Padmi

Threat and Vulnerability Manager

Bangalore · HybridPosted 2 months ago
Technology ManagementSenior
Apply at Tieto

Opens the source posting on naukri.com

Source description

About the role

View original

Job Description Job Title: Senior Threat & Vulnerability Management (TVM) Manager Experience: 812 Years Location: Bangalore / Chandigarh Role Summary The Senior Threat & Vulnerability Management (TVM) Manager is responsible for leading and maturing the organization's enterprise Threat & Vulnerability Management program. The role focuses on vulnerability governance, threat intelligence integration, risk-based prioritization, remediation management, compliance, reporting, and continuous improvement of the organization's security posture. The Senior TVM Manager will work closely with Infrastructure, Cloud, Application Development, DevSecOps, Security Operations Center (SOC), Risk & Compliance, IT Operations, and Business stakeholders to proactively identify, assess, prioritize, and mitigate security vulnerabilities across enterprise environments. The role also provides leadership to the TVM team while driving automation, governance, and operational excellence. Key Responsibilities Threat & Vulnerability Governance Lead and manage the enterprise Threat & Vulnerability Management (TVM) program across on-premises, cloud, hybrid, and containerized environments. Develop, implement, and maintain TVM policies, standards, procedures, operational playbooks, and governance frameworks. Establish Risk-Based Vulnerability Management (RBVM) practices aligned with organizational security objectives. Define vulnerability remediation SLAs and monitor compliance across business units. Ensure consistent vulnerability management processes across infrastructure, cloud, applications, databases, endpoints, and network assets. Drive continuous maturity improvements of the organization's vulnerability management capabilities. Vulnerability Assessment & Risk Prioritization Oversee enterprise-wide authenticated vulnerability assessments across servers, endpoints, cloud workloads, web applications, APIs, databases, containers, and network infrastructure. Validate vulnerability scan results and coordinate false-positive analysis. Prioritize vulnerabilities using: CVSS v3.1 / v4.0 EPSS CISA Known Exploited Vulnerabilities (KEV) Threat Intelligence Asset Criticality Business Impact Internet Exposure Track vulnerability lifecycle from identification through remediation and validation. Lead emergency response for critical vulnerabilities and zero-day threats. Threat Intelligence Integration Integrate internal and external Threat Intelligence into vulnerability prioritization. Monitor emerging threats, zero-day vulnerabilities, ransomware campaigns, and exploit trends. Correlate vulnerability findings with MITRE ATT&CK techniques and threat actor activities. Recommend proactive mitigation strategies based on threat landscape analysis. Remediation & Security Operations Collaborate with Infrastructure, Cloud, DevOps, Network, Database, and Application teams to coordinate remediation activities. Monitor remediation SLAs and escalate overdue vulnerabilities. Conduct remediation review meetings with technical and business stakeholders. Validate remediation through rescanning and risk acceptance processes. Support Security Operations Center (SOC) and Incident Response teams during active security incidents. Compliance, Audit & Risk Management Ensure vulnerability management processes align with: ISO 27001 NIST Cybersecurity Framework CIS Controls PCI DSS SOC 2 GDPR HIPAA NIS2 Support internal and external security audits. Maintain audit evidence, remediation tracking, and compliance documentation. Conduct vulnerability risk assessments and support enterprise risk management activities. Track risk exceptions and compensating controls. Reporting & Metrics Develop executive dashboards and operational reports for leadership. Track and report key metrics including: Vulnerability trends Risk exposure SLA compliance Mean Time to Remediate (MTTR) Critical vulnerability aging Asset coverage Patch compliance Risk reduction Present security posture and remediation status to executive leadership and customer stakeholders. Automation & Process Improvement Drive automation initiatives for vulnerability scanning, ticket creation, remediation tracking, reporting, and asset correlation. Integrate TVM platforms with: ServiceNow SIEM CMDB Asset Management Security Orchestration platforms Identify opportunities to improve operational efficiency through scripting, APIs, and workflow automation. Lead continuous improvement initiatives and adoption of industry best practices. Team Leadership & Stakeholder Management Lead and mentor Threat & Vulnerability Management Engineers and Analysts. Provide technical guidance, coaching, and career development. Collaborate with cross-functional teams including SOC, Infrastructure, Cloud, DevSecOps, Compliance, and Audit. Manage customer and executive stakeholder communications. Participate in strategic security planning and governance meetings. Required Technical Skills Threat & Vulnerability Management Enterprise Vulnerability Management Risk-Based Vulnerability Management (RBVM) Vulnerability Risk Assessment Vulnerability Prioritization Patch Management Governance Threat Intelligence Integration Vulnerability Validation Security Configuration Assessment Secure Baseline Compliance Exposure Management Vulnerability Management Platforms Tenable Security Center Tenable.io Nessus Qualys VMDR Rapid7 InsightVM Microsoft Defender Vulnerability Management CrowdStrike Falcon Exposure Management Prisma Cloud Wiz ServiceNow Vulnerability Response Cloud & Infrastructure Security Microsoft Azure Amazon Web Services (AWS) Google Cloud Platform (GCP) Kubernetes Docker VMware Windows Server Linux Network Infrastructure Threat Intelligence & Security Frameworks CVSS v3.1 / v4.0 EPSS MITRE ATT&CK MITRE CVE CISA Known Exploited Vulnerabilities (KEV) OWASP Top 10 CIS Benchmarks NIST Cybersecurity Framework ISO/IEC 27001 PCI DSS SOC 2 ITSM & Process Management ServiceNow ITIL Framework Incident Management Change Management Problem Management Configuration Management (CMDB) Documentation & Reporting Executive Reporting Security Metrics & KPIs Dashboard Development Risk Registers Audit Evidence Management Process Documentation Standard Operating Procedures (SOPs) Preferred Qualifications Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related discipline. 8 to 12 years of experience in Cybersecurity with a strong focus on Threat & Vulnerability Management. Minimum 4 years of experience managing enterprise Vulnerability Management or Security Operations teams. Experience leading enterprise-scale Vulnerability Management programs across hybrid and multi-cloud environments. Experience working with Managed Security Services (MSS), Security Operations Centers (SOC), or large enterprise security teams. Strong understanding of cloud security, exposure management, and DevSecOps practices. Experience integrating vulnerability management with SIEM, SOAR, CMDB, Asset Management, and ITSM platforms. Preferred Certifications Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Certified Information Systems Auditor (CISA) GIAC Certified Enterprise Defender (GCED) GIAC Continuous Monitoring Certification (GMON) CompTIA CySA+ CompTIA Security+ Microsoft Certified: Cybersecurity Architect Expert Microsoft Certified: Azure Security Engineer Associate (AZ-500) AWS Certified Security Specialty Tenable Certified Nessus Auditor Qualys Certified Specialist ITIL Foundation Key Competencies Strategic Leadership Risk-Based Decision Making Customer Focus Innovation & Continuous Improvement Stakeholder Management Analytical Thinking Team Leadership & Coaching Executive Communication Cross-functional Collaboration Operational Excellence Problem Solving Project & Program Management Security Governance Process Optimization Results Orientation

One address, no account. We’ll tell you when matching roles go live.

More at Tieto

Related open roles

View all roles