Source description
About the role
Role Overview To lead and drive the end-to-end Vulnerability Management and Remediation program across multi-cloud environments, with primary focus on Microsoft Azure and secondary exposure to Google Cloud Platform (GCP), ensuring proactive identification, prioritization, and resolution of security vulnerabilities while mentoring and managing a high-performing team. This role supports and secures the customer's public cloud environments as the firm evolves from a predominantly Azure-based footprint into a multi-cloud operating model. The Vulnerability Management Lead / Public Cloud Security Engineer serves as a technical leader responsible for identifying, engineering, and operating cloud-native vulnerability and exposure management capabilities across public cloud platforms. Requires Immediate Joiners - 15 Days Notice Period Location Pune (Work from Offshore Development Center ODC)Chennai (Client location) Key Responsibilities Lead the Vulnerability Management function across cloud and hybrid environmentsDefine strategy, roadmap, and operating model for vulnerability managementLead the engineering, onboarding, and production support of cloud security and vulnerability management platformsOwn the architecture, deployment, and lifecycle management of cloud security platformsDesign and operate security controls that support Azure today while scaling into GCPPerform vulnerability scanning, assessment, prioritization, and remediationDetect, analyze, and remediate cloud vulnerabilities, misconfigurations, and control gapsEngineer control-break detection techniques to identify systemic security failures earlyEnsure closure of vulnerabilities within defined Service Level Agreements (SLAs)Manage the vulnerability lifecycle: Discovery Assessment Remediation ReportingDefine and measure security-focused SLIs and SLOs in partnership with stakeholdersDrive automation and reporting dashboardsAct as escalation point for critical vulnerabilities; contribute to incident response, mitigation, and post-incident reviews from a cloud security perspectivePartner with cloud engineering teams to embed security controls into platform designResearch, evaluate, and recommend cloud security technologies aligned to the customer's risk postureLead, mentor, and guide the vulnerability management team; develop junior security engineers, promoting strong engineering discipline and operational excellencePrioritize team tasks and workload Cloud Environment & Security ScopeMicrosoft Azure (primary / incumbent platform) heavy hands-on exposure, approximately 70%Google Cloud Platform (GCP) for emerging data, platform, and AI workloads working exposure, approximately 30%Multi-region cloud architectures supporting production, pre-production, and development environmentsShared responsibility security models across infrastructure, platform, and application layers Cloud Security Focus Areas Cloud vulnerability management across compute, container, platform, and managed servicesIdentify, prioritize, and remediate cloud misconfigurations and vulnerabilities across Azure and GCP, including via Microsoft Defender for Cloud, Azure Security Center, Azure Policy, Azure Resource Graph, and cloud security posture management (CSPM)GCP-side visibility via Security Command Center, Cloud Asset Inventory, and Identity and Access Management (IAM) Detection of misconfigurations, control drift, and insecure cloud patternsExposure management spanning identity, network, data, and workload layersReducing systemic risk through automation, standardization, and preventative controls Security Platforms & Tooling Vulnerability management tools: Qualys, Tenable (Nessus), Rapid7, and cloud-native security tools across Azure and GCPCloud-native and enterprise security platforms, including vulnerability scanning and posture management tools; SIEM and centralized logging platforms; endpoint and workload protection technologies (EDR/XDR); packet capture and network visibility tooling where requiredIntegration of security platforms via APIs into cloud and DevOps workflowsConfiguration management and automation across large-scale security platformsWorking knowledge of network, operating system, endpoint, application, and cloud security Infrastructure & Automation Infrastructure as Code (IaC) and configuration management for security controlsTerraform and cloud-native tooling to enforce secure-by-default patternsCI/CD and DevSecOps integrations to shift vulnerability detecti .
More at PeoplePilot