Senior Vulnerability Management Engineer

LSEG

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

LSEG is seeking a Senior Vulnerability Management Engineer in Bengaluru, India to bridge offensive security and engineering by addressing penetration testing findings. The successful candidate will analyze test reports, develop remediation guidance, and coordinate remediation activities across teams. A solid background in penetration testing and application security, along with effective communication skills, is essential. The role demands hands-on experience with tools like Burp Suite and cloud platforms, aimed at reducing security risks through remediation efforts.

Qualifications

  • Proven hands-on experience in penetration testing of Web Applications, APIs, Thick Client, and Infrastructures.
  • Proficient communication skills in English, both written and verbal.
  • Familiarity with OWASP Top 10 and secure coding practices.

Responsibilities

  • Analyze and review penetration test reports to understand impact and risk.
  • Develop remediation guidance and patterns for vulnerabilities.
  • Coordinate remediation activities and manage backlog.

Skills

Penetration testing
Application security
Burp Suite
Cloud platforms (AWS, Azure, GCP)
Kubernetes
Threat modeling
Clear technical reporting

Tools

Docker
Custom scripts
Command-line tools

Job description

LSEG is seeking a Senior Vulnerability Management Engineer to join our internal offensive security team with focus on driving closure of penetration testing findings. This role bridges offensive security and engineering by translating penetration test results into clear, actionable remediation guidance and partnering with application and platform teams to implement secure fixes. The successful candidate has a strong penetration testing or application security background, hands‑on remediation experience, and the ability to coordinate multiple collaborators to reduce risk at scale. This is a highly technical, delivery‑focused role with responsibility for both individual findings and systemic improvements.

Key Responsibilities
  • Analyze and review penetration test reports to understand technical impact, exploitability, and business risk.
  • Develop, document and maintain remediation guidance, patterns, and blue‑prints for common vulnerability types (e.g. injections, access control, auth, session management, misconfigurations).
  • Provide consultation to application and platform teams on secure design and remediation approaches, including code‑level, configuration‑level and business‑level recommendations.
  • Coordinate remediation activities across multiple teams, ensuring clear ownership, agreed timelines, and risk‑based prioritization.
  • Validate fixes by retesting vulnerabilities (manually and/or via tools/scripts) and updating the status of findings through closure.
  • Manage and track the remediation backlog, including SLAs, aging findings, and critical issues when needed.
  • Produce and maintain documentation on remediation processes, workflows, and controls for audit and compliance purposes.
  • Prepare and deliver regular status reports and metrics on remediation progress, trends, and risk reduction to management and partners.
  • Perform root‑cause analysis for recurring or systemic issues and work with engineering, architecture, and governance teams to implement long‑term corrective actions.
  • Contribute to continuous improvement of the pentest‑to‑remediation lifecycle, including automation, standardization and integration with SDLC/DevSecOps pipelines.
  • Compile technical documents, track, and document remediation metadata
    • Engagement details (who, what, when, where)
    • Testing team members and roles
    • Tools and methodologies used
    • Schedule and timelines
    • Target systems and environments
    • Constraints, exclusions, and limitations
    • Testing activities and event logs
  • Contribute to team improvement efforts and ensure all initiatives and feedback are well documented for future references.
  • Contribute to the continuous improvement of testing methodologies, tooling, automation.
  • Stay ahead of emerging threats, vulnerabilities, and offensive security techniques.
  • Participate in R&D initiatives as guided from leadership.
  • Support knowledge sharing and mentoring within the team.

Understanding project requirements and aligning work with agreed upon objectives and timelines.

Required Skills & Experience
  • Proven hands‑on experience in penetration testing of Web Applications, APIs, Thick Client and Common Infrastructures (Active Directory, Cloud and Cloud‑native based environments).
  • Proficiency with tools such as Burp Suite, common command‑line tools, and ability to write custom scripts when needed.
  • Experience in automating pentesting tasks.
  • Solid understanding of application security, network protocols, and operating systems.
  • Experience with cloud platforms (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes).
  • Solid understanding of common vulnerabilities and exposures (OWASP Top 10, SANS Top 25) and secure coding practices in at least one major language stack (e.g. Java/Springboot, .NET, JavaScript/Node, Python).
  • Ability to write clear, technical reports and communicate findings and fixes to both technical and non‑technical partners.
  • Experience working in large, complex enterprise environments.
  • Proficient communication skills in English, both written and verbal.
  • Relevant certifications and engagement with the security community is a plus.
  • Threat Modelling experience is a plus.
  • Proven track record of successfully managing and driving security engagements for various organizations with differing operational and technical profiles.
  • Ability to identify, assess, and communicate technical and project risks to partners.

Career Stage: Senior Associate

We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone’s race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

London Stock Exchange Group • Bengaluru

On-site
INR 2,000,000 - 3,200,000
Healthcare
Retirement planning
Paid volunteering days
+1
Senior Security Specialist
Senior Security Specialist

LSEG • Port Blair

On-site
INR 1,800,000 - 2,400,000
Healthcare
Retirement planning
Paid volunteering days
+1
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

Remote
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Senior Security Specialist
Senior Security Specialist

LSEG • Bengaluru

On-site
INR 4,000,000 - 7,000,000
SENIOR ENGINEER - Penetration Testing
SENIOR ENGINEER - Penetration Testing

Happiest Minds Technologies • Bengaluru

On-site
INR 1,100,000 - 1,700,000
Senior Penetration Tester
Senior Penetration Tester

LSEG • Bengaluru

On-site
INR 1,800,000 - 2,500,000
Healthcare
Retirement planning
Paid volunteering days
+1
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Penetration Testing Manager
Penetration Testing Manager

VikingCloud • India

On-site
INR 1,200,000 - 1,800,000
Security Penetration Testing Consultant
Security Penetration Testing Consultant

Withum • Bengaluru

On-site
INR 900,000 - 1,300,000
Senior Security Consultant
Senior Security Consultant

Eventus Security • Navi Mumbai

On-site
INR 1,500,000 - 2,500,000