Senior Vulnerability Management Analyst (Qualys)

UST

Gurugram District

Hybrid

INR 1,800,000 - 2,800,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

UST in Gurgaon, India, seeks a Senior Vulnerability Management Analyst for a contract role. The role blends hands-on vulnerability management with CTEM program leadership in a hybrid setup requiring two onsite days per week.

You will drive remediation standards across multi‑cloud environments, leveraging Qualys VMDR, Wiz and Tanium, while coordinating with IT, security and engineering teams. Strong analytics and leadership are essential.

Qualifications

  • 5–7 years of hands-on vulnerability management or related security operations experience.
  • Experience maturing vulnerability management lifecycle across large environments.
  • Hands-on with Qualys VMDR, Wiz and Tanium — deployment, configuration, tuning and reporting.
  • Familiarity with CVSS, EPSS, threat intel and risk-based prioritization.
  • Ability to mentor and lead junior analysts and communicate with leadership.

Responsibilities

  • Own and mature the end-to-end vulnerability management lifecycle across the enterprise.
  • Operate the core exposure tooling stack hands-on (Qualys VMDR, Wiz, Tanium) including deployment and health checks.
  • Lead CTEM program scoping, discovery, prioritization, validation and mobilization cycles.
  • Set remediation SLAs and drive accountability with IT, infra, cloud and eng teams.
  • Partner with threat intel to correlate external activity with internal findings and surface material risks.
  • Build dashboards and executive reporting using native tools and BI tooling.
  • Mentor junior analysts and uphold standards for triage, documentation and reporting.

Skills

Vulnerability management
CTEM program
Threat intelligence
Data reporting
Leadership mentoring

Tools

Qualys VMDR
Wiz
Tanium
Excel
Power BI

Job description

Role Description

Role at a glance ROLE INFORMATION DETAIL Job title Senior Vulnerability Management Analyst Team/function Technology Services Group (TSG) — Cyber Operations/Vulnerability Management Level Senior Analyst Employment type Contract (Contractor) Location Gurgaon, India Work arrangement Hybrid. Minimum two days per week onsite at the Gurgaon office, subject to prevailing workplace policy. About the role seeking an experienced Senior Vulnerability Management Analyst to join our Cyber Operations team within the Technology Services Group on a contract basis. This is a hands‑on engagement in which you will operate and drive the day‑to‑day maturity of our vulnerability and exposure management program across a large, diverse global environment spanning servers, endpoints, network devices, containers, and multi-cloud workloads. You will run the core tooling stack hands‑on — Qualys (VMDR) for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation — and lead a Continuous Threat Exposure Management (CTEM) program that turns findings from these tools into a single, risk‑prioritized view of real exposure. Working closely with IT, infrastructure, cloud, and engineering teams, you will set remediation standards, drive accountability, guide junior analysts, and brief leadership on exposure and risk trends. This role is a fixed‑term contract; extension or conversion is subject to business need and performance. The role is based at our Gurgaon office in India and is hybrid, with a minimum of two days each week worked onsite. Location and work arrangement

