Vulnerability Management Consultant

Genpact

Región Centro

Presencial

MXN 2.037.000 - 2.716.000

Jornada completa

hace 44 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura hecha para este puesto de trabajo: un currículum y una carta de presentación adaptados que responden directamente a la oferta.

Supera los filtros ATS

Descripción de la vacante

Genpact is urgently seeking a Threat and Vulnerability Management Consultant to support a USA client. You will manage Qualys VMDR, CSAM and EASM operations, translating scan results into Jira tickets and coordinating remediation with IT partners.

As a senior analyst, you will monitor asset inventories, validate remediation, and deliver weekly metrics on open versus closed vulnerabilities, enhancing the external attack surface visibility for leadership.

Formación

  • Bachelor’s degree in information security, computer science, or equivalent operational experience.
  • Qualys VMDR: run scans, analyze results, and manage the subscription.
  • Asset management experience using CSAM or similar tools to reconcile inventories.
  • Knowledge of EASM concepts and identifying exposed assets on the internet.
  • Proficiency with Jira and using JQL to search issues and dashboards.
  • Experience partnering with System Administrators and DevOps to drive remediation.

Responsabilidades

  • Qualys Operations: manage daily health of VMDR, CSAM, and EASM.
  • Asset Discovery & Hygiene: monitor for unmanaged devices and shadow IT.
  • External Exposure: monitor external footprint and alert on unexpected assets.
  • Vulnerability Remediation Management: translate findings into Jira tickets and shepherd remediation.
  • Remediation Verification: run re-scans to confirm vulnerabilities are closed.
  • Reporting & Metrics: produce weekly reports on Open vs Closed vulnerabilities and agent health.

Conocimientos

Operational Specialist
Radar Operator
Collaborative Influencer
Data Steward
Ticket Master

Educación

Bachelor’s degree in information security / computer science

Herramientas

Qualys VMDR
Qualys CSAM
Qualys EASM
Jira
JQL

Descripción del empleo

About the Company

Genpact (NYSE: G) is a global professional services and solutions firm delivering outcomes that shape the future. Our 125,000+ people across 30+ countries are driven by our innate curiosity, entrepreneurial agility, and desire to create lasting value for clients. Powered by our purpose the relentless pursuit of a world that works better for people we serve and transform leading enterprises, including the Fortune Global 500, with our deep business and industry knowledge, digital operations services, and expertise in data, technology, and AI.

About the Company

Genpact (NYSE: G) is a global professional services and solutions firm delivering outcomes that shape the future. Our 125,000+ people across 30+ countries are driven by our innate curiosity, entrepreneurial agility, and desire to create lasting value for clients. Powered by our purpose the relentless pursuit of a world that works better for people we serve and transform leading enterprises, including the Fortune Global 500, with our deep business and industry knowledge, digital operations services, and expertise in data, technology, and AI.

About the Role

Genpact is urgently looking for a strong Consultant for one of our precious clients in USA.

Title: Threat and Vulnerability Management Consultant
Job Summary

The Senior Security Analyst (TVM Operations) ensures the organization maintains a comprehensive and real-time view of its security posture. This operational role manages the daily execution of the Qualys platform, utilizing VMDR, CSAM, and EASM to detect vulnerabilities, discover unmanaged assets, and monitor our external attack surface.

You will not be patching systems yourself; rather, you will be the "source of truth" for partner teams. Your goal is to deliver accurate, actionable data into Jira, collaborate with System Administrators to prioritize fixes, and validate that remediation has occurred.

