Vulnerability & Incident Response Analyst

OMEGA, Inc.

Chennai District

On-site

INR 1,200,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HBK Hottinger Brüel & Kjaer (HBK) seeks a Vulnerability & Incident Response Analyst to coordinate product vulnerability management, incident reporting, and cross-functional remediation in line with EU CRA requirements.

You will liaise between Product Security, DevSecOps, and Product Teams to ensure timely assessment, tracking, remediation, and regulatory reporting across HBK products.

Qualifications

  • Experience in vulnerability management, security operations, incident response and PSIRT.
  • Understanding of vulnerability assessment methodologies, CVSS scoring, remediation workflows, and reporting.
  • Familiarity with threat intelligence sources (CVE, NVD, KEV) and secure development practices.

Responsibilities

  • Coordinate vulnerability management activities across Product Security, DevSecOps, and Product teams.
  • Assess vulnerabilities, prioritize remediation, and track status with audit trails.
  • Support regulatory reporting and governance by preparing required notifications and metrics.
  • Monitor vulnerability disclosures, advisories and KEVs relevant to HBK products and technologies.
  • Produce vulnerability status reports and dashboards for governance forums and programme tracking.
  • Facilitate cross-functional communication to resolve issues and drive timely remediation.

Skills

Vulnerability management
Incident response
PSIRT
Security incident reporting
Regulatory compliance

Education

Cyber security degree
Information Security

Tools

Vulnerability management platforms
Ticketing systems
Security scanning tools

Job description

Role Summary

The Vulnerability & Incident Response Analyst will play a key role in supporting HBK's Product Security function by coordinating product vulnerability management activities, security incident reporting obligations, and cross-functional remediation efforts. The role acts as a central liaison between Product Security, Dev SecOps, and Product Teams to ensure vulnerabilities are effectively assessed, tracked, remediated, and reported in accordance with internal policies and regulatory requirements, including the EU Cyber Resilience Act (CRA).


Key Responsibilities


  • Vulnerability Triage & Analysis Perform initial triage, validation, and analysis of product vulnerabilities identified through vulnerability disclosures, internal testing, security assessments, penetration testing, or automated scanning tools.

  • Assess vulnerability severity using CVSS, exploitability, product applicability, and business impact criteria.

  • Review vulnerability reports and collaborate with product teams to determine applicability, exploitability, and remediation requirements and help to prioritize the vulnerabilities that need to be addressed considering the Risk.

  • Maintain accurate vulnerability records, evidence, and audit trails to support governance and compliance requirements.

  • Incident & Regulatory Reporting Coordination Support coordination of security incident and exploited vulnerability reporting activities in accordance with applicable regulatory obligations.

  • Prepare and maintain the information required for regulatory notifications, working closely with Product Security, Legal, and Product Teams.

  • Track incident reporting timelines and ensure escalation activities are completed within defined regulatory timeframes.

  • Support incident readiness exercises and reporting process validation activities.

  • Vulnerability Disclosure & Threat Intelligence Monitoring Monitor vulnerability disclosure channels, PSIRT mailboxes, public vulnerability disclosures, security advisories, and relevant threat intelligence feeds.

  • Identify vulnerabilities and emerging threats that may impact HBK products and coordinate investigations with relevant stakeholders.

  • Track Known Exploited Vulnerabilities (KEVs), industry alerts, and security advisories relevant to HBK products and technologies.

  • Maintain awareness of evolving cybersecurity threats, attacker techniques, and regulatory developments.

  • Prior experience of Bug bounty portals will be an added advantage.

  • Remediation Coordination & Tracking Coordinate remediation activities with Product Teams, Dev Secops, and Product Security stakeholders.

  • Track vulnerability remediation progress against defined remediation targets and service level objectives.

  • Support review of proposed security updates, patches, and mitigation plans.

  • Produce vulnerability status reports, metrics, and management updates to support governance forums and programme tracking.

  • Cross-Functional Collaboration Serve as the operational liaison between Product Security, Dev SecOps, Customer Support, Legal, and Product Teams.

  • Facilitate communication and issue resolution across stakeholders involved in vulnerability management and incident response activities.

