Source description
About the role
Job Description Job Title: Senior Threat & Vulnerability Management (TVM) Manager Experience: 812 Years Location: Bangalore / Chandigarh Role Summary The Senior Threat & Vulnerability Management (TVM) Manager is responsible for leading and maturing the organization's enterprise Threat & Vulnerability Management program. The role focuses on vulnerability governance, threat intelligence integration, risk-based prioritization, remediation management, compliance, reporting, and continuous improvement of the organization's security posture. The Senior TVM Manager will work closely with Infrastructure, Cloud, Application Development, DevSecOps, Security Operations Center (SOC), Risk & Compliance, IT Operations, and Business stakeholders to proactively identify, assess, prioritize, and mitigate security vulnerabilities across enterprise environments. The role also provides leadership to the TVM team while driving automation, governance, and operational excellence. Key Responsibilities Threat & Vulnerability Governance Lead and manage the enterprise Threat & Vulnerability Management (TVM) program across on-premises, cloud, hybrid, and containerized environments. Develop, implement, and maintain TVM policies, standards, procedures, operational playbooks, and governance frameworks. Establish Risk-Based Vulnerability Management (RBVM) practices aligned with organizational security objectives. Define vulnerability remediation SLAs and monitor compliance across business units. Ensure consistent vulnerability management processes across infrastructure, cloud, applications, databases, endpoints, and network assets. Drive continuous maturity improvements of the organization's vulnerability management capabilities. Vulnerability Assessment & Risk Prioritization Oversee enterprise-wide authenticated vulnerability assessments across servers, endpoints, cloud workloads, web applications, APIs, databases, containers, and network infrastructure. Validate vulnerability scan results and coordinate false-positive analysis. Prioritize vulnerabilities using CVSS v3.1 / v4.0 EPSS CISA Known Exploited Vulnerabilities (KEV) Threat Intelligence Asset Criticality Business Impact Internet Exposure Track vulnerability lifecycle from identification through remediation and validation. Lead emergency response for critical vulnerabilities and zero-day threats. Threat Intelligence Integration Integrate internal and external Threat Intelligence into vulnerability prioritization. Monitor emerging threats, zero-day vulnerabilities, ransomware campaigns, and exploit trends. Correlate vulnerability findings with MITRE ATT&CK techniques and threat actor activities. Recommend proactive mitigation strategies based on threat landscape analysis. Remediation & Security Operations Collaborate with Infrastructure, Cloud, DevOps, Network, Database, and Application teams to coordinate remediation activities. Monitor remediation SLAs and escalate overdue vulnerabilities. Conduct remediation review meetings with technical and business stakeholders. Validate remediation through rescanning and risk acceptance processes. Support Security Operations Center (SOC) and Incident Response teams during active security incidents. Compliance, Audit & Risk Management Ensure vulnerability management processes align with: ISO 27001 NIST Cybersecurity Framework CIS Controls PCI DSS SOC 2 GDPR HIPAA NIS2 Support internal and external security audits. Maintain audit evidence, remediation tracking, and compliance documentation. Conduct vulnerability risk assessments and support enterprise risk management activities. Track risk exceptions and compensating controls. Reporting & Metrics Develop executive dashboards and operational reports for leadership. Track and report key metrics including: Vulnerability trends Risk exposure SLA compliance Mean Time to Remediate (MTTR) Critical vulnerability aging Asset coverage Patch compliance Risk reduction Present security posture and remediation status to executive leadership and customer stakeholders. Automation & Process Improvement Drive automatio Job Description Job Title: Senior Threat & Vulnerability Management (TVM) Manager Experience: 812 Years Location: Bangalore / Chandigarh Role Summary The Senior Threat & Vulnerability Management (TVM) Manager is responsible for leading and maturing the organization's enterprise Threat & Vulnerability Management program. The role focuses on vulnerability governance, threat intelligence integration, risk-based prioritization, remediation management, compliance, reporting, and continuous improvement of the organization's security posture. The Senior TVM Manager will work closely with Infrastructure, Cloud, Application Development, DevSecOps, Security Operations Center (SOC), Risk & Compliance, IT Operations, and Business stakeholders to proactively identify, assess, prioritize, and mitigate security vulnerabilities across enterprise environments. Th
More at Tieto
Related open roles
Senior Software Engineer- 5G UE L1/ L2 - Telecom- Tieto Tech Consulting ( m/f/d)
Bangalore · Hybrid
Director, Data and Integration - Tieto Tech Consulting (m/f/d)
Bangalore
5G RAN Software Architect L1/L2- Telecom- Tieto Tech Consulting (m/f/d)
Bangalore · Hybrid
Senior IAM GRC Analyst L2 - Tieto Tech Consulting (m/f/d)
Bangalore
IAM Analyst L1/L2 - Tieto tech Consulting (m/f/d)
Bangalore
IAM Analyst L1/L2 - Tieto tech Consulting (m/f/d)
Bangalore