Vulnerability & Exposure Management Lead

Mizuho

Pune District

On-site

INR 4,000,000 - 6,500,000

Full time

42 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Mizuho Pune is seeking a senior, hands-on Vulnerability & Exposure Management Lead to evolve our vulnerability program into a risk-based Exposure Management and CTEM capability. You will reduce cyber risk by improving visibility, prioritization, remediation governance, and continuous improvement across our global operations.

You will lead exposure management strategy, platform modernization, and stakeholder engagement while partnering with Cyber Fusion Center, Infrastructure, Cloud Security, and

Qualifications

  • 12-15 years of experience in Vulnerability Management or related security disciplines.
  • Proven experience building or maturing enterprise Vulnerability & Exposure Management programs.
  • Strong knowledge of CTEM, attack surface management, and risk-based remediation.

Responsibilities

  • Define and execute vulnerability & exposure management strategy and CTEM roadmap.
  • Improve visibility of vulnerabilities across infra, cloud, applications, and networks.
  • Establish risk-based prioritization methodologies using threat intelligence and asset criticality.
  • Drive remediation governance, prioritization, escalation, and risk acceptance processes.
  • Lead modernization of vulnerability management platforms, automation, and reporting.
  • Collaborate with Threat Intelligence, Cloud Security, SecOPS, and Architecture teams to reduce cyber risk.
  • Deliver executive reporting, KPIs, KRIs, and strategic recommendations.

Skills

Vulnerability management
Exposure management
CTEM
Leadership
Stakeholder management
Python
PowerShell
SQL
Data analytics
Reporting
Communication
Mentoring

Education

Bachelor's degree in Cybersecurity/CS/IT/Engineering

Tools

Qualys VMDR
Tenable
CTEM platforms
ITSM
CMDB
SIEM
Threat intelligence
Cloud security tools

Job description

At Mizuho, we provide the stability of an international industry leader with the career trajectory of a growing business. Our steady, strategic growth gives our people at all levels rewarding degrees of responsibility and richer work experience than a boutique firm or an established giant could offer alone.

It’s the local expertise of our employees that makes our global network so powerful. By collaborating with colleagues and clients who share the same ambition and drive, you can amplify your sphere of influence and base of knowledge as part of one of the largest banks in the world.

Summary:

Mizuho Global Services (MGS) is seeking a senior, hands-on Vulnerability & Exposure Management Lead to drive the evolution of vulnerability management into a risk-based Exposure Management and Continuous Threat Exposure Management (CTEM) capability supporting Mizuho's global operations. This role is responsible for reducing cyber risk through improved visibility, intelligent prioritization, effective remediation governance, and continuous enhancement of vulnerability management capabilities.

The successful candidate will lead exposure management strategy, platform modernization, remediation governance, and stakeholder engagement while partnering with Cyber Fusion Center, Infrastructure, Cloud, Application Security, and Risk teams to strengthen the organization's security posture.

Key Responsibilities:

  • Define and execute the Vulnerability & Exposure Management strategy, governance framework, remediation standards, and CTEM roadmap aligned with business and cybersecurity objectives.
  • Improve visibility of vulnerabilities and exposures across infrastructure, cloud, applications, identity systems, databases, endpoints, networks, and internet-facing assets.
  • Establish risk-based prioritization methodologies leveraging threat intelligence, exploitability, asset criticality, attack-path analysis, business impact, and external exposure.
  • Drive enterprise remediation governance through prioritization, escalation, validation, exception management, risk acceptance, and accountability processes.
  • Lead modernization of vulnerability management platforms, automation capabilities, integrations, reporting, scanning programs, and operational processes.
  • Partner with Threat Intelligence, Threat Hunting, Security Operations, Cloud Security, Security Engineering, and Architecture teams to improve exposure analysis and cyber risk reduction.
  • Deliver executive reporting, KPIs, KRIs, remediation metrics, and strategic recommendations to leadership and governance forums.

