Vulnerability & Exposure Management Lead

Mizuho

Pune District

On-site

INR 3,500,000 - 6,500,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Mizuho Pune is seeking a senior Vulnerability & Exposure Management Lead to drive a risk-based CTEM capability across global operations. You will lead strategy, platform modernization, remediation governance and stakeholder engagement, partnering with Cyber Fusion Center, Cloud, and Risk teams to strengthen security posture.

The ideal candidate brings 12-15 years in security, expertise in vulnerability programs, and strong leadership in cross-functional environments.

Qualifications

  • 12-15 years of experience in Vulnerability Management, Exposure Management or related security disciplines.
  • Proven experience building or maturing enterprise Vulnerability & Exposure Management programs in large environments.
  • Strong knowledge of CTEM, attack surface management, risk-based remediation, and emerging threat trends.
  • Understanding of CVE, CVSS, KEV, threat intelligence and exposure prioritization.
  • Experience driving governance, executive reporting, and regulatory compliance activities.
  • Knowledge across cloud, on premise, identity, endpoints, networks, and ITSM integrations.

Responsibilities

  • Define and execute vulnerability and exposure management strategy and CTEM roadmap.
  • Improve visibility across infrastructure, cloud, applications, identity, and endpoints.
  • Develop risk-based prioritization using threat intel, exploitability, asset criticality, and business impact.
  • Lead remediation governance including prioritization, escalation, validation, and exception management.
  • Modernize platforms, automation, integrations, reporting, and scanning programs.
  • Partner with security teams to improve exposure analysis and risk reduction.
  • Deliver executive KPIs, KRIs, and strategic recommendations to leadership.

Skills

Vulnerability Management
Exposure Management
CTEM
Threat Intelligence
Risk-based Remediation
Cloud Security
Leadership
Stakeholder Management
Automation
Python
PowerShell
SQL
APIs

Education

Bachelor's degree in Cybersecurity
Bachelor's degree in Computer Science/Engineering

Tools

APIs
Python
PowerShell
SQL

Job description

Job Description
Why Mizuho

At Mizuho, we provide the stability of an international industry leader with the career trajectory of a growing business. Our steady, strategic growth gives our people at all levels rewarding degrees of responsibility and richer work experience than a boutique firm or an established giant could offer alone. It’s the local expertise of our employees that makes our global network so powerful. By collaborating with colleagues and clients who share the same ambition and drive, you can amplify your sphere of influence and base of knowledge as part of one of the largest banks in the world.

Summary

Mizuho Global Services (MGS) is seeking a senior, hands-on Vulnerability & Exposure Management Lead to drive the evolution of vulnerability management into a risk-based Exposure Management and Continuous Threat Exposure Management (CTEM) capability supporting Mizuho's global operations. This role is responsible for reducing cyber risk through improved visibility, intelligent prioritization, effective remediation governance, and continuous enhancement of vulnerability management capabilities. The successful candidate will lead exposure management strategy, platform modernization, remediation governance, and stakeholder engagement while partnering with Cyber Fusion Center, Infrastructure, Cloud, Application Security, and Risk teams to strengthen the organization's security posture.

