
Vulnerability Manager
- Bangalore, Karnataka
- Permanent
- Full-time
- Own and operate the end-to-end vulnerability management process: oversee scanning, validation, triage, risk classification, and remediation tracking.
- Coordinate with internal stakeholders to ensure vulnerabilities are addressed according to defined SLAs and risk thresholds.
- Maintain and enhance the vulnerability management framework, ensuring alignment with SAP Fioneer's security standards and regulatory requirements.
- Interface with incident response teams to contextualize vulnerabilities and prioritize remediation activities based on contextual threat intelligence, business impact, and exploitability (CVSS, KEV, EPSS).
- Deliver actionable reports and dashboards to senior leadership, highlighting trends, KPIs, and risk posture.
- Support audit and regulatory requirements by maintaining documented vulnerability management controls and remediation evidence.
- Collaborate with product and cloud security teams to embed vulnerability detection into CI/CD pipelines and cloud-native environments.
- Continuously improve the vulnerability management program, aligning with evolving threat landscapes and industry standards.
- Proven experience (5+ years) in vulnerability management, security operations, or related cybersecurity roles in a cloud/hybrid environment.
- Strong understanding of vulnerability management concepts and deep knowledge of vulnerability scanning tools.
- Solid understanding of cloud environments, especially Microsoft Azure.
- Hands-on experience with Microsoft Defender Vulnerability Management across both server and endpoint fleets.
- Hands-on experience with data analysis and reporting tools such as PowerBI or similar.
- Familiarity with Kubernetes security best practices and container scanning.
- Familiarity with ITIL-based processes and integration with ITSM platforms (e.g., ServiceNow).
- Excellent communication skills and ability to influence cross-functional teams.
- Certifications such as CISSP, OSCP, GIAC or AZ-500/SC-100
- Experience working in a regulated industry (e.g., financial services, healthcare).
- Familiarity with SAP environments and enterprise applications.
- Experience with SAP BTP represents an advantage.