Principal Engineer

Insight

Hinoba-an

Hybrid

PHP 793,000 - 1,190,000

Full time

3 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Freedom to work from another location
Medical Insurance
Professional Development: Learning &Re

Job summary

Insight is hiring an Attack Surface Support Analyst to join the CTEM/CPEN delivery team. You’ll manage vulnerability discovery, validation, prioritization, and remediation for managed client environments using Qualys and related tools.

You’ll partner with MSP teams to onboard clients, track tickets, and ensure timely remediation while contributing to automation and process improvements.

Qualifications

  • 6–10 years of experience in vulnerability management or related cybersecurity
  • Hands-on with at least one enterprise vulnerability management platform (Qualys preferred)
  • Working knowledge of CVSS, EPSS, and risk-based prioritization concepts
  • Familiarity with patching and endpoint management tools (Intune/SCCM)
  • Experience operating within an ITSM/ticketing platform (ServiceNow)
  • Solid grasp of networking and Windows/Linux systems
  • Bachelor’s degree in Information Security, CS, or related field or equivalent experience

Responsibilities

  • Operate vulnerability management tools to discover and enrich asset exposure across hybrid environments.
  • Prioritize remediation using risk-based scoring and surface high-impact exposures.
  • Validate findings to reduce false positives before remediation.
  • Maintain exposure dashboards and metrics for clients and analysts.

Skills

Vulnerability management
Security operations
Risk-based prioritization
Patch & endpoint management
ITSM / ServiceNow
Networking & OS (Windows/Linux)
Bachelor's degree or equivalent

Education

Bachelor's degree in Information Security, Computer Science, or related field

Tools

Qualys VMDR
Tenable / Rapid7 InsightVM
Microsoft Defender Vulnerability Management
ServiceNow

Job description

Select how often (in days) to receive an alert:

Principal Engineer

Gurugram Gurgaon HR, IN

Requisition Number: 105816

Location:This is a hybrid opportunity in Delhi NCR, Bangalore, Hyderabad, Gurugram, Pune, Trivandrum area.

Insightat a Glance

  • 14,000+ engaged teammates globally with operations in 25 countries across the globe.
  • Received 35+ industry and partner awards in the past year
  • $9.2 billion in revenue
  • #14 on Forbes World's Best Employers in IT – 2023
  • #23 on Forbes Best Employers for Women in IT- 2023
  • $1.4M+ total charitable contributions in 2023 by Insight globally

Now is the time to bring your expertise to Insight. We are not just a tech company; we are a people-first company. We believe that by unlocking the power of people and technology, we can accelerate transformation and achieve extraordinary results. As aFortune 500 Solutions Integratorwith deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organisations through complex digital decisions.

About the role

The Attack Surface Support Analyst is a foundational member of the Continuous Threat Exposure Management (CTEM) and Continuous Penetration Testing (CPEN) delivery team within Insight’s Managed Security Services organization. The analystis responsible forthe day-to-day work of discovering,validating, prioritizing, and tracking remediation of vulnerabilities and exposures across managed client environments. Leveraging enterprise vulnerability management platforms such as Qualys, the analyst works in concert with automated and agentic workflows to ensure exposures are continuously cataloged, risk-ranked, and driven to verified closure. The analyst partners closely with the Managed Infrastructure Services team to dispatch and confirm remediation,supportsonboarding ofnew clients, andsustainsengagements throughout the contract lifecycle.

