Base Career helps you apply smarter for this job.
Key skills for this role
Design, implement, and mature the enterprise-wide Vulnerability Management Program aligned with business risk appetite.
Establish standardized processes for vulnerability identification, assessment, prioritization, remediation, and validation.
Define and enforce risk-based remediation SLAs based on asset criticality and exposure.
Oversee vulnerability scanning across networks, endpoints, databases, applications, APIs, and cloud platforms.
Ensure coverage across internal assets, internet-facing systems, and third-party integrations.
Establish and operationalize a Threat Intelligence capability to monitor emerging threats, attack vectors, and adversary tactics.
Correlate threat intelligence with internal vulnerabilities to identify exploitable risks.
Track global threat trends (e.g., ransomware, zero-day exploits, supply chain risks) and assess organizational exposure.
Provide actionable threat insights to SOC, incident response, and leadership teams.
Drive risk-based vulnerability prioritization using CVSS, exploitability, threat context, and business impact.
Integrate vulnerability data with enterprise risk registers and GRC platforms.
Work closely with IT, DevOps, cloud, and application teams to ensure timely remediation.
Track remediation progress, exceptions, and compensating controls.
Establish governance forums to review vulnerability posture and drive accountability.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Secunderabad, IND
Secunderabad, IND
Hyderabad, IND
Secunderabad, IND
Secunderabad, IND
Hyderabad, IND
Secunderabad, IND
Hyderabad, IND
Define and track key metrics such as vulnerability aging, remediation SLAs, exposure trends, and risk reduction.
Develop dashboards and reports for senior leadership and board-level visibility.
Conduct periodic program reviews, maturity assessments, and benchmarking against industry standards.
Continuously enhance tools, processes, and automation capabilities.
Drive periodic penetration testing, red teaming, and adversary simulation exercises.
Conduct threat modeling for critical applications, systems, and new initiatives.
Validate effectiveness of security controls against real-world attack scenarios.
Partner with IT, Engineering, Cloud, SOC, Risk, and Compliance teams to ensure alignment.
Act as a subject matter expert on vulnerability and threat management for internal stakeholders.
Support audits, regulatory requirements, and third-party risk assessments.
CISSP / CISM / CRISC
CEH / OSCP (preferred for technical depth)
GIAC certifications (e.g., GPEN, GWAPT, GCIH)
ISO 27001 Lead Auditor / Implementer
Risk-based decision-making and prioritization
Strong analytical and problem-solving skills
Deep understanding of threat landscape and attack methodologies
Ability to translate technical risk into business impact
Strong stakeholder management and influencing skills
High ownership, accountability, and execution focus
A digital insurance provider building financial resilience among farmers from income shocks due to climate events.
Visit company websiteJobs and hiring trendsFull-time
Senior · 8+ years experience
Onsite
Apply faster on company sites with our extension.