Source description
About the role
Job ID: 865217 10 - 14 Years 1 Opening Bengaluru, Kolkata Role description Role Summary We are seeking a highly skilled Product Vulnerability Management Architect to lead the design, implementation, and evolution of enterprise-wide vulnerability management programs across products and applications. This role will also drive innovation through Agentic AIpowered security solutions, enabling automated vulnerability discovery, triage, and remediation. The ideal candidate combines deep cybersecurity expertise, strong software engineering skills, and modern AI-driven approaches to build intelligent, scalable, and secure systems. Key Responsibilities - Define and architect the end-to-end Product Vulnerability Management (PVM) framework - Design and implement Agentic AI systems for: - Automated vulnerability detection and classification - Intelligent triage and prioritization using contextual risk signals - Autonomous or semi-autonomous remediation recommendations - Develop Python-based automation frameworks for vulnerability ingestion, correlation, and response - Build custom integrations and wrappers around security scanners and AI models - Integrate vulnerability management into CI/CD pipelines and DevSecOps workflows - Establish vulnerability discovery, triage, prioritization, and remediation processes across SDLC - Drive risk-based vulnerability management aligned with business impact and threat intelligence - Collaborate with engineering teams to ensure timely remediation and secure coding practices - Perform root cause analysis and implement systemic fixes using data-driven insights - Define security standards aligned with frameworks like OWASP (Open Worldwide Application Security Project), NIST (National Institute of Standards and Technology), and ISO/IEC 27001 - Partner with AppSec, Red Team, and Threat Intelligence teams to enhance detection and response - Establish metrics, dashboards, and SLAs for vulnerability posture and remediation efficiency Skills Required Skills & Experience Cybersecurity & Vulnerability Management - 10-15 years in cybersecurity, application security, or product security roles - Deep expertise in vulnerability management at enterprise scale - Strong knowledge of: - CVE (Common Vulnerabilities and Exposures) - CVSS (Common Vulnerability Scoring System) - OWASP Top 10 - MITRE ATT&CK; Advanced Python & Automation Engineering - Strong programming expertise in Python with focus on: - API orchestration (REST, GraphQL integrations) - Data pipelines (parsing scan outputs, logs, telemetry) - Automation scripts for vulnerability remediation workflows - Experience with: - Asynchronous processing for large-scale scanning systems - SDK integrations with security tools and cloud platforms - Ability to: - Build custom wrappers and orchestration layers around scanners and AI/LLM models Agentic AI & Intelligent Automation - Hands-on experience designing Agentic AI systems and LLM-driven workflows - Understanding of: - Multi-step reasoning agents and tool orchestration - Context management, memory, and guardrails - Experience integrating AI into real-world security workflows DevSecOps & Integration Architecture - Deep understanding of: - CI/CD pipelines (GitHub Actions, Jenkins, GitLab CI) - Infrastructure as Code using Terraform and CloudFormation - Experience implementing: - Pre-commit security checks - Build-time scanning (SAST/SCA/container scans) - Runtime monitoring and feedback loops - Strong ability to embed security controls seamlessly into developer workflows Cloud & Container Security - Hands-on experience with: - AWS, Azure, or GCP security models - Kubernetes and container security - Strong understanding of: - Identity and access misconfigurations - Container and image vulnerabilities - Secrets management and secure configuration practices Preferred Certifications (Required / Highly Valued) Core Security Certifications - CISSP (Certified Information Systems Security Professional) - CISM (Certified Information Security Manager) - CISA (Certified Information Systems Auditor) Application & Offensive Security - CSSLP (Certified Secure Software Lifecycle Qualified) - OSCP (Offensive Security Certified Professional) - GIAC GWEB (GIAC Web Application Penetration Tester) Cloud & Emerging Technologies - AWS Certified Security Specialty - Microsoft Certified: Azure Security Engineer Associate - Google Professional Cloud Security Engineer AI / Automation (Nice to Have) - Certifications or coursework in AI/ML, LLMs, or autonomous systems Nice to Have - Experience with AI-assisted vulnerability management platforms - Familiarity with bug bounty programs (HackerOne, Bugcrowd) - Knowledge of Zero Trust Architecture - Experience in regulated industries (banking, fintech, healthcare) Soft Skills - Strong analytical and systems-thinking mindset - Ability to bridge security, AI, and engineering teams - Excellent communication and architecture documentation
More at Grant Thornton INDUS
Related open roles
Oracle Fusion Cloud Discrete Manufacturing Functional Lead Consultant
India
Director Risk Operation Center
India
Network Security Engineer Illumio Micro-Segmentation Specialist
Bangalore
Workday Adaptive Planning Consutant Kolkata (India)
India
Network Security Engineer Illumio Micro-Segmentation Specialist (India)
India
AI Product Security - AppSec - Assistant Manager (Kolkata)
India