Vulnerability Management Engineer

Posted on July 30, 2026

Apply Now

Job Description

Job Description: TJOB-44060

Overview

  • Total experience: Hands-on experience: 6 - 8 yrs
  • Minimum 5 yrs
  • Work Location: WFH / Remote
  • Work Timings: 10 AM to 7 PM (IST) | Extendable to 9 PM (IST) whenever required for interaction with US based team
  • Selection process: Initial discussions / Tech screening by Client (Audio-Video), 2 Audio-Video Technical interview(s) by the client
  • For all discussions / technical screening, the screen sharing if requested for is mandatory.
  • Identification: Aadhar Card, PAN Card, Recent & Formal photograph + First & Last page of valid passport if available
  • BGV: To be performed by the client on selection (parallely with the onboarding)
  • Internet: Appropriate bandwidth is a MUST.
  • Laptop: Will be provided by the client

Qualifications

  • Bachelor’s / Master’s degree in Computer science and Engineering / Computer Applications / Information Technology OR equivalent.
  • Any certification associated with mandatory technical skill(s) will be an added advantage.

Brief description of Role

Detection is only half of VDR — the "R" is response, and the new rules attach aggressive, class-dependent timeframes to it (as little as 12 hours for the most critical exploitable, internet-reachable findings). This role owns the operational side of the program: the runbooks, workflows, and response muscle that ensure vulnerabilities are actually evaluated, remediated, and verified within SLA. The candidate is expected to design the response playbooks, build the on-call and emergency-patch processes, execute them during the parallel-run, and train internal teams to run them after cutover.

Key Responsibilities

  • Develop the runbook library for vulnerability response: triage and evaluation runbooks, standard remediation workflows per finding type (container image, host, dependency, code), emergency-patch runbooks for PAIN-5 LEV+IRV findings (12h-2d SLAs), and verification/closure procedures
  • Design and implement the on-call and escalation model, including PagerDuty alerting rules tied to PAIN/LEV/IRV thresholds
  • Operate the response process during the parallel-run and cutover period: drive real findings through evaluation à prioritization à remediation à verification, proving the SLAs are achievable before the deadline.
  • Build the remediation verification step, ensuring fixes are confirmed in the deployed environment - not just in a rebuilt image - before findings close (runtime reconciliation as an operational practice)
  • Define SLA telemetry and drift alerting: dashboards and alerts that show when findings are approaching or breaching their timeframe class.
  • Coordinate remediation with engineering teams: patching guidance, upgrade paths, compensating controls, and clear acceptance criteria for fixes
  • Run tabletop exercises for the emergency-patch scenario and refine runbooks from lessons learned
  • Train internal security and platform teams on the runbooks; produce operator-quality documentation for handoff.

Mandatory Skills

  • Minimum 5+ years of hands-on experience in security operations, vulnerability management operations, or detection & response roles
  • Hands-on remediation experience: personally driven patching campaigns, container image updates, and dependency upgrades across engineering teams, and you know where they stall
  • Experience writing operational runbooks and incident/response procedures that other people successfully execute
  • Working knowledge of exploit intelligence and prioritization (CISA KEV, EPSS, vendor advisories) and how it changes urgency
  • Experience with alerting and on-call tooling (PagerDuty or equivalent) and SLA-driven workflows
  • Cloud and container fluency: comfortable reasoning about how a fix actually reaches production in an EKS/ECS + ECR + CI environment
  • Experience in a FedRAMP or other regulated environment where remediation timeframes are compliance obligations, not goals
  • Familiarity with DefectDojo / DefectDojo Pro or similar platforms as the system of record for response workflows
  • Incident response background (helpful for the emergency-patch discipline)
  • Experience running tabletop exercises and operational readiness reviews

Soft Skills

  • Excellent problem-solving skills, with a keen attention to detail.
  • Effective communication skills – written, spoken, listening and presentation.
  • Great Team player and experience working with global teams and global organizations.
  • Genuine interest in learning and knowledge sharing
  • Strong collaboration and communication skills, with experience working in cross-functional teams.

Required Skills

No specific skills listed.

Community Discussion

Ask questions, share feedback, or discuss this opportunity. Your comment will be visible to everyone.
Be the first to share your thoughts on this opportunity.

Clarification Board

Your Clarifications
"Send your Job Related Query - you'll get a reply soon."