Product Security Analyst - Vulnerability Management

GCS Recruitment Specialists

Pune District

On-site

INR 1,200,000 - 2,000,000

Full time

41 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

GCS Recruitment Specialists is seeking a Product Security Analyst - Vulnerability Management to own and improve the vulnerability management lifecycle across software products, cloud environments, and supporting platforms. You will consolidate findings, validate exposure with business context, and drive remediation with product teams.

The role emphasizes reducing risk and building secure product posture, not just triaging issues.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, IT, or related field.
  • Several years of experience in vulnerability management, vulnerability analysis, security operations, cloud security, or related role.
  • Hands-on experience with vulnerability scanning and security posture tools across apps, cloud, or infra.
  • Strong understanding of CVE, CVSS, vulnerability classes, exploitability, and risk-based prioritization.
  • Ability to validate findings using logs, configurations, and targeted testing.
  • Knowledge of cloud services, OS, networks, containers, IAM, APIs, and software dependencies.
  • Experience managing remediation workflows, evidence, and SLA reporting.
  • Strong data analysis skills and dashboards/metrics experience.
  • Excellent communication skills in English; able to drive follow-through.
  • Willingness to travel internationally for workshops/assessments.

Responsibilities

  • Operate end-to-end vulnerability management across apps, APIs, cloud services, and containers.
  • Consolidate findings from scanners, tests, and advisories; enrich with asset ownership and business context.
  • Prioritize vulnerabilities using severity, exploitation, exposure, and customer impact.
  • Assign remediation owners, set target dates, track progress, verify closures.
  • Develop and maintain vulnerability dashboards, heatmaps, and KRIs for leaders and teams.
  • Collaborate with Product, Architecture, and Platform teams to map products and owners.
  • Support risk treatment workflows and escalation of material or overdue risks.
  • Coordinate follow-up from penetrations, audits, incidents, and advisories.

Skills

Vulnerability management
Security analysis
Dashboards & reporting

Education

Bachelor's degree in Cybersecurity or related field

Tools

Tenable
Qualys
Rapid7
Wiz
Microsoft Defender for Cloud
AWS Security Hub
Snyk
SonarQube

Job description

Product Security Analyst - Vulnerability Management

Department

Software Technology

Reports to

Business Information Security Officer (BISO)

Role Summary

We are seeking a Product Security Analyst - Vulnerability Management to operate and continuously improve the vulnerability management lifecycle across software products, cloud environments, and supporting technology platforms.

The role consolidates security findings, validates and prioritizes exposure using technical and business context, coordinates accountable remediation, and provides reliable product security posture reporting.

The successful candidate is technically credible, analytical, and highly structured, working closely with product and engineering teams to reduce risk rather than merely administer findings. This is a product security and vulnerability management role, not a 24/7 SOC monitoring position.

