Vulnerability Lead

SHI

Hyderabad

On-site

INR 1,800,000 - 3,600,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SHI is seeking a Vulnerability Management Lead to own end-to-end vulnerability program across enterprise environments, coordinating with IT, IAM, patch, and security teams. The role emphasizes risk prioritization, governance, and executive reporting, with strong focus on remediation closure of high-risk findings.

The candidate will mentor engineers, review data quality, and drive remediation using tools like Tenable, Rapid7, Tanium, and CyberArk, while aligning with industry frameworks.

Qualifications

  • 6–10 years of cybersecurity experience, focused on vulnerability management and risk-based remediation.
  • 2+ years in lead, senior analyst, or team coordination roles.
  • Experience working with US-based clients or stakeholders preferred.

Responsibilities

  • Own vulnerability management program end-to-end across servers, endpoints, networks, and cloud assets.
  • Lead vulnerability scanning strategy, schedules, coverage, and remediation governance.
  • Review findings from Tenable and Rapid7; validate risk severity and remediation priority.
  • Coordinate with patch, IAM, application, and business teams to drive remediation.
  • Develop dashboards, reports, and metrics for leadership (SLA, aging, trends).
  • Mentor vulnerability management engineers and review analysis and tickets.
  • Ensure alignment with ISO 27001, NIST, CIS Controls, PCI-DSS, and internal risk requirements.

Skills

Lead vulnerability management
Risk-based remediation
Executive reporting
Mentoring engineers
Cross-team collaboration

Education

Diploma/ Bachelor's in CS/IT

Tools

Tenable
Rapid7
TruOps
Tanium
Automox
Okta
CyberArk
CrowdStrike
SentinelOne
Power BI
Excel

Job description

Timings: 5:30pm to 2:30pm

The Vulnerability Management Lead will own and manage end-to-end vulnerability management operations across enterprise environments. This role is responsible for leading vulnerability discovery, risk prioritization, remediation governance, SLA tracking, executive reporting, and coordination with IT, infrastructure, application, IAM, endpoint, and patch management teams. The Lead will manage engineers, review vulnerability data quality, ensure accurate risk classification, and drive closure of high-risk findings using tools such as Tenable, Rapid7, TruOps, Tanium, CyberArk, Okta, CrowdStrike, SentinelOne, and Cyberfusion.

OPERATIONAL RESPONSIBILITIES
  • Lead the vulnerability management program across servers, endpoints, network devices, cloud assets, applications, identity platforms, and privileged access environments.
  • Own vulnerability scanning strategy, scan schedules, authenticated scan coverage, exception handling, risk acceptance, and remediation governance.
  • Review vulnerability findings from Tenable and Rapid7 and validate risk severity, asset criticality, exploitability, exposure, business impact, and remediation priority.
  • Coordinate with patch management, infrastructure, endpoint security, IAM, application, and business teams to drive timely vulnerability remediation.
  • Use TruOps or similar GRC/risk platforms to track risks, exceptions, remediation plans, risk acceptance, and compliance evidence.
  • Partner with patch teams using Tanium and legacy/transition tools such as Automox to Tanium to align remediation execution with vulnerability priorities.
  • Track remediation SLAs for critical, high, medium, and low vulnerabilities and elevate overdue items to stakeholders.
  • Develop dashboards, reports, and metrics for leadership, including vulnerability aging, SLA compliance, risk trends, asset coverage, recurring findings, and remediation performance.
  • Review vulnerabilities related to privileged access and identity systems such as CyberArk and Okta, ensuring privileged and identity-related risks are prioritized appropriately.
  • Collaborate with endpoint security teams using CrowdStrike and SentinelOne to correlate endpoint exposure, threat activity, and remediation priority.
  • Define and improve vulnerability management processes, playbooks, operational runbooks, exception workflows, and reporting templates.
  • Lead weekly/monthly vulnerability review meetings with internal stakeholders and client teams during USA hours.
  • Mentor vulnerability management engineers and review their analysis, reports, ticket updates, and remediation recommendations.
  • Ensure vulnerability processes align with security frameworks such as ISO 27001, NIST, CIS Controls, PCI-DSS, and internal risk requirements.
EDUCATIONAL REQUIREMENTS, TOOLS & CERTIFICATIONS

Education: Diploma/bachelors degree in computer science, Information Technology or equivalent experience.

Experience:
  • 6 to10 years of cybersecurity experience, with strong hands-on experience in vulnerability management, risk-based remediation, security operations, or infrastructure security.
  • At least 2 years in a lead, senior analyst, or team coordination role.
  • Experience working with US-based clients or stakeholders preferred.
Tools & Technologies:
  • Primary VM Tools: Tenable, Rapid7 / InsightVM
  • Patch / Remediation Tools: Tanium, Automox-to-Tanium transition exposure
  • Risk & GRC: TruOps, Cyberfusion
  • IAM / PAM: Okta, CyberArk
  • Endpoint Security: CrowdStrike, SentinelOne
  • Reporting: Power BI, Excel, dashboards, executive reporting, ticketing workflows
Certifications:
  • CISSP, CISM, Security+, CySA+, CEH, GSEC, Tenable certification, Rapid7 certification, ITIL Foundation, or equivalent.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Analyst
Vulnerability Analyst

SHI • Hyderabad

On-site
INR 900,000 - 1,300,000
Threat Vulnerability Manager
Threat Vulnerability Manager

Trekrecruit India. • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Vulnerability Analyst
Vulnerability Analyst

Zensar Technologies • Dadri

On-site
INR 1,200,000 - 1,800,000
Vulnerability Management SME
Vulnerability Management SME

Talworx Solutions • Pune District

Hybrid
INR 2,800,000 - 3,800,000
Consultant - Vulnerability Management
Consultant - Vulnerability Management

YASH Technologies • Bengaluru

On-site
INR 800,000 - 1,200,000
Cyber Security Vulnerability Assessment/ Management Specialist
Cyber Security Vulnerability Assessment/ Management Specialist

Sonata Software • Pune District

On-site
INR 1,200,000 - 2,000,000
Estuate - Vulnerability Management Engineer - SIEM Tools
Estuate - Vulnerability Management Engineer - SIEM Tools

Estuate, Inc. • Kolkata District

On-site
INR 1,200,000 - 1,800,000
Senior Cybersecurity Incident Responder - Vulnerability Management
Senior Cybersecurity Incident Responder - Vulnerability Management

Baker Tilly • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Vulnerability Analyst
Vulnerability Analyst

Zensar Technologies • Hyderabad

On-site
INR 1,200,000 - 1,800,000
VAPT Lead
VAPT Lead

SQ1 Security • Chennai District

On-site
INR 2,000,000 - 3,200,000