Cyber Threat Exposure Management Lead

Gruve

Maharashtra

On-site

INR 1,400,000 - 2,800,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Gruve is seeking an experienced CTEM Expert to design, implement, and operate exposure management programs for clients. You will work with CISOs, security teams, and IT owners to identify, prioritize, validate, and reduce cyber exposure across on-prem, cloud, and hybrid environments, driving measurable risk reduction over time.

You will lead end-to-end CTEM engagements, mature playbooks, and governance, while mentoring junior staff and aligning with client risk appetite and regulatory

Qualifications

  • BE/BTech (CS/IT/E&TC) or equivalent.
  • 5-10 years of cybersecurity experience with 3+ years in exposure management, vulnerability management, ASM, or red team/adversary simulation.
  • Hands-on with CTEM/exposure management platforms such as Tenable, Qualys VMDR/ETM, CrowdStrike Falcon Exposure Management, or similar.
  • Experience with attack surface management (ASM) and breach & attack simulation (BAS) platforms.
  • Cloud security posture familiarity (AWS, Azure, GCP) and CSPM tools; understanding of CTEM tooling.
  • Strong client-facing communication skills — translate exposure data into business risk narratives.

Responsibilities

  • Lead end-to-end CTEM engagements across the five stages: Scoping, Discovery, Prioritization, Validation, Mobilization.
  • Design and operationalize continuous exposure management programs tailored to client risk appetite and regulatory context.
  • Integrate data across vulnerability management, ASM, CSPM, threat intelligence, and BAS to build a unified exposure view.
  • Translate findings (CVEs, misconfigurations, exposed assets) into business-risk-prioritized remediation plans.
  • Drive adversarial validation with red/purple teams or automated platforms to confirm exploitability.
  • Own exposure reduction metrics and reporting for client leadership.
  • Coordinate remediation and patching with asset owners, IT, and SOC teams.
  • Build CTEM playbooks, governance, and risk-acceptance processes.
  • Support pre-sales activities — scoping calls, PoCs, and maturity assessments.
  • Mentor analysts and contribute to practice capability building.
  • Stay current on threat landscape and CTEM tooling ecosystem.

Skills

Cybersecurity
CTEM
Vulnerability management
ASM
BAS
Threat intelligence
Cloud security
MITRE ATT&CK
Stakeholder communication

Education

BE/BTech in CS/IT/E&TC

Tools

Tenable Exposure Management
Qualys VMDR/ETM
CrowdStrike Falcon Exposure Management
ASM tools

Job description

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position Summary

We are looking for an experienced CTEM (Continuous Threat Exposure Management) Expert to lead the design, implementation, and continuous operation of exposure management programs for our clients. This role sits at the intersection of vulnerability management, attack surface management, threat intelligence, and risk-based remediation helping clients move from periodic point-in-time assessments to a continuous, adversary-informed exposure reduction program aligned with 5-stage CTEM framework (Scoping, Discovery, Prioritization, Validation, and Mobilization).

You will work directly with client CISOs, security operations teams, and IT owners to build programs that identify, prioritize, validate, and reduce cyber exposure across on-prem, cloud, and hybrid environments and demonstrate measurable reduction in exploitable risk over time.