Responsibilities

  • Operate the end-to-end vulnerability management process across applications, APIs, cloud services, infrastructure components, containers, and third-party dependencies.
  • Consolidate findings from vulnerability scanners, penetration tests, application security tools, cloud security services, vendor advisories, and enterprise cybersecurity sources.
  • Validate findings, remove duplicates and false positives, and enrich records with asset ownership, exposure, exploitability, and business context.
  • Prioritize vulnerabilities using severity, known exploitation, reachability, internet exposure, compensating controls, product criticality, and customer impact.
  • Assign accountable remediation owners, agree target dates, track progress, challenge overdue items, and verify closure evidence.
  • Maintain an accurate inventory and mapping of covered products, repositories, services, and technical owners in coordination with Product, Architecture, and Platform teams.
  • Develop and maintain vulnerability dashboards, heatmaps, KRIs, and aging metrics for security leadership, business leadership, product teams, and governance forums.
  • Identify systemic weakness patterns and recommend preventive actions, platform improvements, secure configurations, and remediation campaigns.
  • Support risk treatment and exception workflows by preparing evidence, documenting residual exposure, and escalating material or overdue risks.
  • Coordinate operational follow-up from penetration tests, audits, incidents, external disclosures, and security advisories.
  • Perform focused vulnerability assessments and technical validation using approved tools and methods.
  • Monitor emerging vulnerabilities and threat intelligence relevant to the technology stack and initiate rapid assessment when urgent exposure is suspected.
  • Use CISA Known Exploited Vulnerabilities and other verified threat intelligence as inputs to risk-based vulnerability prioritization.
  • Use EPSS as one empirical exploitation likelihood signal alongside CVSS, reachability, exposure, product criticality, and customer impact.
  • Support Cyber Resilience Act reporting readiness through rapid assessment of active exploitation, evidence collection, and escalation to security leadership.
  • Maintain visibility of product versions, declared support periods, and end-of-support status to inform vulnerability treatment and customer obligations.
  • Use SBOM and dependency data to determine which products, versions, and services contain affected components and accelerate impact assessment.
  • Support security advisories, customer notifications, and coordinated vulnerability disclosure with Product Management, Legal, Quality, and Security stakeholders.
  • Support audit, regulatory, and ISO 27001 evidence requirements related to vulnerability management and operational security controls.
  • Collaborate with Application Security, DevSecOps, Platform Engineering, and Security teams on complex findings, scanning coverage, and automation.
  • Continuously improve workflows, service levels, data quality, and reporting to drive measurable exposure reduction.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience.
  • Several years of experience in vulnerability management, vulnerability analysis, security operations, cloud security, or a related technical cybersecurity role.
  • Hands-on experience with vulnerability scanning and security posture tools across applications, cloud, or infrastructure environments.
  • Strong understanding of CVE, CVSS, common vulnerability classes, exploitability, attack paths, and risk-based prioritization.
  • Ability to validate findings using logs, configurations, source information, command-line tools, and targeted technical testing.
  • Knowledge of cloud services, operating systems, networks, containers, identity and access management, APIs, and software dependencies.
  • Experience managing remediation workflows, security exceptions, evidence, and service-level reporting.
  • Strong data analysis skills and experience producing dashboards, metrics, and concise management reporting.
  • Excellent analytical, organizational, and problem-solving skills with strong attention to data quality.
  • Ability to communicate clearly with engineers, product owners, and senior stakeholders and drive accountable follow-through.
  • Strong written and verbal communication skills in English.
  • High level of integrity, judgment, and commitment to protecting customers and software assets.
  • Ability to travel internationally when required for key workshops, assessments, or team collaboration.
  • Ability to collaborate effectively across global time zones with teams distributed across multiple continents.

Preferred Qualifications

  • Experience with tools such as Tenable, Qualys, Rapid7, Wiz, Microsoft Defender for Cloud, AWS Security Hub, Snyk, SonarQube, or equivalent.
  • Knowledge of CISA Known Exploited Vulnerabilities, EPSS, NIST guidance, CIS Benchmarks, and ISO 27001-aligned vulnerability management practices.
  • Experience with scripting, APIs, workflow automation, and reporting tools such as Power BI.
  • Familiarity with application security tooling and software development concepts sufficient to collaborate effectively with engineering teams.
  • Experience supporting incident response, coordinated vulnerability disclosure, or penetration testing follow-up.
  • Relevant certifications such as Security+, CySA+, GSEC, or equivalent.
  • Familiarity with engineering or technical software environments is advantageous

GCS is acting as an Employment Agency in relation to this vacancy.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

GCS Recruitment Specialists • Pune District

On-site
INR 1,800,000 - 2,800,000
Product Security Engineer (Vulnerability Management)
Product Security Engineer (Vulnerability Management)

JUARA IT SOLUTIONS • Chennai District

On-site
INR 2,500,000 - 4,000,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Clarivate • Bagaluru

Hybrid
INR 2,000,000 - 3,400,000
Vulnerability & Incident Response Analyst
Vulnerability & Incident Response Analyst

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,000,000 - 1,600,000
Product Security Engineer
Product Security Engineer

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,200,000 - 1,800,000
IT & Data Vulnerability Analyst
IT & Data Vulnerability Analyst

Infosys • Hyderabad

On-site
INR 900,000 - 1,300,000
Senior Product Security Engineer
Senior Product Security Engineer

Dun & Bradstreet • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Security Analyst
Security Analyst

Achieve Cybersecurity Solutions • Hyderabad

On-site
INR 600,000 - 900,000
Cyber Security Consultant
Cyber Security Consultant

Infosys • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Product Security Engineer (Devsec Ops)
Product Security Engineer (Devsec Ops)

Lenskart • Gurugram District

On-site
INR 1,500,000 - 2,300,000