Required Qualifications:

  • 12-15 years of experience in Vulnerability Management, Exposure Management, Security Engineering, Cybersecurity Operations, Technology Risk, or related security disciplines.
  • Proven experience building, leading, or maturing enterprise Vulnerability & Exposure Management programs within large, complex environments.
  • Strong knowledge of CTEM, attack surface management, risk-based remediation, cyber risk reduction methodologies, and vulnerability management operating models.
  • Deep understanding of CVE, CVSS, EPSS, CISA Known Exploited Vulnerabilities (KEV), threat intelligence, exploitability analysis, attack-path analysis, asset criticality, and exposure prioritization frameworks.
  • Experience driving remediation governance, executive reporting, stakeholder engagement, exception management, and regulatory compliance activities.
  • Strong knowledge of cloud, infrastructure, application, database, identity, endpoint, network, and internet-facing security vulnerabilities and remediation practices.
  • Experience integrating vulnerability management capabilities with ITSM, CMDB, asset management, threat intelligence, SIEM, analytics, and workflow automation platforms.
  • Proficiency with APIs, Python, PowerShell, SQL, data analytics, automation, and reporting technologies.
  • Strong leadership, communication, mentoring, stakeholder management, negotiation, analytical, and decision-making skills.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or equivalent experience.
  • Security Technologies: Qualys VMDR, Tenable, CTEM and exposure management platforms, attack surface management solutions, ITSM, CMDB, SIEM, threat intelligence, cloud security, asset management, workflow automation, APIs, Python, PowerShell, SQL, and enterprise reporting platforms.

Preferred Qualifications:

  • Certifications such as CISSP, CISM, CRISC, CCSP, GIAC, Qualys, Tenable, or equivalent.
  • Experience implementing CTEM, attack surface management, exposure validation, or risk-based vulnerability management programs.
  • Experience within financial services or other highly regulated industries.
  • Familiarity with NIST, CIS Controls, FFIEC, PCI-DSS, and cybersecurity regulatory frameworks.

Company Overview:

Mizuho Pune is an integral part of Mizuho Financial Group, one of the world’s leading financial institutions with a strong global presence across the Americas, EMEA, and Asia. Based in India, Mizuho Pune supports Mizuho’s international businesses by delivering high-quality, scalable, and resilient services across multiple functions.

Mizuho Pune plays a critical role in driving operational excellence, standardization, and innovation for Mizuho Americas. By combining deep domain expertise with strong process, technology, and analytical capabilities, it partners closely with regional and global teams to support corporate and investment banking, capital markets, and corporate services functions, while adhering to the highest standards of risk management, regulatory compliance, and control.

Mizuho Pune offers competitive compensation and benefits package aligned with industry standards and local market practices.

Mizuho Pune is an equal opportunity employer and is committed to fostering an inclusive and diverse workplace.

Employment is subject to applicable background verification checks in accordance with Indian laws and company policies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat & Exposure Management Lead
Threat & Exposure Management Lead

Mizuho • Pune District

On-site
INR 4,500,000 - 6,500,000
Vulnerability Management and Threat Exposure Management - Analyst
Vulnerability Management and Threat Exposure Management - Analyst

Mizuho • Pune District

On-site
INR 1,200,000 - 1,800,000
Cyber Fusion Center Shift Lead
Cyber Fusion Center Shift Lead

Mizuho • Pune District

Hybrid
INR 2,000,000 - 3,500,000
Cyber Security Advisory Lead
Cyber Security Advisory Lead

Mizuho • Pune District

On-site
INR 4,000,000 - 6,500,000
L1 SOC Analyst
L1 SOC Analyst

Mizuho • Pune District

On-site
INR 900,000 - 1,400,000
Cybersecurity Controls Testing Lead
Cybersecurity Controls Testing Lead

Mizuho • Pune District

On-site
INR 1,800,000 - 2,400,000
L2 SOC Analyst
L2 SOC Analyst

Mizuho • Pune District

On-site
INR 1,500,000 - 2,100,000
Senior Product Security Lead
Senior Product Security Lead

Mizuho • Pune District

On-site
INR 350,000 - 700,000
Cyber Fusion Center Threat Hunting Lead
Cyber Fusion Center Threat Hunting Lead

Mizuho • Pune District

On-site
INR 4,500,000 - 6,500,000
Cybersecurity Controls Testing Analyst
Cybersecurity Controls Testing Analyst

Mizuho • Pune District

On-site
INR 900,000 - 1,300,000