Key Roles & Responsibilities
  • Lead end-to-end delivery of CTEM engagements across the five stages: Scoping, Discovery, Prioritization, Validation, and Mobilization
  • Design and operationalize continuous exposure management programs tailored to client risk appetite, industry, and regulatory context
  • Integrate and correlate data across vulnerability management, attack surface management (ASM), cloud security posture management (CSPM), threat intelligence, and breach & attack simulation (BAS) tools to build a unified exposure view
  • Translate technical findings (CVEs, misconfigurations, exposed assets, identity risks) into business-risk-prioritized remediation plans using exploitability, asset criticality, and threat context (e.g., KEV, EPSS, active exploitation campaigns)
  • Drive adversarial validation of exposures through coordination with red/purple teams, pentesters, or automated validation platforms to confirm real-world exploitability
  • Own exposure reduction metrics and reporting and present progress to client stakeholders and leadership
  • Coordinate remediation and patch/mitigation execution with client asset owners, IT, and SOC teams; manage emergency response for zero-days and actively exploited vulnerabilities
  • Build and refine CTEM playbooks, runbooks, and governance frameworks; establish exception and risk-acceptance processes
  • Support pre-sales activities — scoping calls, proposals, PoCs, and CTEM maturity assessments for prospective clients
  • Mentor junior consultants/analysts and contribute to practice capability building, including tool evaluation and methodology development
  • Stay current on the threat landscape, emerging attack techniques, and CTEM tooling ecosystem
Mandatory Qualifications
  • BE/BTech (CS/IT/E&TC) or equivalent.
  • 5-10 years of overall cybersecurity experience, with 3+ years in exposure management, vulnerability management, attack surface management, or red team/adversary simulation
  • Strong hands-on experience with CTEM/exposure management platforms such as Tenable (Exposure Management/One), Qualys VMDR/ETM, CrowdStrike Falcon Exposure Management, or similar
  • Practical experience with attack surface management (ASM) tools and breach & attack simulation (BAS) platforms
  • Solid understanding of vulnerability prioritization frameworks: CVSS, EPSS, CISA KEV, exploit maturity, and asset-criticality-based risk scoring
  • Experience integrating exposure data with SIEM/SOAR, ticketing (ServiceNow, Jira), and patch management tools.
  • Familiarity with cloud security posture (AWS, Azure, GCP) and CSPM tools, and how cloud exposures fit into a unified CTEM program
  • Strong grasp of the MITRE ATT&CK framework and how attack-path/graph analysis supports validation and prioritization
  • Experience defining and reporting exposure/remediation KPIs (MTTD, MTTR, MTRER, risk reduction trend lines) to executive and client audiences
  • Working knowledge of relevant compliance/regulatory frameworks
  • Excellent client-facing communication skills — able to translate technical exposure data into business risk narratives for CISOs and boards
Preferred Qualifications
  • Relevant certifications: CISSP, CISM, Tenable/Qualys certifications
  • Experience building or scaling a CTEM-as-a-Service offering within an MSSP/consulting practice
  • Experience with pre-sales, proposal writing, and CTEM maturity/readiness assessments
  • Prior experience mentoring teams or leading a practice/pod within a cybersecurity consulting or MSSP environment
Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Exposure Management Lead
Cyber Threat Exposure Management Lead

Gruve • Pune District

On-site
INR 1,800,000 - 3,200,000
Security Consultant II
Security Consultant II

Gruve • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Security Consultant II
Security Consultant II

Gruve • Pune District

On-site
INR 1,200,000 - 1,800,000
Security Analyst I
Security Analyst I

gruve • Pune District

On-site
INR 600,000 - 900,000
Threat Hunter Analyst
Threat Hunter Analyst

Gruve • Pune District

On-site
INR 1,000,000 - 1,500,000
Dynamic work environment
Commitment to diversity and inclusion
Senior Pre-Sales Consultant - CyberSecurity
Senior Pre-Sales Consultant - CyberSecurity

Gruve • Mumbai

On-site
INR 1,500,000 - 2,500,000
Dynamic work environment
Inclusive workplace culture
Continuous learning opportunities
Senior Project Manager - (Cybersecurity Services)
Senior Project Manager - (Cybersecurity Services)

Gruve • Pune District

On-site
INR 2,500,000 - 4,000,000
Cyber Threat Exposure Management Analyst
Cyber Threat Exposure Management Analyst

Version 1 • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Principal Engineer
Principal Engineer

Insight • Gurugram District

On-site
INR 1,500,000 - 2,000,000
Medical Insurance
Health Benefits
Shift Allowance
+1
Senior Cybersecurity Engineer – Exposure Management
Senior Cybersecurity Engineer – Exposure Management

Syneos Health, Inc. • Madhapur

On-site
INR 3,500,000 - 6,500,000