U

Senior Vulnerability Management Analyst (Qualys)

UST Verified employer

Actively hiring · Posted 12d ago · JEV2609B752C05274

SalarySalary not disclosed
Experience5–7 yrs
LocationGurugram, Haryana
Work modeHybrid · Full time
Openings1

Job description

Senior Vulnerability Management Analyst (Qualys)

Posted by UST

Gurugram

Posted: imported by Jeevika

JobsPopular categoriesIT jobsSales jobsMarketing jobsData Science jobsHR jobsEngineering jobsJobs in demandFresher jobsMNC jobsRemote jobsWork from home jobsWalk-in jobsPart-time jobsJobs by locationJobs in DelhiJobs in MumbaiJobs in BangaloreJobs in HyderabadJobs in ChennaiJobs in PuneCompaniesExplore categoriesUnicornMNCStartupProduct basedInternetExplore collectionsTop companiesIT companiesFintech companiesSponsored companiesFeatured companiesResearch companies by AmbitionboxInterview questionsCompany salariesCompany reviewsSalary CalculatorServicesAI career toolsNeo AI job agentResume score checkerAI resume makerInterview Q&AAI mock interviewLive AI interviewPremium servicesNaukri ProMost popularExpert resume writingExpert power profileAI BootcampsNewFree resourcesResume samplesJob letter samplesSearch jobs hereLoginRegisterFor employersBuy onlineNaukri Talent CloudEmployer LoginSenior Vulnerability Management Analyst (Qualys)UST3.76.1K Reviews5 - 7 yearsNot DisclosedGurugramPosted: 3 days agoOpenings: 1Applicants: 35Senior Vulnerability Management Analyst (Qualys)UST3.76.1K ReviewsJob descriptionJob Summary Role at a glance Role information detail Job title Senior Vulnerability Management Analyst Team/Function Technology Services Group (TSG) - Cyber Operations/Vulnerability Management Level Senior Analyst Employment type Contract (Contractor) Location Gurgaon, India Work arrangement Hybrid. Minimum two days per week onsite at the Gurgaon office, subject to prevailing workplace policy. About the role seeking an experienced Senior Vulnerability Management Analyst to join our Cyber Operations team within the Technology Services Group on a contract basis. This is a hands-on engagement in which you will operate and drive the day-to-day maturity of our vulnerability and exposure management program across a large, diverse global environment spanning servers, endpoints, network devices, containers, and multi-cloud workloads. You will run the core tooling stack hands-on - Qualys (VMDR) for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation - and lead a Continuous Threat Exposure Management (CTEM) program that turns findings from these tools into a single, risk-prioritized view of real exposure. Working closely with IT, infrastructure, cloud, and engineering teams, you will set remediation standards, drive accountability, guide junior analysts, and brief leadership on exposure and risk trends. This role is a fixed-term contract; extension or conversion is subject to business need and performance. The role is based at our Gurgaon office in India and is hybrid, with a minimum of two days each week worked onsite. Location and work arrangement The role is based in Gurgaon, India. Candidates must be based in Gurgaon or within a daily commute of the office. The contractor is required to work from the Gurgaon office a minimum of two days per week, with the remaining days worked remotely. Specific onsite days will be confirmed with the hiring manager to fit team and operational needs. The contractor must follow prevailing workplace and attendance policy at all times. If that policy changes, including any change to the required number of office days or to the firms hybrid working model, the contractor is expected to comply with the revised policy. Key responsibilities Own and continuously mature the end-to-end vulnerability management lifecycle across the enterprise - asset discovery, scanning, detection, validation, prioritization, remediation governance, rescanning, and closure verification. Operate and administer the core exposure tooling stack hands-on - Qualys (VMDR) for host and application scanning, Wiz for cloud and container posture, and Tanium for endpoint visibility and remediation - including deployment, configuration, tuning, integration, and scanner/agent/sensor health. Lead the Continuous Threat Exposure Management (CTEM) program - running the scoping, discovery, prioritization, validation, and mobilization cycles, and correlating findings across host, cloud, and endpoint sources into a single de-duplicated, risk-ranked view of exposure. Prioritize vulnerabilities using CVSS combined with exploitability signals (EPSS, CISA Known Exploited Vulnerabilities), threat intelligence, and asset/business criticality - focusing remediation on what is actually exploitable and material. Set and enforce remediation SLAs and drive accountability with IT, infrastructure, cloud, and engineering teams - translating findings into clear, actionable work and escalating aged or high-risk exposures. Partner with threat intelligence to correlate external threat activity with internal findings, translate emerging threats into targeted validation and remediation, and surface material risks for escalation. Define exception and risk-acceptance standards, review and adjudicate requests, and maintain defensible documentation to support audits, compliance, and leadership reporting. Build and automate dashboards, metrics, and executive reporting on exposure, scan coverage, vulnerability aging, and SLA adherence - using native tool reporting, Excel (including pivot tables), and query/BI tooling. Mentor junior analysts, set standards for triage, documentation, and reporting quality, and act as the escalation point for complex or contested findings. Advise on secure configuration, hardening, and overall program maturity, and communicate findings and recommendations clearly to audiences ranging from engineers to senior stakeholders. Required qualifications Experience: 5-7 years of hands-on experience in vulnerability management, exposure management, or closely related security operations, including time in a senior or lead capacity. Lifecycle and governance: Deep understanding of the vulnerability management lifecycle, risk based remediation, and