Padmi

Manager- Threat and Vulnerability Management

HyderabadPosted 3 months ago
Technology ManagementSeniorFull Time; Regular
Apply at Kshema General Insurance

Opens the source posting on shine.com

Source description

About the role

View original

As the Threat & Vulnerability Management Lead, your role involves establishing and driving the organization's end-to-end vulnerability management and threat intelligence program. Your responsibilities include proactive identification, assessment, prioritization, and remediation of security weaknesses across various areas such as infrastructure, applications, cloud environments, and third-party ecosystems. To be successful in this role, you need to adopt a strong risk-based approach, possess a deep understanding of the evolving threat landscape, and integrate vulnerability insights with enterprise risk, SOC operations, and business priorities. Key Responsibilities: - Design, implement, and mature the enterprise-wide Vulnerability Management Program aligned with business risk appetite. - Establish standardized processes for vulnerability identification, assessment, prioritization, remediation, and validation. - Define and enforce risk-based remediation SLAs based on asset criticality and exposure. - Oversee vulnerability scanning across networks, endpoints, databases, applications, APIs, and cloud platforms. - Ensure coverage across internal assets, internet-facing systems, and third-party integrations. - Establish and operationalize a Threat Intelligence capability to monitor emerging threats, attack vectors, and adversary tactics. - Correlate threat intelligence with internal vulnerabilities to identify exploitable risks. - Track global threat trends (e.g., ransomware, zero-day exploits, supply chain risks) and assess organizational exposure. - Provide actionable threat insights to SOC, incident response, and leadership teams. - Drive risk-based vulnerability prioritization using CVSS, exploitability, threat context, and business impact. - Integrate vulnerability data with enterprise risk registers and GRC platforms. - Work closely with IT, DevOps, cloud, and application teams to ensure timely remediation. - Track remediation progress, exceptions, and compensating controls. - Establish governance forums to review vulnerability posture and drive accountability. - Collaborate with DevSecOps teams to embed vulnerability management into CI/CD pipelines. - Oversee SAST, DAST, SCA, and container security scanning practices. - Ensure cloud-native vulnerability management across IaaS, PaaS, and SaaS environments. - Support secure configuration baselines and continuous posture management. - Define and track key metrics such as vulnerability aging, remediation SLAs, exposure trends, and risk reduction. - Develop dashboards and reports for senior leadership and board-level visibility. - Conduct periodic program reviews, maturity assessments, and benchmarking against industry standards. - Continuously enhance tools, processes, and automation capabilities. - Drive periodic penetration testing, red teaming, and adversary simulation exercises. - Conduct threat modeling for critical applications, systems, and new initiatives. - Validate effectiveness of security controls against real-world attack scenarios. - Partner with IT, Engineering, Cloud, SOC, Risk, and Compliance teams to ensure alignment. - Act as a subject matter expert on vulnerability and threat management for internal stakeholders. - Support audits, regulatory requirements, and third-party risk assessments. Preferred Certifications: - CISSP / CISM / CRISC - CEH / OSCP (preferred for technical depth) - GIAC certifications (e.g., GPEN, GWAPT, GCIH) - ISO 27001 Lead Auditor / Implementer Key Competencies: - Risk-based decision-making and prioritization - Strong analytical and problem-solving skills - Deep understanding of threat landscape and attack methodologies - Ability to translate technical risk into business impact - Strong stakeholder management and influencing skills - High ownership, accountability, and execution focus Requirements: - 812+ years of experience in cybersecurity, with a strong focus on vulnerability management and threat intelligence. - Experience in BFSI / Insurance sector preferred. - Hands-on experience with vulnerability management tools (e.g., Qualys, Ten (Note: The job description provided is incomplete and cuts off at "Tools (e.g., Qualys, Ten". If there is more content after this, please provide it for a complete job description.) As the Threat & Vulnerability Management Lead, your role involves establishing and driving the organization's end-to-end vulnerability management and threat intelligence program. Your responsibilities include proactive identification, assessment, prioritization, and remediation of security weaknesses across various areas such as infrastructure, applications, cloud environments, and third-party ecosystems. To be successful in this role, you need to adopt a strong risk-based approach, possess a deep understanding of the evolving threat landscape, and integrate vulnerability insights with enterprise risk, SOC operations, and business priorities. Key Responsibilities: - Design, implement, and matu

One address, no account. We’ll tell you when matching roles go live.

More at Kshema General Insurance

Related open roles

View all roles