Who you are:[AO1]
  • Operational Specialist: You enjoy the rhythm of daily operations—ensuring scans run, agents report, and data flows correctly.
  • The "Radar Operator": You are vigilant about the External Attack Surface (EASM), spotting exposed services or forgotten subdomains before adversaries do.
  • Collaborative Influencer: Since you do not apply the patches, you rely on building strong relationships with IT partner teams to drive remediation action.
  • Data Steward: You understand that a Vulnerability Management program is only as good as its asset inventory (CSAM), and you relentlessly chase down "unknown" assets.
  • Ticket Master: You are comfortable working in Jira, ensuring that security findings don't get lost in the backlog.
Responsibilities include
  • Qualys Operations: Manage the daily health of the Qualys subscription, specifically VMDR (Vulnerability Management), CSAM (CyberSecurity Asset Management), and EASM (External Attack Surface Management).
  • Asset Discovery & Hygiene (CSAM): continuously monitor the network for unmanaged devices and unauthorized software. Work with IT to install agents or decommission shadow IT.
  • External Exposure (EASM): Monitor the organization’s external footprint. Identify and alert on unexpected public-facing assets, open ports, or expired certificates.
  • Vulnerability Remediation Management: Translate scan findings into actionable Jira tickets. Assign tasks to appropriate partner teams (Server, Network, Cloud) and participate in sprint planning/backlog reviews to advocate for security tasks.
  • Remediation Verification: Execute validation scans (re-scans) once partner teams mark Jira tickets as "Resolved" to confirm the vulnerability is truly closed.
  • Scanning Execution: Configure and schedule discovery and vulnerability scans. Manage scanner appliances and exclude lists to prevent operational disruption.
  • False Positive Analysis: Review technical evidence provided by partner teams to validate "False Positive" or "Risk Acceptance" requests.
  • Reporting & Metrics: Generate weekly operational reports on "Open Vulnerabilities vs. Closed," Remediation SLAs, and Agent Health.
  • Agent Health: Troubleshoot Qualys Cloud Agents on endpoints that have stopped reporting or are failing to authenticate.
  • Threat Triage: When high-profile vulnerabilities (e.g., Log4j, HTTP/2 Rapid Reset) are announced, use VMDR and CSAM to provide immediate impact assessments to leadership.
Experience you’ll need
  • Bachelor’s degree in information security, computer science, or equivalent operational experience.
  • Qualys Power User: Proven operational experience with VMDR (running scans, analyzing results).
  • Asset Management Experience: Experience using Qualys CSAM or similar tools to reconcile asset inventories and identify "blind spots" in coverage.
  • Attack Surface Knowledge: Experience with EASM concepts—understanding DNS, public IP ranges, and how to identify assets that shouldn't be on the internet.
  • Jira Proficiency: Strong working knowledge of Jira for ticket management. Ability to use JQL (Jira Query Language) to search for issues and create dashboards.
  • Partner Collaboration: A track record of successfully working with System Administrators and DevOps teams. You know how to "speak their language" to get patches prioritized.
  • Network & OS Fundamentals: Sufficient knowledge of Windows, Linux, and Networking to help partner teams understand where a vulnerability is located and why it needs fixing.
  • Troubleshooting Skills: Ability to diagnose why a scanner can't reach a host or why an agent is offline.
  • Analytical Mindset: Ability to correlate an external finding (EASM) with an internal vulnerability (VMDR) to determine true risk.
Preferred Experience
  • Qualys Certified Specialist in CSAM or VMDR.
  • Knowledge of Cloud (AWS/Azure) asset discovery and vulnerability/misconfiguration remediation.
  • Experience with risk-based prioritization (focusing on what is exploitable vs. just high severity).
Suggestion: order these logically in some way, perhaps by Vail competencies: [AO1]

"The Vail Resorts Leadership Competencies are based on our company's core values: Leadership-Based Competencies Article"

Connect
Develop
Drive
Out Front
Re-imagine
  • Elevate
Why join Genpact
  • Lead AI-first transformation – Build and scale AI solutions that redefine industries
  • Make an impact – Drive change for global enterprises and solve business challenges that matter
  • Accelerate your career—Gain hands‑on experience, world‑class training, mentorship, and AI certifications to advance your skills
  • Grow with the best – Learn from top engineers, data scientists, and AI experts in a dynamic, fast‑moving workplace
  • Committed to ethical AI – Work in an environment where governance, transparency, and security are at the core of everything we build
  • Thrive in a values‑driven culture – Our courage, curiosity, and incisiveness - built on a foundation of integrity and inclusion - allow your ideas to fuel progress Come join the 140,000+ coders, tech shapers, and growth makers at Genpact and take your career in the only direction that matters: Up. Let’s build tomorrow together.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cyber Security Specialist
Cyber Security Specialist

Genpact • Región Centro

Presencial
MXN 900.000 - 1.300.000
Tech Lead - Cybersecurity S 4C
Tech Lead - Cybersecurity S 4C

EDM S. DE RL DE CV • Nuevo México

Híbrido
MXN 900.000 - 1.300.000
Threat & Vulnerability Management Ops Consultant
Threat & Vulnerability Management Ops Consultant

Genpact • Región Centro

Presencial
MXN 2.037.000 - 2.716.000
Consultant - Enterprise Risk Advisory 4B
Consultant - Enterprise Risk Advisory 4B

BrightClaim • Región Centro

Híbrido
MXN 600.000 - 900.000
Sr. Engineer - Infrastructure Services S 4B
Sr. Engineer - Infrastructure Services S 4B

EDM S. DE RL DE CV • Nuevo México

Híbrido
MXN 600.000 - 900.000
Specialist - F&A - R2R 4B
Specialist - F&A - R2R 4B

BrightClaim • Región Centro

Híbrido
MXN 360.000 - 720.000
Vulnerability Management
Vulnerability Management

HCLTech • Región Centro

Presencial
MXN 450.000 - 650.000
Premium coverage
Savings fund 13%
Insurance (Dental, Vision, Auto)
+2
Sr. Tech Lead - Infrastructure Services S 4D
Sr. Tech Lead - Infrastructure Services S 4D

EDM S. DE RL DE CV • Nuevo México

Híbrido
MXN 1.100.000 - 1.500.000
Specialist - F&A - I2C 4B
Specialist - F&A - I2C 4B

EDM S. DE RL DE CV • San Pedro Garza García

Híbrido
MXN 300.000 - 520.000
Sr. Network Administrator S 4B
Sr. Network Administrator S 4B

EDM S. DE RL DE CV • Nuevo México

Híbrido
MXN 350.000 - 650.000