Principal Engineer

Cyod

Dadri

Hybrid

INR 3,000,000 - 5,500,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Health Benefits
Learning Platform
Certificate Reimbursement
Shift Allowance

Job summary

Insight is seeking a Principal Engineer (Cyber Exposure) to lead vulnerability management and risk‑based prioritization across hybrid environments in India. You will partner with CTEM/CPEN teams to ensure timely remediation, dashboards, and client engagement while advancing automation and playbooks.

Responsibilities include managing vulnerabilities end‑to‑end, validating findings, and collaborating with ServiceNow and security operations.

Qualifications

  • 6–10 years of experience in vulnerability management, security operations, IT systems administration, or related cybersecurity discipline.
  • Hands-on experience with at least one enterprise vulnerability management platform — Qualys strongly preferred; Tenable, Rapid7 InsightVM, or Microsoft Defender VM acceptable.
  • Working understanding of CVSS, EPSS, and risk-based vulnerability prioritisation concepts.
  • Familiarity with patch and endpoint management tooling (e.g., Intune/SCCM, automated patching solutions).
  • Experience operating within an ITSM/ticketing platform (ServiceNow preferred).
  • Solid grasp of networking, Windows and Linux operating systems, and common enterprise infrastructure.
  • Bachelor’s degree in Information Security, Computer Science, or a related field — or equivalent practical experience.

Responsibilities

  • Operate vulnerability management tooling to discover, catalog, and enrich an accurate inventory of assets and exposures.
  • Prioritise remediation using risk-based scoring that combines CVSS, EPSS, exploit availability, threat intel, and asset criticality.
  • Validate findings to confirm exploitability and reduce false positives before remediation.
  • Maintain exposure dashboards and metrics and surface emerging risk to senior analysts and clients.
  • Own the ticketing and remediation lifecycle from finding through verified closure within the ITSM platform.

Skills

Vulnerability management
Security operations
IT systems administration
Risk-based prioritization
Networking basics
Windows & Linux

Education

Bachelor's degree in Information Security/CS

Tools

Qualys VMDR
TruRisk
Microsoft Defender VM
ServiceNow

Job description

Principal Engineer (Cyber Exposure)

Location: This is a hybrid opportunity in Delhi NCR, Bangalore, Hyderabad, Gurugram, Pune, Trivandrum area.

Insight at a Glance
  • 14,000+ engaged teammates globally with operations in 25 countries across the globe.
  • Received 35+ industry and partner awards in the past year
  • $9.2 billion in revenue
  • #20 on Fortune’s World's Best Workplaces™ list
  • #14 on Forbes World's Best Employers in IT – 2023
  • #23 on Forbes Best Employers for Women in IT- 2023
  • $1.4M+ total charitable contributions in 2023 by Insight globally

Now is the time to bring your expertise to Insight. We are not just a tech company; we are a people‑first company. We believe that by unlocking the power of people and technology, we can accelerate transformation and achieve extraordinary results. As a Fortune 500 Solutions Integrator with deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organisations through complex digital decisions.

About the role

The Attack Surface Support Analyst is a foundational member of the Continuous Threat Exposure Management (CTEM) and Continuous Penetration Testing (CPEN) delivery team within Insight’s Managed Security Services organization. The analyst is responsible for the day-to‑day work of discovering, validating, prioritising, and tracking remediation of vulnerabilities and exposures across managed client environments. Leveraging enterprise vulnerability management platforms such as Qualys, the analyst works in concert with automated and agentic workflows to ensure exposures are continuously catalogued, risk‑ranked, and driven to verified closure. The analyst partners closely with the Managed Infrastructure Services team to dispatch and confirm remediation, supports onboarding of new clients, and sustains engagements throughout the contract lifecycle.