SLA governance across large, complex environments. Tooling (hands-on): Direct, hands-on experience operating and administering Qualys (VMDR), Wiz, and Tanium - including deployment, configuration, tuning, integration, and reporting. Hands-on depth with all three is required. CTEM: Demonstrated experience running or materially contributing to a Continuous Threat Exposure Management (CTEM) program across its scoping, discovery, prioritization, validation, and mobilization phases. Risk prioritization: Proficiency in CVSS analysis combined with exploitability signals (EPSS, CISA KEV) and threat-intelligence-driven, risk-based prioritization. Data and reporting: Strong data and reporting skills - Excel (including pivot tables), native tool reporting, and ideally query or BI tooling - to produce both technical and executive-level metrics. Environment breadth: Proven experience securing large, diverse environments spanning Windows, Linux, network devices, endpoints, containers, and multi-cloud workloads. Threat awareness: Strong working knowledge of threat intelligence sources and the ability to correlate external threat data with internal findings to drive prioritization. Communication and leadership: Excellent written, verbal, and presentation skills, with the ability to influence remediation owners, brief senior leadership, and mentor junior analysts. Preferred / nice-to-have Cloud and container security: Working knowledge of cloud security posture (CSPM/CNAPP) and container/Kubernetes security concepts, ideally via Wiz or an equivalent platform. Benchmarking: Working knowledge of CIS Benchmarks and secure configuration/hardening standards. Automation: Exposure to scripting or automation (e.g., Python, PowerShell, tool APIs, Power Query) to integrate tooling and streamline reporting or remediation workflows. Integrations: Experience integrating vulnerability/exposure tooling with ITSM platforms (e.g., ServiceNow) to automate remediation workflows. Certifications One or more relevant certifications preferred (or willingness to obtain): Qualys VMDR Certification Wiz Certified (or equivalent cloud security/CNAPP certification) GIAC (e.g., GEVA/GCED) or Certified Ethical Hacker (CEH) CISSP, or Tanium/CompTIA Security+ (or progress toward these) Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.Role: IT Operations Management,Industry Type: IT Services & Consulting,Department: IT & Information Security,Employment Type: Full Time, PermanentRole Category: IT Infrastructure ServicesEducationUG: Any GraduatePG: Any Postgraduateread moreKey SkillsremediationAutomationLinuxCisaPowershellWindowsSecurity operationsVulnerability managementOperationsPythonAbout the companyUST 3.7 6.1K employee reviewsIT Services & ConsultingForeign MNCPrivateProductServiceFollow372.6k followers OverviewSince 1999, UST has worked side by side with the world's best companies to make a powerful impact through transformation. Powered by technology, driven by AI, inspired by people, and led by our purpose, we partner with our clients from design to operation. Our AI-driven digital solutions, proprietary platforms, engineering, R&D, products, and innovation ecosystem turn core challenges into impactful, disruptive business outcomes. With deep industry knowledge and a future-ready mindset, we infuse expertise, innovation, and agility into our clients' organizations-delivering measurable value and positive lasting change for them, their customers, and communities around the world. Together, with 30,000+ employees in 30+ countries, we build for boundless impact-touching billions of lives in the process. Visit us at [hidden] read moreChampioning Diversity, Equity & InclusionAt UST, we believe in the power of ‘One’. Because this number signifies the immeasurable power of our unified and diverse workforce – the over 30,000 associates spread across the globe – coming together as One UST to create magic every single day. We thrive on the myriad colors of innovation that this diverse community brings to our vision of Transforming Lives. Their distinct, unique and culturally rich perspectives constitute UST’s organizational fabric that creates boundless impact for our clients, communities and people around the world. We are committed to creating and sustaining a bias-free environment and culture where every voice is heard, valued, welcome and respected. Every day is a new beginning as we continue to strengthen this culture of belonging. And as we move forward, we get closer to our goal of a brave, new, inclusive world, one small step at a time, as One UST. read moreCompany InfoLink:UST websiteAddress:Aliso Viejo, United States (USA)Beware of imposters! Naukri.com does not promise a job or an interview in exchange of money. Fraudsters may ask you to pay in the pretext of registration fee, Refundable Fee…Read moreUST rolesyou might be interested inData Engineer8-13 YrsNoidaPosted 3 Days AgoPresales Solution Architect-Network9-12 YrsGurugramPosted 2 Days AgoProduct Engineer I - Generative AI0-8 YrsGurugramPosted 30+ Days AgoAwards & Recognitions2024America's Greatest Workplaces for Diversity.2023UST Named Top Employer 2023 for 10 Countries and Retains Prestigious Blue Seal Certification for North America and Asia-Pacific from TEI.2023UST Wins 10 Brandon Hall 2023 Human Capital Management Excellence Awards.2022UST Recognised as One of the '100 Best Companies for Women in India 2022' and ‘Exemplars in Most Inclusive Companies Index in India 2022' by Avtar & Seramount.2020Business Culture Award 2020 for "Best International Initiative for Business Culture."2020Recognized as “Champion of Inclusion” and one of the “100 Best Companies for Women in India 2020” by Working Mother and Avtar.2020UST was certified as a “Great Place to Work” in the UK in 2020.ReviewsView all6

How to apply

  1. Sign in or create your free profile — takes about two minutes.
  2. Apply with one tap — your profile is shared directly with UST.
  3. Track your application and get updates by email and WhatsApp.
Apply now
You may also like

Similar jobs

More jobs
Senior Vulnerability Management Analyst (Qualys)Salary not disclosed · Gurugram
Apply