  • The role is based in Gurgaon, India. Candidates must be based in Gurgaon or within a daily commute of the office.
  • The contractor is required to work from the Gurgaon office a minimum of two days per week, with the remaining days worked remotely.
  • Specific onsite days will be confirmed with the hiring manager to fit team and operational needs.
  • The contractor must follow prevailing workplace and attendance policy at all times. If that policy changes, including any change to the required number of office days or to the firm's hybrid working model, the contractor is expected to comply with the revised policy. Key responsibilities
  • Own and continuously mature the end-to-end vulnerability management lifecycle across the enterprise — asset discovery, scanning, detection, validation, prioritization, remediation governance, rescanning, and closure verification.
  • Operate and administer the core exposure tooling stack hands‑on — Qualys (VMDR) for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation — including deployment, configuration, tuning, integration, and scanner/agent/sensor health.
  • Lead the Continuous Threat Exposure Management (CTEM) program — running the scoping, discovery, prioritization, validation, and mobilization cycles, and correlating findings across host, cloud, and endpoint sources into a single de-duplicated, risk-ranked view of exposure.
  • Prioritize vulnerabilities using CVSS combined with exploitability signals (EPSS, CISA Known Exploited Vulnerabilities), threat intelligence, and asset/business criticality — focusing remediation on what is actually exploitable and material.
  • Set and enforce remediation SLAs and drive accountability with IT, infrastructure, cloud, and engineering teams — translating findings into clear, actionable work and escalating aged or high-risk exposures.
  • Partner with threat intelligence to correlate external threat activity with internal findings, translate emerging threats into targeted validation and remediation, and surface material risks for escalation.
  • Define exception and risk‑acceptance standards, review and adjudicate requests, and maintain defensible documentation to support audits, compliance, and leadership reporting.
  • Build and automate dashboards, metrics, and executive reporting on exposure, scan coverage, vulnerability aging, and SLA adherence — using native tool reporting, Excel (including pivot tables), and query/BI tooling.
  • Mentor junior analysts, set standards for triage, documentation, and reporting quality, and act as the escalation point for complex or contested findings.
  • Advise on secure configuration, hardening, and overall program maturity, and communicate findings and recommendations clearly to audiences ranging from engineers to senior stakeholders. Required qualifications
  • Experience: 5–7 years of hands‑on experience in vulnerability management, exposure management, or closely related security operations, including time in a senior or lead capacity.
  • Lifecycle and governance: Deep understanding of the vulnerability management lifecycle, risk based remediation, and SLA governance across large, complex environments.
  • Tooling (hands‑on): Direct, hands‑on experience operating and administering Qualys (VMDR), Wiz, and Tanium — including deployment, configuration, tuning, integration, and reporting. Hands‑on depth with all three is required.
  • CTEM: Demonstrated experience running or materially contributing to a Continuous Threat Exposure Management (CTEM) program across its scoping, discovery, prioritization, validation, and mobilization phases.
  • Risk prioritization: Proficiency in CVSS analysis combined with exploitability signals (EPSS, CISA KEV) and threat‑intelligence-driven, risk-based prioritization.
  • Data and reporting: Strong data and reporting skills — Excel (including pivot tables), native tool reporting, and ideally query or BI tooling — to produce both technical and executive-level metrics.
  • Environment breadth: Proven experience securing large, diverse environments spanning Windows, Linux, network devices, endpoints, containers, and multi-cloud workloads.
  • Threat awareness: Strong working knowledge of threat intelligence sources and the ability to correlate external threat data with internal findings to drive prioritization.
  • Communication and leadership: Excellent written, verbal, and presentation skills, with the ability to influence remediation owners, brief senior leadership, and mentor junior analysts.
  • Preferred/nice-to-have
  • Cloud and container security: Working knowledge of cloud security posture (CSPM/CNAPP) and container/Kubernetes security concepts, ideally via Wiz or an equivalent platform.
  • Benchmarking: Working knowledge of CIS Benchmarks and secure configuration/hardening standards.
  • Automation: Exposure to scripting or automation (e.g., Python, PowerShell, tool APIs, Power Query) to integrate tooling and streamline reporting or remediation workflows.
  • Integrations: Experience integrating vulnerability/exposure tooling with ITSM platforms (e.g., ServiceNow) to automate remediation workflows. Certifications One or more relevant certifications preferred (or willingness to obtain):
  • Qualys VMDR Certification
  • Wiz Certified (or equivalent cloud security/CNAPP certification)
  • GIAC (e.g., GEVA/GCED) or Certified Ethical Hacker (CEH)
  • CISSP, or Tanium/CompTIA Security+ (or progress toward these)
Skills

Vulnerability Management, Wiz, Tanium, Qualys

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Vulnerability Management Specialist Qualys VMDR And QGS Expert
Senior Vulnerability Management Specialist Qualys VMDR And QGS Expert

Zensar Technologies • Bengaluru Urban

On-site
INR 4,500,000 - 7,500,000
Senior VMDR Consultant
Senior VMDR Consultant

EY • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Consultant - Vulnerability Management
Consultant - Vulnerability Management

YASH Technologies • Bengaluru

On-site
INR 800,000 - 1,200,000
Senior Qualys Security Consultant
Senior Qualys Security Consultant

EY • Bengaluru

On-site
INR 2,600,000 - 3,800,000
Vulnerability Lead
Vulnerability Lead

SHI • Hyderabad

On-site
INR 1,800,000 - 3,600,000
Qualys Engineer
Qualys Engineer

Cloudxtreme • Hyderabad

On-site
INR 1,200,000 - 2,400,000
Vulnerability Management
Vulnerability Management

Cloudxtreme • Pune District, Bengaluru

On-site
INR 800,000 - 1,200,000
Vulnerability Management
Vulnerability Management

Deloitte US-India Offices • Bengaluru

On-site
INR 900,000 - 1,300,000
Vulnerability Analyst
Vulnerability Analyst

SHI • Hyderabad

On-site
INR 900,000 - 1,300,000
Qualys Guard Vulnerability Management
Qualys Guard Vulnerability Management

VOLTO Consulting • Hyderabad

On-site
INR 1,400,000 - 2,400,000