Key Responsibilities:
Vulnerability Management & Risk-Based Prioritization
  • Operate vulnerability management tooling (Qualys VMDR/TruRisk and equivalent platforms) to discover, catalog, and enrich an accurate inventory of assets and exposures across hybrid on‑premises, Azure, and AWS client environments.
  • Prioritise remediation using risk‑based scoring that combines CVSS, EPSS, exploit availability, threat intelligence, and asset criticality — not raw severity alone — to focus effort on the exposures that matter most.
  • Validate findings to confirm exploitability and reduce false positives before remediation is dispatched.
  • Maintain exposure dashboards and metrics (mean time to remediate, SLA adherence, exposure trend lines) and surface emerging risk to senior analysts and clients.
Automated & Agentic Workflow Operations
  • Monitor and interact with automated and agentic workflows supporting risk‑based validation, prioritisation, and remediation dispatch for vulnerabilities.
  • Apply human‑in‑the‑loop oversight by reviewing agentic recommendations for accuracy, confirming high‑impact actions, and escalating anomalies or low‑confidence outputs.
  • Provide tuning feedback to continuously improve automation logic, detection content, and orchestration playbooks.
Remediation Lifecycle & Ticketing
  • Own the ticketing and remediation lifecycle from finding through verified closure within the ITSM platform (ServiceNow preferred).
  • Operate integrated patching tools and coordinate with the Managed Infrastructure Services team to apply patches, configuration changes, or compensating controls.
  • Track SLAs and manage exceptions including documented risk acceptances, and confirm closure through rescan and validation.
Client Onboarding & Engagement Support
  • Support onboarding of new CTEM & CPEN clients — scanner deployment, asset scoping, credentialed scan configuration, connector/integration setup, and baseline establishment.
  • Sustain active engagements for the full contract duration, participating in recurring client touchpoints, reporting cycles, and exposure review meetings.
  • Contribute to client‑facing deliverables including remediation guidance, status reporting, and proof‑of‑execution artifacts.
What we’re looking for
Required Qualifications
  • 6-10 years of experience in vulnerability management, security operations, IT systems administration, or a related cybersecurity discipline.
  • Hands‑on experience with at least one enterprise vulnerability management platform — Qualys strongly preferred; Tenable, Rapid7 InsightVM, or Microsoft Defender Vulnerability Management acceptable.
  • Working understanding of CVSS, EPSS, and risk‑based vulnerability prioritisation concepts.
  • Familiarity with patch and endpoint management tooling (e.g., Microsoft Intune/SCCM, automated patching solutions).
  • Experience operating within an ITSM/ticketing platform (ServiceNow preferred) for workflow and tracking.
  • Solid grasp of networking, Windows and Linux operating systems, and common enterprise infrastructure.
  • Bachelor’s degree in Information Security, Computer Science, or a related field — or equivalent practical experience.
Preferred Qualifications
  • Industry certifications such as CompTIA Security+, Network+, CySA+, Qualys VMDR certification, or GIAC GFACT.
  • Exposure to penetration testing or automated/continuous pen testing platforms (e.g., NodeZero, Pentera, Cobalt) and the Gartner CTEM framework.
  • Familiarity with SOAR/security automation and scripting (PowerShell, Python, KQL).
  • Understanding of compliance frameworks (NIST CSF, CIS Controls v8, HIPAA/HITECH) as they relate to exposure management.
  • Prior experience in a managed services (MSSP/MXDR) or client‑facing delivery environment.
Core Competencies
  • Detail orientation and analytical rigor — comfortable working with large data sets and prioritisation logic.
  • Clear communication — able to translate technical findings into actionable remediation guidance for varied audiences.
  • Collaboration and service mindset — works effectively across SOC, infrastructure, and client teams.
  • Curiosity and adaptability — eager to learn evolving CTEM/CPEN tooling and agentic workflows.
What you can expect
  • Freedom to work from another location—even an international destination—for up to 30 consecutive calendar days per year.
  • Medical Insurance
  • Health Benefits
  • Professional Development: Learning Platform and Certificate Reimbursement
  • Shift Allowance

But what really sets us apart are our core values of Hunger, Heart, and Harmony, which guide everything we do, from building relationships with teammates, partners, and clients to making a positive impact in our communities.

At Insight, we celebrate diversity of skills and experience so even if you don’t feel like your skills are a perfect match - we still want to hear from you! Today's talent leads tomorrow's success. Learn more about Insight: https://www.linkedin.com/company/insight/

Insight does not accept unsolicited resumes from recruiters or employment agencies. Unsolicited resumes will be treated as direct applications from the candidate, and recruiters or agencies who submit candidates for this position without a prior, written vendor agreement will not be eligible for any form of compensation, even if the candidate is hired.

Insight is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, sexual orientation or any other characteristic protected by law.

Insight India Location: Level 16, Tower B, Building No 14, Dlf Cyber City In It/Ites Sez, Sector 24 &25 A Gurugram Gurgaon Hr 122002 India

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Engineer
Principal Engineer

Insight Enterprises • Gurugram District

Hybrid
INR 3,000,000 - 6,000,000
Principal Engineer
Principal Engineer

Insight • Gurugram District

Hybrid
INR 1,500,000 - 2,000,000
Medical Insurance
Health Benefits
Shift Allowance
+1
Principal Engineer
Principal Engineer

Insight Enterprises, Inc. • Dadri

Hybrid
INR 1,800,000 - 3,000,000
Medical Insurance
Professional Development: Learning平台 &
Freedom to work from another location
Principal Engineer
Principal Engineer

Cyod • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Remote work
Medical Insurance
Health Benefits
+2
SOC Analyst Sr
SOC Analyst Sr

Insight • Gurugram District

Hybrid
INR 900,000 - 1,300,000
Shift Allowance
Medical Insurance
Health Benefits
+1
Engineer III- Compute
Engineer III- Compute

Insight • India

Hybrid
INR 1,800,000 - 3,000,000
Medical Insurance
Health Benefits
Certificate Reimbursement
+2
Architect I - Security Presales
Architect I - Security Presales

Cyod • Bengaluru

Hybrid
INR 300,000 - 480,000
Medical Insurance
Health benefits
Professional development: Learning & 2
+2
Engineer III- Compute
Engineer III- Compute

Cyod • Gurugram District

Hybrid
INR 1,200,000 - 2,100,000
Remote work flexibility
Medical Insurance
Health Benefits
+2
Engineer II
Engineer II

Insight • Gurugram District

Hybrid
INR 550,000 - 700,000
Freedom to work from another location
Medical Insurance
Health Benefits
+2
Principal Engineer- Infra/DevOps
Principal Engineer- Infra/DevOps

Insight Enterprises, Inc. • Gurugram District

Hybrid
INR 3,500,000 - 7,000,000
Medical Insurance
Professional Development: Learning平台 &