  • Support the implementation and continual improvement of vulnerability management and coordinated vulnerability disclosure processes.

  • Contribute to regulatory readiness initiatives associated with the EU Cyber Resilience Act and related cybersecurity requirements.


Qualifications

Education Bachelor’s or master’s degree in cyber security, Computer Science, Information Security, Software Engineering, or a related technical discipline.


Required Experience & Skills Experience in vulnerability management, security operations, incident response, PSIRT, application security, or a related cybersecurity discipline. Understanding of vulnerability assessment methodologies, CVSS scoring, exploitability analysis, and remediation workflows. Familiarity with vulnerability management platforms, ticketing systems, and security scanning tools. Knowledge of common vulnerability databases and threat intelligence sources (e.g., CVE, NVD, KEV). Understanding of software development lifecycles and secure development practices. Familiarity with cybersecurity regulations and standards such as EU CRA, ISO/IEC 30111, ISO/IEC 29147, IEC 62443, NIST SP 800 series, or ISO 27001. Strong analytical and problem-solving skills with the ability to prioritise and manage multiple activities simultaneously. Excellent stakeholder management and communication skills, with the ability to work effectively across technical and non-technical teams. Experience preparing security reports, metrics, and compliance evidence is desirable.


Preferred Experience

Experience working within a Product Security Incident Response Team (PSIRT). Exposure to regulatory reporting obligations and coordinated vulnerability disclosure programmes. Experience with vulnerability management automation, DevSecOps pipelines (SAST, DAST integration), SBOM tooling, or software composition analysis platforms. Familiarity with cloud, desktop, SaaS, embedded, or industrial control system products. Knowhow on Penetration testing


Company

One Company – HBK Hottinger Brüel & Kjaer (HBK) is a global leader in the fields of sensors, data acquisition, analytics and collaboration for various R&D, production and in-operation applications. Until the end of July 2020, the companies were known as Hottinger Baldwin Messtechnik GmbH (HBM) and Brüel & Kjær Sound & Vibration Measurement A/S respectively. HBK is part of Spectris Limited and employs around 3500 people worldwide. Our product eco system covers all layers from sensors, electronics, to software and collaboration. Our customers range from end users of the entire tool chain focusing on analytics and results in virtual testing, physical testing, and monitoring, to our OEM and system integrator partners and customers integrating our products into their own offering and solution. The product portfolio is as versatile and varied as our customer base covering many industries. We have engineering and production facilities in Germany, Denmark, UK, Portugal, USA and China and are represented in over 80 countries worldwide. We are proud to be one of the top three suppliers worldwide in our market segments served, thanks to our high-quality products and the commitment of our employees.

"IsExpired":false} }
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

OMEGA, Inc. • Chennai District

On-site
INR 11,461,000 - 17,192,000
Vulnerability & Incident Response Analyst
Vulnerability & Incident Response Analyst

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,000,000 - 1,600,000
Vulnerability And Incident Response Analyst
Vulnerability And Incident Response Analyst

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,200,000 - 1,800,000
IT Senior Architect - Linux & Open-Source
IT Senior Architect - Linux & Open-Source

OMEGA, Inc. • India

Hybrid
INR 3,500,000 - 6,500,000
SAP Basis, Cloud and Compliance Lead
SAP Basis, Cloud and Compliance Lead

OMEGA, Inc. • India

Remote
INR 300,000 - 600,000
Product Security Architect
Product Security Architect

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 3,000,000 - 5,400,000
SAP Solution Architect – Order-to-Cash (O2C)
SAP Solution Architect – Order-to-Cash (O2C)

OMEGA, Inc. • India

On-site
INR 4,000,000 - 7,000,000
Freedom with responsibility
SAP Basis, Cloud and Compliance Lead
SAP Basis, Cloud and Compliance Lead

HBK - Hottinger Brüel & Kjær • India

On-site
INR 2,600,000 - 4,200,000
Product Security Architect
Product Security Architect

OMEGA, Inc. • Chennai District

On-site
INR 1,200,000 - 1,800,000
Cyber Security Engineer (Technical Role)
Cyber Security Engineer (Technical Role)

BDx Data Centers • Navi Mumbai

On-site
INR 1,500,000 - 2,500,000