Job Description
Role Purpose
The purpose of this role is to analyze attack patterns, develop incident response plans, ensure audit readiness, and implement disaster recovery measures, to ensure adherence to cyber security regulatory frameworks.
Â
͏
Areas of responsibility
Monitoring and Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards.
Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement disaster recovery measures to minimize business disruption
Threat Assessment and Analytics-Undertake forensic analysis using advanced analytics tools and implement mitigation measures to align with compliance requirements.
Stakeholder Coordination and Audit Assistance-"Liaise with cross functional teams, external vendors and auditors to ensure compliance with security frameworks.
Maintain audit documentation and ensure its accuracy while implementing processes that support audit readiness and continuous compliance."
Training and Awareness-Assist in creating and delivering cybersecurity awareness sessions, including guidance on phishing and malicious emails.
͏
͏
Role: Vulnerability Management Analyst – Qualys VM
Role Summary
We are looking for a hands‑on Vulnerability Management professional with strong operational experience on Qualys VM / VMDR to support BAU vulnerability operations for large enterprise environments.
The role is execution‑heavy and requires day‑to‑day ownership of scanning, validation, remediation tracking, reporting, and stakeholder coordination, rather than advisory or governance‑only work.
Key Responsibilities
Qualys VM Operations
- Perform authenticated and unauthenticated vulnerability scans using Qualys VM / VMDR across:
- Servers (Windows & Linux)
- Network devices
- Endpoints
- Cloud workloads (AWS / Azure)
- Manage asset discovery, tagging, and grouping within Qualys.
- Configure and maintain scan profiles, schedules, and exclusions based on environment and risk.
- Troubleshoot scan failures, authentication issues, and agent‑related problems.
Vulnerability Analysis & Validation
- Analyze Qualys scan results and:
- Validate true positives
- Identify and eliminate false positives
- Apply risk‑based prioritization using CVSS, exploitability, asset criticality, and threat context.
- Track zero‑day and high‑severity vulnerabilities and support expedited remediation.
Remediation & Stakeholder Coordination
- Create, track, and manage remediation tickets using:
- ServiceNow / Jira or equivalent ITSM tools
- Work closely with:
- Infrastructure teams
- Application owners
- Cloud and platform teams
- Follow up on remediation SLAs and perform re‑scans to confirm closure.
Reporting & BAU Governance
- Prepare and publish:
- Weekly / Monthly vulnerability reports
- Executive summaries and dashboards
- Support compliance and audit requirements (ISO 27001, CIS benchmarks, etc.).
- Maintain SOPs, runbooks, and BAU documentation.
Tooling & Automation (Good to Have)
- Support Qualys API integrations with ServiceNow, SIEM, or reporting tools.
- Basic scripting exposure (Python / PowerShell / Bash) for automation and data handling.
Mandatory Skills & Experience
Core Technical Skills
- Strong hands‑on experience with Qualys VM / Qualys VMDR (mandatory)
- Solid understanding of:
- Vulnerability lifecycle (identify → assess → remediate → validate)
- CVE, CVSS, exploitability, patching concepts
- Experience with:
- Windows & Linux OS
- Networking fundamentals (TCP/IP, ports, firewalls)
- Exposure to cloud vulnerability scanning (AWS / Azure) is highly desirable.
Tools & Platforms
- Qualys VM / VMDR
- ITSM tools: ServiceNow / Jira
- Supporting tools: Nessus / Rapid7 (good to have, not mandatory)
- Reporting tools: Excel / Power BI (basic to intermediate)
Soft Skills (Important for BAU Success)
- Strong operational ownership mindset
- Ability to manage multiple remediation streams in parallel
- Clear communication with technical and non‑technical stakeholders
- Comfortable handling escalations and SLA‑driven delivery
- Good documentation and reporting discipline
Preferred / Nice to Have
- Experience in managed security services
- Exposure to:
- Policy compliance scanning
- Cloud posture / infrastructure security
- Certifications (preferred, not mandatory):
- Qualys certification
- CEH / Security+ / ISO 27001 awareness
Role Type
- Hands‑on BAU / Run Operations
- Not a consulting‑only or GRC‑only role
- Ideal for candidates who enjoy day‑to‑day vulnerability operations and execution
Mandatory Skills: Vulnerability Management .
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.