Senior Cybersecurity Engineer – Exposure Management

Syneos Health, Inc.

Madhapur

On-site

INR 3,500,000 - 6,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Syneos Health is seeking a Senior Cybersecurity Engineer – Exposure Management in Madhapur, India. The role focuses on designing, operating, and maturing exposure management capabilities across infrastructure, cloud, endpoints, and applications.

You will drive CTEM program maturity, correlate threat intel with exposure data, and enable risk-based remediation to reduce real-world exposure. The position requires strong hands-on experience in vulnerability management and working knowledge of

Qualifications

  • 7+ years of cybersecurity experience with vulnerability/exposure management emphasis.
  • Experience with CTEM-style programs and risk-based remediation.
  • Ability to lead cross-functional remediation initiatives without direct reporting authority.

Responsibilities

  • Define and mature CTEM lifecycle across scoping, discovery, prioritization, validation, and mobilization.
  • Translate exposure strategy into repeatable operating processes and governance.
  • Maintain tooling aggregating vulnerability data, asset context, and threat intelligence.
  • Drive risk-informed prioritization beyond CVSS and coordinate remediation priorities.
  • Lead cross-functional exposure management initiatives and mentor engineers.

Skills

Vulnerability management
Exposure management
Threat-informed defense
Cloud security
Security operations engineering
Automation & scripting

Tools

Vulnerability scanners
EDR/XDR
CMDB/CAASM
Cloud CSPM/CNAPP
Identity/IAM tools
ITSM/SIEM/SOAR

Job description

Senior Cybersecurity Engineer – Exposure Management

Updated: Yesterday
Location: Madhapur, TS, India
Job ID:25110029

Description

Senior Cybersecurity Engineer – Exposure Management

Syneos Health® is a leading fully-integrated life sciences services organization built to accelerate customer success. We partner with innovators at every point across the drug development and commercialization continuum, helping them navigate complexity, anticipate change and accelerate progress.

Every day we perform better because of how we work together, as one team, each the best at what we do. We bring together talented experts across a broad spectrum of business critical corporate functions. Every role plays an essential part in enabling our customers to achieve their goals. Our teams are agile, collaborative, and committed to delivering—for each other, for our customers, and ultimately for the people who rely on the services we support.

Discover what your 25,000 future colleagues already know:

Why Syneos Health

We are passionate about developing our people, through career development and progression; supportive and engaged line management; technical and therapeutic area training; peer recognition and total rewards program.

We are committed to building an inclusive culture – where you can authentically be yourself. Central to this is our purpose – Driven to Deliver – which captures the passion of our colleagues to show up each day and shape solutions that have the ability to dramatically impact someone’s life.

We are continuously building the company we all want to work for and our customers want to work with. Why? Because we know that when we bring together smart colleagues from across the world, we can shape the future of healthcare, driving impact for customers and defining the pace of patient progress.

Job Responsibilities
Core Responsibilities
  • CTEM Program Maturity & Operating Model

  • Help define, implement, and continuously improve the CTEM lifecycle across scoping, discovery, prioritization, validation, and mobilization.
  • Translate exposure management strategy into repeatable operating processes, decision criteria, governance routines, and measurable outcomes.
  • Identify maturity gaps across asset coverage, signal quality, prioritization, validation, remediation ownership, exception handling, and executive reporting.
  • Partner with security, infrastructure, cloud, endpoint, identity, application, architecture, and business teams to establish shared accountability for exposure reduction.
  • Drive structured exposure review cycles that move the organization from vulnerability reporting to validated, risk-based remediation and measurable risk reduction.
  • Exposure Management Engineering

  • Engineer and operate exposure management capabilities across infrastructure, cloud, endpoints, identity, applications, and third-party surfaces.
  • Maintain and enhance tooling that aggregates vulnerability data, asset context, threat intelligence, and exploitability signals.
  • Ensure accurate asset discovery, coverage validation, and telemetry quality across the enterprise attack surface.
  • Risk-Based Prioritization

  • Drive risk- and threat-informed prioritization beyond CVSS scoring.
  • Incorporate exploit intelligence, threat actor activity, asset criticality, and compensating controls.
  • Partner with technology and business owners to translate exposure into remediation priorities.
  • Threat-Aligned Analysis