Key Responsibilities:
Vulnerability Management & Risk-Based Prioritization
  • Operate vulnerability management tooling(Qualys VMDR/TruRiskand equivalent platforms) to discover, catalog, and enrichan accurateinventory of assets and exposures across hybrid on-premises, Azure, and AWS client environments.
  • Prioritize remediation using risk-based scoringthat combines CVSS, EPSS, exploit availability, threat intelligence, and asset criticality — not raw severity alone — to focus effort on the exposures that matter most.
  • Validate findingsto confirm exploitability and reduce false positives before remediation is dispatched.
  • Maintainexposuredashboards and metrics(mean time to remediate, SLA adherence, exposure trend lines) and surface emerging risk to senior analysts and clients.
Automated & Agentic Workflow Operations
  • Monitor and interact with automated and agentic workflowssupporting risk-based validation, prioritization, and remediation dispatch for vulnerabilities.
  • Apply human-in-the-loop oversightby reviewing agentic recommendations for accuracy, confirming high-impact actions, and escalating anomalies or low-confidence outputs.
  • Provide tuning feedbackto continuously improve automation logic, detection content, and orchestration playbooks.
Remediation Lifecycle & Ticketing
  • Own the ticketing and remediation lifecyclefrom finding through verified closure within the ITSM platform (ServiceNow preferred).
  • Operate integrated patching toolsand coordinate with the Managed Infrastructure Services team to apply patches, configuration changes, or compensating controls.
  • Track SLAs and manage exceptionsincluding documented riskacceptances, andconfirm closure throughrescanand validation.
Client Onboarding & Engagement Support
  • Support onboarding of new CTEM & CPEN clients— scanner deployment, asset scoping, credentialed scan configuration, connector/integration setup, and baseline establishment.
  • Sustain active engagementsfor the full contract duration,participatingin recurring client touchpoints, reporting cycles, and exposure review meetings.
  • Contribute to client-facing deliverablesincluding remediation guidance, status reporting, and proof-of-execution artifacts.
What we’re looking for
Required Qualifications
  • 6-10years of experience in vulnerability management, security operations, IT systems administration, or a related cybersecurity discipline.
  • Hands-on experience with at least one enterprise vulnerability management platform — Qualys strongly preferred; Tenable, Rapid7InsightVM, or Microsoft Defender Vulnerability Management acceptable.
  • Workingunderstanding ofCVSS, EPSS, and risk-based vulnerability prioritization concepts.
  • Familiarity with patch and endpoint management tooling (e.g., Microsoft Intune/SCCM, automated patching solutions).
  • Experienceoperatingwithin an ITSM/ticketing platform (ServiceNow preferred) for workflow and tracking.
  • Solid grasp of networking, Windows and Linux operating systems, and common enterprise infrastructure.
  • Bachelor’s degree in Information Security, Computer Science, or a related field — or equivalent practical experience.
Preferred Qualifications
  • Industry certifications such as CompTIA Security+, Network+,CySA+, Qualys VMDR certification, or GIAC GFACT.
  • Exposure to penetration testing or automated/continuous pen testing platforms (e.g.,NodeZero, Pentera, Cobalt) and the Gartner CTEM framework.
  • Familiarity with SOAR/security automation and scripting (PowerShell, Python, KQL).
  • Understandingofcompliance frameworks (NIST CSF, CIS Controls v8, HIPAA/HITECH) as they relate to exposure management.
  • Prior experience in a managed services (MSSP/MXDR) or client-facing delivery environment.
Core Competencies
  • Detail orientation and analytical rigor— comfortable working with large data sets and prioritization logic.
  • Clear communication— able to translate technical findings into actionable remediation guidance for varied audiences.
  • Collaboration and service mindset— works effectively across SOC, infrastructure, and client teams.
  • Curiosity and adaptability— eager to learnevolving CTEM/CPEN tooling and agentic workflows.
What you can expect

We’re legendary for taking care of you, your family and to help you engage with your local community. We want you to enjoy a full, meaningful life and own your career at Insight. Some of our benefits include:

  • Freedom to work from another location—even an international destination—for up to 30 consecutive calendar days per year.
  • Medical Insurance
  • Professional Development: Learning Platform and Certificate Reimbursement

But what really sets us apart are our core values of Hunger, Heart, and Harmony, which guide everything we do, from building relationships with teammates, partners, and clients to making a positive impact in our communities.

Insight is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, sexual orientation or any other characteristic protected by law.

Insight India Location:Level 16, Tower B, Building No 14, Dlf Cyber City In It/Ites Sez, Sector 24 &25 A Gurugram Gurgaon Hr 122002 India

Job Segment:

Computer Science, Social Media, Cyber Security, Information Security, Engineer, Technology, Marketing, Security, Engineering

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer III
Security Engineer III

Insight • Hinoba-an

Hybrid
PHP 1,984,000 - 3,042,000
Global remote options
Medical Insurance
Certificate reimbursement
Vulnerability Consultant
Vulnerability Consultant

HRTX • Philippines

On-site
PHP 900,000 - 1,300,000
Principal Engineer - Digital Workplace
Principal Engineer - Digital Workplace

Insight • Hinoba-an

Hybrid
PHP 2,645,000 - 4,628,000
Medical Insurance
Professional Development: Learning & 1
Certificate Reimbursement
+1
Lead Security Engineer India
Lead Security Engineer India

Amtech Software • Hinoba-an

On-site
PHP 1,200,000 - 2,000,000
Vulnerability Consultant – Attack Surface Management
Vulnerability Consultant – Attack Surface Management

HRTX • Philippines

On-site
PHP 1,200,000 - 1,600,000
Application Security Manager
Application Security Manager

PwC • Makati

On-site
PHP 1,200,000 - 1,600,000
SLS Consultant Sr
SLS Consultant Sr

Insight • Hinoba-an

Hybrid
PHP 1,190,000 - 1,851,000
Freedom to work from another location
Medical Insurance
Certificate Reimbursement
Cyber Security Analyst - HYBRID 3X ONSITE
Cyber Security Analyst - HYBRID 3X ONSITE

Risewave Consulting Inc. • Quezon City

On-site
Sr Cybersecurity Analyst
Sr Cybersecurity Analyst

Dexcom Inc. • Philippines

Hybrid
PHP 1,200,000 - 2,400,000
Senior Vulnerability & Threat Engineer (CTEM/CPEN)
Senior Vulnerability & Threat Engineer (CTEM/CPEN)

Insight • Hinoba-an

Hybrid
PHP 793,000 - 1,190,000
Freedom to work from another location
Medical Insurance
Professional Development: Learning &Re