Key Responsibilities
  • Define and execute the Vulnerability & Exposure Management strategy, governance framework, remediation standards, and CTEM roadmap aligned with business and cybersecurity objectives.
  • Improve visibility of vulnerabilities and exposures across infrastructure, cloud, applications, identity systems, databases, endpoints, networks, and internet-facing assets.
  • Establish risk-based prioritization methodologies leveraging threat intelligence, exploitability, asset criticality, attack-path analysis, business impact, and external exposure.
  • Drive enterprise remediation governance through prioritization, escalation, validation, exception management, risk acceptance, and accountability processes.
  • Lead modernization of vulnerability management platforms, automation capabilities, integrations, reporting, scanning programs, and operational processes.
  • Partner with Threat Intelligence, Threat Hunting, Security Operations, Cloud Security, Security Engineering, and Architecture teams to improve exposure analysis and cyber risk reduction.
  • Deliver executive reporting, KPIs, KRIs, remediation metrics, and strategic recommendations to leadership and governance forums.
Required Qualifications
  • 12-15 years of experience in Vulnerability Management, Exposure Management, Security Engineering, Cybersecurity Operations, Technology Risk, or related security disciplines.
  • Proven experience building, leading, or maturing enterprise Vulnerability & Exposure Management programs within large, complex environments.
  • Strong knowledge of CTEM, attack surface management, risk-based remediation, cyber risk reduction methodologies, and vulnerability management operating models.
  • Deep understanding of CVE, CVSS, EPSS, CISA Known Exploited Vulnerabilities (KEV), threat intelligence, exploitability analysis, attack-path analysis, asset criticality, and exposure prioritization frameworks.
  • Experience driving remediation governance, executive reporting, stakeholder engagement, exception management, and regulatory compliance activities.
  • Strong knowledge of cloud, infrastructure, application, database, identity, endpoint, network, and internet-facing security vulnerabilities and remediation practices.
  • Experience integrating vulnerability management capabilities with ITSM, CMDB, asset management, threat intelligence, SIEM, analytics, and workflow automation platforms.
  • Proficiency with APIs, Python, PowerShell, SQL, data analytics, automation, and reporting technologies.
  • Strong leadership, communication, mentoring, stakeholder management, negotiation, analytical, and decision-making skills.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or equivalent experience.
Security Technologies
  • Qualys VMDR, Tenable, CTEM and exposure management platforms, attack surface management solutions, ITSM, CMDB, SIEM, threat intelligence, cloud security, asset management, workflow automation, APIs, Python, PowerShell, SQL, and enterprise reporting platforms.
Preferred Qualifications
  • Certifications such as CISSP, CISM, CRISC, CCSP, GIAC, Qualys, Tenable, or equivalent.
  • Experience implementing CTEM, attack surface management, exposure validation, or risk-based vulnerability management programs.
  • Experience within financial services or other highly regulated industries.
  • Familiarity with NIST, CIS Controls, FFIEC, PCI-DSS, and cybersecurity regulatory frameworks.
Company Overview

Mizuho Pune is an integral part of Mizuho Financial Group, one of the world’s leading financial institutions with a strong global presence across the Americas, EMEA, and Asia. Based in India, Mizuho Pune supports Mizuho’s international businesses by delivering high-quality, scalable, and resilient services across multiple functions. Mizuho Pune plays a critical role in driving operational excellence, standardization, and innovation for Mizuho Americas. By combining deep domain expertise with strong process, technology, and analytical capabilities, it partners closely with regional and global teams to support corporate and investment banking, capital markets, and corporate services functions, while adhering to the highest standards of risk management, regulatory compliance, and control.

Mizuho Pune offers competitive compensation and benefits package aligned with industry standards and local market practices.

Mizuho Pune is an equal opportunity employer and is committed to fostering an inclusive and diverse workplace.

Employment is subject to applicable background verification checks in accordance with Indian laws and company policies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat & Exposure Management Lead
Threat & Exposure Management Lead

Mizuho • Pune District

On-site
INR 4,500,000 - 6,500,000
Vulnerability Management and Threat Exposure Management - Analyst
Vulnerability Management and Threat Exposure Management - Analyst

Mizuho • Pune District

On-site
INR 1,200,000 - 1,800,000
Cyber Fusion Center Shift Lead
Cyber Fusion Center Shift Lead

Mizuho • Pune District

Hybrid
INR 2,000,000 - 3,500,000
L1 SOC Analyst
L1 SOC Analyst

Mizuho • Pune District

On-site
INR 900,000 - 1,400,000
Cyber Fusion Center Threat Hunting Lead
Cyber Fusion Center Threat Hunting Lead

Mizuho • Pune District

On-site
INR 4,500,000 - 6,500,000
L2 SOC Analyst
L2 SOC Analyst

Mizuho • Pune District

On-site
INR 1,500,000 - 2,100,000
Cybersecurity Business Intelligence & Analytics Lead
Cybersecurity Business Intelligence & Analytics Lead

Mizuho • Pune District

On-site
INR 3,000,000 - 6,000,000
Cybersecurity Governance Analyst
Cybersecurity Governance Analyst

Mizuho • Pune District

On-site
INR 1,200,000 - 1,800,000
L3 SOC Analyst
L3 SOC Analyst

Mizuho • Pune District

On-site
INR 2,800,000 - 4,200,000
Cybersecurity Governance Lead
Cybersecurity Governance Lead

Mizuho • Pune District

On-site
INR 4,500,000 - 7,500,000