Estuate - Vulnerability Management Engineer - SIEM Tools

Estuate, Inc.

Kolkata District

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Estuate, Inc. seeks a Vulnerability Management Engineer to identify and drive remediation across enterprise environments, leveraging risk-based approaches to reduce the attack surface. You will manage scanning, triage findings, and coordinate with infrastructure, app, and cloud teams to improve security posture.

You will work with Tenable, Qualys, and Rapid7, integrate with ServiceNow CMDB, Tanium, and SIEM, and develop risk dashboards to track exposure, SLA adherence, and remediation progress.

Qualifications

  • Strong experience in vulnerability management and exposure management lifecycle.
  • Hands-on with Tenable, Qualys, or Rapid7.
  • Knowledge of CVEs, CVSS scoring, exploitability, and threat context.
  • Experience with enterprise environments (Windows, Linux, network, cloud).
  • Familiarity with Tanium Deploy/Comply, ServiceNow, and CMDB integrations.
  • Understanding of patching, configuration management, and remediation workflows.
  • Scripting/automation experience (Python, PowerShell, APIs).
  • Strong analytical and problem-solving skills.

Responsibilities

  • Perform and manage vulnerability scanning across infrastructure, endpoints, applications, and cloud environments
  • Analyze findings and prioritize remediation based on risk, exploitability, and business impact
  • Drive vulnerability lifecycle: discovery, validation, remediation, closure
  • Correlate vulnerabilities with threat intelligence and exposure context (CTEM approach)
  • Configure and manage exposure management tools (Tenable One, Tenable.io/sc, Qualys, Rapid7)
  • Integrate VM tools with Tanium, ServiceNow CMDB, SIEM, and asset management platforms
  • Support API integration and automation of scanning, ticketing, and reporting workflows
  • Partner with infrastructure, application, and cloud teams to drive remediation activities
  • Implement compensating controls where patching is not immediately feasible
  • Support patch management and configuration hardening initiatives
  • Develop risk-based dashboards and reports (exposure trends, SLA adherence, coverage)
  • Identify recurring vulnerabilities and root causes
  • Provide insights to support prioritization and decision-making
  • Support audit, compliance, and regulatory requirements (NIST, CIS, SOX)
  • Improve vulnerability prioritization using risk scoring, asset criticality, and exploit data
  • Enhance automation, coverage, and program maturity aligned to CTEM framework

Skills

Vulnerability management
Exposure management lifecycle
Tenable
Qualys
Rapid7
Windows
Linux
Tanium
ServiceNow
APIs
Python
PowerShell
MITRE ATT&CK

Tools

Tenable One
Tenable.io
Qualys
Rapid7
Tanium
ServiceNow CMDB
SIEM
APIs
Power BI
Tableau

Job description

Role Summary

The VM Engineer is responsible for identifying, analyzing, prioritizing, and driving remediation of vulnerabilities and security exposures across enterprise environments, leveraging risk-based approaches to reduce overall attack surface.

Job Title

Vulnerability Management (VM) Engineer

Key Responsibilities
Vulnerability & Exposure Management
  • Perform and manage vulnerability scanning across infrastructure, endpoints, applications, and cloud environments
  • Analyze findings and prioritize remediation based on risk, exploitability, and business impact
  • Drive vulnerability lifecycle: discovery, validation, remediation, closure
  • Correlate vulnerabilities with threat intelligence and exposure context (CTEM approach)
Tooling & Platform Management
  • Configure and manage exposure management tools (Tenable One, Tenable.io/sc, Qualys, Rapid7)
  • Integrate VM tools with Tanium, ServiceNow CMDB, SIEM, and asset management platforms
  • Support API integration and automation of scanning, ticketing, and reporting workflows
Remediation & Risk Reduction
  • Partner with infrastructure, application, and cloud teams to drive remediation activities
  • Implement compensating controls where patching is not immediately feasible
  • Support patch management and configuration hardening initiatives
Data Analysis & Reporting
  • Develop risk-based dashboards and reports (exposure trends, SLA adherence, coverage)
  • Identify recurring vulnerabilities and root causes
  • Provide insights to support prioritization and decision-making
Governance & Continuous Improvement
  • Support audit, compliance, and regulatory requirements (NIST, CIS, SOX, etc.)
  • Improve vulnerability prioritization using risk scoring, asset criticality, and exploit data
  • Enhance automation, coverage, and program maturity aligned to CTEM framework
Required Skills & Experience
  • Strong experience in vulnerability management and exposure management lifecycle
  • Hands‑on expertise with Tenable (preferred), Qualys, or Rapid7
  • Knowledge of CVEs, CVSS scoring, exploitability, and threat context
  • Experience with enterprise environments (Windows, Linux, network, cloud)
  • Familiarity with Tanium (Deploy/Comply), ServiceNow, and CMDB integrations
  • Understanding of patching, configuration management, and remediation workflows
  • Scripting/automation experience (Python, PowerShell, APIs)
  • Strong analytical and problem‑solving skills
Preferred Qualifications
  • Experience with Tenable One and CTEM (Continuous Threat Exposure Management)
  • Knowledge of MITRE ATT&CK, threat intelligence, and exploit frameworks
  • Exposure to cloud security (AWS, Azure) and container environments
  • Experience with Power BI/Tableau dashboards for VM reporting
  • Certifications: Security+, CEH, CISSP, GIAC VM certifications
Key Deliverables
  • Vulnerability scan reports and prioritized remediation plans
  • Risk‑based exposure dashboards and metrics
  • Automated workflows (scan, ticket, remediation tracking)
  • Integration artifacts (VM, Tanium, ServiceNow CMDB)
  • Root cause analysis and continuous improvement recommendations
Success Metrics
  • Reduction in critical/high vulnerabilities within SLA
  • Improved remediation cycle time and throughput
  • Increased asset coverage and scan completeness
  • Reduction in repeat/recurring vulnerabilities
  • Enhanced visibility into enterprise exposure and risk posture
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

TECHNICAL LEAD - Vulnerability Assessment
TECHNICAL LEAD - Vulnerability Assessment

Happiest Minds Technologies • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Senior Cybersecurity Incident Responder - Vulnerability Management
Senior Cybersecurity Incident Responder - Vulnerability Management

Baker Tilly • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Consultant - Vulnerability Management
Consultant - Vulnerability Management

YASH Technologies • Bengaluru

On-site
INR 800,000 - 1,200,000
Security Vulnerability Analyst
Security Vulnerability Analyst

Experian Group • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Manager- Threat and Vulnerability Management
Manager- Threat and Vulnerability Management

Kshema General Insurance Limited • Hyderabad

On-site
INR 350,000 - 700,000
Senior Cybersecurity Engineer – Exposure Management
Senior Cybersecurity Engineer – Exposure Management

Jobtailor • Hyderabad

On-site
INR 1,800,000 - 2,800,000
Cyber Security Vulnerability Assessment/ Management Specialist
Cyber Security Vulnerability Assessment/ Management Specialist

Sonata Software • Pune District

On-site
INR 1,200,000 - 2,000,000
Vulnerability & Patch Management Engineer
Vulnerability & Patch Management Engineer

TechDefence Labs • Mumbai

On-site
INR 1,200,000 - 1,800,000
Vulnerability and Patch Management Engineer
Vulnerability and Patch Management Engineer

Cywarden Global Services • Chandigarh, Pune District

On-site
INR 1,800,000 - 3,000,000
Full Stack Engineer
Full Stack Engineer

AagatiServe Pvt Ltd • Bengaluru

On-site
INR 2,600,000 - 4,200,000