Vulnerability Management lead to implement and oversee vulnerability tools, assess risks, and drive remediation across its IT landscape. You will lead vulnerability assessments, perform penetration testing, and coordinate patch management to strengthen security posture.

The role requires strong knowledge of vulnerability management processes, compliance frameworks, and collaboration with senior leadership to enforce security controls and best

Qualifications

  • Understanding of Vulnerability Management Program including Assessment and Remediation.
  • Experience analyzing risk and prioritization of vulnerabilities, validating vulnerability reports and driving remediation.
  • Understanding of the overall threat and vulnerability management process, including metrics to measure performance.
  • Working knowledge of compliance frameworks and security management standards (ISO 27001, NIST CSF, PCI-DSS).
  • Thorough understanding of enterprise security controls, network protocols and OS environments (Windows/Linux).

Responsibilities

  • Lead Vulnerability Assessment, Penetration Testing & Patch Management programs.
  • Develop and monitor vulnerability management and security testing capabilities.
  • Coordinate patch management/remediation for all IT assets.
  • Provide technical expertise for information security policies and standards.
  • Conduct vulnerability assessments and communicate issues to technical and non-technical audiences.
  • Monitor vendor SLAs and oversee vendor teams for security program delivery.

Skills

Vulnerability management
Risk prioritization
Security testing
Compliance frameworks
Enterprise security controls
Windows/Linux security
Stakeholder management
Analytical thinking
Problem solving

Education

Bachelor's in CS/Engineering
Master's in CS

Tools

Nessus
Rapid7
AWS Inspector
Open source tools

Job description

Role Purpose

Responsible for implementing and managing Infrastructure vulnerability tools and processes to reduce technical risks due to vulnerabilities, including identifying and evaluating vulnerabilities and supporting remediation activities. This role is also responsible for leveraging expert knowledge of today's ever-changing cybersecurity and risk landscape to influence IT landscape across SBIC Card environment.

Role Accountability
  • Lead the Vulnerability Assessment, Penetration Testing & Patch Management Program in support of the functional & company strategy, goals, and performance objectives
  • Manage development, implementation, and effectiveness of vulnerability management and security testing programs, initiatives, and capabilities
  • Assist with planning, providing input on capabilities and methods used for vulnerability management and security testing, and driving improvements
  • Develop Vulnerability management framework, support compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks
  • Provide technical expertise for information security policies and standards
  • Conduct vulnerability assessments and penetration testing (application and/or infrastructure) and articulating security issues to technical and non-technical audience
  • Perform vulnerability risk profiling and prioritization of vulnerabilities
  • Identify, research, validate, and exploite various different known and unknown security vulnerabilities on server and client side
  • Perform regular status reviews with IT asset owners & senior leadership to ensure compliance with InfoSec policies
  • Coordinate patch management/Remediation activities for all IT assets (workstations, network, server, application, database etc.)
  • Develop and Monitor patch deployment schedules for all Vulnerability assessments and penetration testing on an ongoing basis as well as auditing for completeness
  • Provide communications across the organization, interfacing with senior leadership on vulnerability remediation, driving security hardening best practices, and representing the Vulnerability and Patch Management team
  • Maintain relationship with managed security services vendor leadership to ensure effective implementation and operation of security programs, ongoing support and deployment of competent resources
  • Oversee the development, implementation and maintenance of vendor standard operating procedures/ run book in line with SBI Card policies & standards
  • Provide technical & program management expertise and oversight over vendor teams
  • Monitor vendor SLAs, perform regular review with vendor management and report to SBI Card leadership
  • Ensure process documentation and compliance adherence
Measures of Success
  • Reduction in security vulnerabilities in SBI Card IT platforms
  • Number of enhancement opportunities identified for the security posture to reduce overall risk to SBI Card
  • Reduction in information leakage and exploitation from vulnerabilities
  • Security metrics / SLA / KPIs are within acceptable threshold
  • Timely updation of Application Security & Vulnerability Management related standards and SOPs and other documents
  • No adverse observations in Internal / External Audits
  • Process Adherence as per MOU
Technical Skills / Experience / Certifications
  • Understanding of Vulnerability Management Program including Assessment and Remediation
  • Experience analyzing risk and prioritization of vulnerabilities, validating vulnerability reports and driving remediation.
  • Understanding of the overall threat and vulnerability management process, including metrics to measure performance
  • Working knowledge of compliance frameworks and security management standards (e.g., ISO 27001, NIST CSF. PCI-DSS etc.)
  • Thorough understanding of enterprise security controls, network protocols and operating system (Windows/Linux environments)
  • Strong knowledge in industry standard VAPT tools like Nessus, Rapid7, AWS Inspector and open source tools
Competencies critical to the role
  • Stakeholder Management
  • Analytical ability
  • Innovation & Problem Solving
Qualification

Bachelor of Engineering in Computer Science / Engineering, Masters in Computer Science

Preferred Industry

BFSI / NBFC /E-commerce/IT & ITES / Telecom

Immediate joiners are preferred.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Manager - Infosec
Assistant Manager - Infosec

Crisil • Kurla

On-site
INR 1,400,000 - 2,400,000
Vulnerability Management
Vulnerability Management

Tekskills • Mumbai

On-site
INR 900,000 - 1,300,000
Manager - Cloud Security
Manager - Cloud Security

SBI Card • Gurugram District

On-site
INR 1,800,000 - 2,600,000
Application Security Manager
Application Security Manager

ICICI Bank • Mumbai

On-site
INR 1,200,000 - 1,500,000
Assistant Vice President - Insider Threat Lead
Assistant Vice President - Insider Threat Lead

SBI Card • Gurugram District

On-site
INR 1,400,000 - 2,100,000
Manager - Senior Incident Analyst
Manager - Senior Incident Analyst

SBI Cards and Payment Services Private Ltd. • Gurugram District

On-site
INR 1,500,000 - 1,900,000
Senior Associate - Cyber Security - VAPT
Senior Associate - Cyber Security - VAPT

BDO India • Pune District

On-site
INR 900,000 - 1,500,000
Vulnerability Management - Senior Associate
Vulnerability Management - Senior Associate

PwC Acceleration Center India • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Technical Analyst - Vulnerability Management [T500-28800]
Technical Analyst - Vulnerability Management [T500-28800]

CIBC India • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Competitive fixed pay
Performance-based incentives
Family-first benefits
+4
Technical Security Manager
Technical Security Manager

Pay10 India • New Delhi

On-site
INR 1,300,000 - 2,100,000