Job Description
Role Purpose
The purpose of this role is to analyze attack patterns, develop incident response plans, ensure audit readiness, and implement disaster recovery measures, to ensure adherence to cyber security regulatory frameworks.
Â
͏
Areas of responsibility
Monitoring and Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards.
Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement disaster recovery measures to minimize business disruption
Threat Assessment and Analytics-Undertake forensic analysis using advanced analytics tools and implement mitigation measures to align with compliance requirements.
Stakeholder Coordination and Audit Assistance-"Liaise with cross functional teams, external vendors and auditors to ensure compliance with security frameworks.
Maintain audit documentation and ensure its accuracy while implementing processes that support audit readiness and continuous compliance."
Training and Awareness-Assist in creating and delivering cybersecurity awareness sessions, including guidance on phishing and malicious emails.
͏
͏
͏
Exposure Management Platform Engineer – JD
Role Overview
We are seeking an experienced L4 Exposure Management Platform Engineer / SME to provide technical ownership and advanced operational support for the Customer's Exposure Management environment. The role will focus on Qualys VMDR and CrowdStrike Exposure Management, covering platform administration, vulnerability scanning, exposure prioritization, integrations, remediation governance, reporting, troubleshooting and continuous improvement.
The resource will act as the technical SME and escalation point, independently handling complex platform issues, optimizing scanning and exposure management processes, supporting Customer governance, and driving automation and service improvements.
Key Responsibilities
- Provide L4 technical ownership for Exposure/Vulnerability Management platforms, primarily Qualys VMDR and CrowdStrike Exposure Management.
- Design and optimize internal, external and authenticated vulnerability scanning strategies, policies, schedules and configurations.
- Troubleshoot complex platform, scanner, agent, credential, API and integration issues and coordinate vendor escalations where required.
- Manage and optimize integrations with CMDB, ServiceNow/ITSM, SIEM, patch management and other security platforms.
- Ensure asset and vulnerability data accuracy through CMDB reconciliation, asset classification, tagging and data-quality reviews.
- Drive risk-based vulnerability prioritization using CVSS, exploitability, EPSS, KEV, asset criticality and business context.
- Provide technical oversight for vulnerability remediation governance, SLA tracking, ageing analysis, exception management and validation rescans.
- Develop and maintain operational dashboards, management reports, KPI/SLA metrics and executive-level reporting.
- Provide technical guidance for platform changes, upgrades, operational incidents and production scanning activities.
- Identify opportunities for automation, process optimization and reduction of manual operational effort.
- Maintain technical SOPs, runbooks and platform standards.
- Act as the primary technical SME for Customer discussions, complex escalations and service improvement initiatives.
- Mentor L3 resources and provide technical guidance on complex operational issues.
Key Skills Required
|
Skill Area |
Expected Capability |
|
Qualys VMDR |
VMDRAdvanced hands-on expertise in VMDR, scanners, Cloud Agents, policies, asset groups, tags, QQL, dashboards and reporting |
|
Exposure Management |
Strong understanding of exposure management, vulnerability lifecycle and risk-based prioritization |
|
Crowdstrike |
Working/advanced knowledge of Falcon Exposure Management |
|
Scanning |
Advanced knowledge of internal, external, authenticated and production-safe scanning |
|
Risk Prioritization |
CVSS, EPSS, KEV, exploitability, asset criticality and business context |
|
Integrations |
APIs, ServiceNow/ITSM, CMDB, SIEM and patch-management integrations |
|
Remediation Governance |
SLA tracking, ageing, burndown, escalation, exceptions and remediation validation |
|
Automation |
Python/PowerShell, REST APIs and automation of repetitive VM activities |
|
Troubleshooting |
Advanced troubleshooting of scanners, agents, credentials, connectors, APIs and platform configurations |
|
Reporting |
Advanced dashboards, KPI/SLA reporting and executive communication |
|
Cloud & Infrastructure |
Strong understanding of Windows/Linux, networking and AWS/Azure/GCP exposure concepts |
|
CTEM |
Good understanding of Continuous Threat Exposure Management and threat-informed prioritization |
Mandatory Qualifications & Certifications
- 8+ years of overall cybersecurity experience with 5+ years in Vulnerability/Exposure Management.
- Strong hands-on Qualys VMDR experience.
- Experience managing enterprise-scale vulnerability scanning operations.
- Experience with vulnerability prioritization, remediation governance and validation.
- Experience with enterprise security-tool integrations and APIs.
- Strong Customer-facing and stakeholder-management capabilities.
- CISSP or equivalent senior security certification.
- Qualys VMDR / Vulnerability Management certification or formal Qualys training – strongly preferred.
Good-to-Have Certifications
- CISM / CRISC
- GIAC security certifications
- CrowdStrike certification/training
- ServiceNow Vulnerability Response certification/training
- ITIL Foundation
- AWS Security Specialty / Azure Security certification
- OSCP – beneficial for deeper technical vulnerability analysis, but not essential for platform operations.
Mandatory Skills: Vulnerability Assessment Penetrationtest .
Experience: 5-8 Years .
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.