  • Correlate exposure data with threat intelligence and adversary TTPs.
  • Support zero-day and emerging threat response through rapid exposure analysis.
  • Metrics, Reporting & Insight

  • Define and maintain CTEM outcome metrics, including exposure reduction, risk burndown, validated closure rate, SLA adherence, exception aging, reintroduced exposure rate, coverage gaps, telemetry freshness, owner assignment accuracy, and remediation cycle time.
  • Build executive, operational, engineering, and audit views that clearly explain risk, accountability, trend, residual exposure, and progress against maturity goals.
  • Convert technical findings into business-relevant narratives that support prioritization, funding, architecture decisions, and remediation mobilization.
  • Identify recurring exposure patterns and recommend control, architecture, automation, or process improvements.
  • Cross-Functional Leadership & Mobilization

  • Lead exposure reduction initiatives across teams without direct reporting authority, using data, risk rationale, business impact, and clear decision records to drive alignment.
  • Facilitate remediation planning across infrastructure, cloud, endpoint, application, identity, SOC, GRC, and business stakeholders.
  • Build consensus on ownership, prioritization, compensating controls, exception paths, and remediation timelines.
  • Escalate systemic blockers with clear options, residual risk framing, and recommended decisions.
  • Mentor analysts and engineers while raising the overall maturity of exposure management practices.
  • Required Qualifications

  • 7+ years of cybersecurity experience, including significant hands-on experience in vulnerability management, exposure management, threat-informed defense, cloud security, infrastructure security, or security operations engineering.
  • Demonstrated experience operating or maturing a risk-based vulnerability management, exposure management, or CTEM-aligned program.
  • Proven ability to lead cross-functional remediation initiatives without direct reporting authority.
  • Strong understanding of CTEM lifecycle concepts: scoping, discovery, prioritization, validation, and mobilization.
  • Experience correlating asset context, exploitability, threat intelligence, business criticality, control state, and remediation feasibility into defensible prioritization decisions.
  • Hands-on experience with vulnerability/exposure platforms and related ecosystem tools, including scanners, EDR/XDR, CMDB/CAASM, cloud/CNAPP/CSPM, identity/IAM, ASM/EASM, ITSM, SIEM/SOAR, and threat intelligence sources.
  • Experience with SLA models, exception workflows, compensating controls, risk acceptance, residual risk reporting, and validated closure.
  • Ability to communicate exposure and residual risk clearly to engineering, operations, security leadership, and non-technical stakeholders.
  • Working knowledge of automation, APIs, scripting, or data analysis methods used to improve exposure management workflows.
  • Nice to Have / Preferred

  • Experience implementing or significantly maturing a CTEM-style program in a large enterprise.
  • Familiarity with EPSS, CISA KEV, SSVC-style decisioning, CVSS v4 environmental/threat context, exploit telemetry, ransomware intelligence, and threat actor TTP mapping.
  • Experience with attack-path analysis, adversarial exposure validation, breach and attack simulation, red-team/pentest integration, or control validation.
  • Experience applying AI or machine learning to exposure management, including summarization, deduplication, risk explanation, ticket enrichment, remediation recommendation drafting, or executive reporting.
  • Knowledge of AI governance, human-in-the-loop controls, model/data protection, auditability, and safe automation design.
  • Experience integrating exposure workflows with ServiceNow or equivalent ITSM platforms.
  • Experience with cloud-native exposure management across AWS, Azure, GCP, containers, Kubernetes, IaC, SaaS, identity, and application security findings.
  • Industry certifications such as CISSP, GIAC, OSCP, cloud security, or relevant offensive/defensive security credentials.
  • Collaborate with SMEs to define mitigation strategies and/or compensating controls
  • Provide leadership with clear, defensible views of exposure and residual risk.
  • Provide operational guidance to and oversight of managed server provider technicians.
Get to know Syneos Health

Over the past 5 years, we have worked with 94% of all Novel FDA Approved Drugs, 95% of EMA Authorized Products and over 200 Studies across 73,000 Sites and 675,000+ Trial patients.

No matter what your role is, you’ll take the initiative and challenge the status quo with us in a highly competitive and ever-changing environment. Learn more about Syneos Health.

http://www.syneoshealth.com

Additional Information

Tasks, duties, and responsibilities as listed in this job description are not exhaustive. The Company, at its sole discretion and with no prior notice, may assign other tasks, duties, and job responsibilities. Equivalent experience, skills, and/or education will also be considered so qualifications of incumbents may differ from those listed in the Job Description. The Company, at its sole discretion, will determine what constitutes as equivalent to the qualifications described above. Further, nothing contained herein should be construed to create an employment contract. Occasionally, required skills/experiences for jobs are expressed in brief terms. Any language contained herein is intended to fully comply with all obligations imposed by the legislation of each country in which it operates, including the implementation of the EU Equality Directive, in relation to the recruitment and employment of its employees. The Company is committed to compliance with the Americans with Disabilities Act, including the provision of reasonable accommodations, when appropriate, to assist employees or applicants to perform the essential functions of the job.

Summary

The Senior Cybersecurity Engineer – Continuous Threat & Exposure Management is responsible for designing, operating, and continuously maturing the organization’s exposure management capabilities across infrastructure, cloud, endpoint, identity, and application surfaces. This role will serve as a technical and programmatic lead for the organization’s Continuous Threat Exposure Management maturity journey, helping define the operating model, governance, prioritization methods, validation approach, and mobilization workflows required to reduce real-world exposure across the enterprise.This is a senior individual contributor role with increasing scope and influence, serving as a technical leader within Security Operations Engineering and a feeder role in people leadership or management.

Discover what our more than 29,000 employees already know: work here matters everywhere. We work hard,and smart, all in the name of getting much-needed therapies to thosewho need them most. A career with Syneos Health means your everyday work improvespatients’ lives around the world. Selecting us as an employer secures a career inwhich you’re guaranteed to:

Syneos Health ® is a leading fully integrated biopharmaceutical solutions organization built to accelerate customer success. We translate unique clinical, medical affairs and commercial insights into outcomes to address modern market realities. Together we share insights, use the latest technologies and apply advanced business practices to speed our customers’ delivery of important therapies to patients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer - Exposure Management
Senior Cybersecurity Engineer - Exposure Management

Syneos Health • India

On-site
INR 1,800,000 - 3,200,000
Principal Security Ops Analyst
Principal Security Ops Analyst

Syneos Health, Inc. • Madhapur

On-site
INR 1,800,000 - 3,200,000
Senior Cybersecurity Engineer – Exposure Management
Senior Cybersecurity Engineer – Exposure Management

Jobtailor • Hyderabad

On-site
INR 1,800,000 - 2,800,000
Principal Security Ops Analyst
Principal Security Ops Analyst

Syneos Health, Inc. • Hyderabad

On-site
INR 2,600,000 - 4,000,000
Cyber Resiliency Senior Technical Analyst
Cyber Resiliency Senior Technical Analyst

Syneos Health • Hyderabad

On-site
INR 800,000 - 1,200,000
Exec Director, Cloud Ops and Infrastructure
Exec Director, Cloud Ops and Infrastructure

Dormont Manufacturing Co • Hyderabad

On-site
INR 3,500,000 - 6,500,000
Project Manager, Clinical portfolio (Transformation Projects)- Hyderabad
Project Manager, Clinical portfolio (Transformation Projects)- Hyderabad

Syneos Health, Inc. • Madhapur

On-site
INR 1,200,000 - 1,800,000
Salesforce Engineer II, Service Cloud / Health Cloud
Salesforce Engineer II, Service Cloud / Health Cloud

Syneos Health, Inc. • Madhapur

On-site
INR 1,200,000 - 1,800,000
SR HRIS / Workday Reporting Analyst
SR HRIS / Workday Reporting Analyst

Syneos Health, Inc. • Gurgaon

On-site
INR 1,800,000 - 2,800,000
Senior Full-Stack Software Engineer - JavaScript & Node (EU-US Working Hours)
Senior Full-Stack Software Engineer - JavaScript & Node (EU-US Working Hours)

Syneos Health, Inc. • Madhapur

On-site
INR 1,200,000 - 2,000,000