
Vulnerability Management SME (Subject Matter Expert)
- Thiruvananthapuram, Kerala
- Permanent
- Full-time
- Lead the vulnerability management program, ensuring comprehensive identification, assessment, and remediation of vulnerabilities.
- Develop and implement strategies to enhance the organization's security posture.
- Conduct in-depth vulnerability assessments and penetration testing to identify security weaknesses.
- Expertise in vulnerability management tools Qualys VMDR, MS Defender, and CrowdStrike, to detect and analyze vulnerabilities and create reports and dashboards for the customer.
- Interpret scan results and provide detailed reports with actionable recommendations.
- Prioritize vulnerabilities based on potential impact and likelihood of exploitation.
- Collaborate with technical teams to develop and implement effective remediation plans.
- Stay updated with the latest cybersecurity threats, trends, and technologies.
- Develop and deliver training sessions on vulnerability management best practices.
- Participate in incident response activities, providing expertise in vulnerability exploitation and mitigation.
- Ensure compliance with industry standards and regulatory requirements.
- Bachelor’s degree in computer science, Information Security, or a related field.
- Minimum of 7 years of experience in cybersecurity, with a focus on vulnerability management.
- In-depth knowledge of cybersecurity principles, threats, and attack vectors.
- Knowledge of network protocols, architecture, and topologies.
- Extensive experience with various operating systems (Windows, Linux, macOS) and their security configurations.
- Advanced skills in using and configuring vulnerability scanning tools, specifically Qualys VMDR, MS Defender, and CrowdStrike.
- Experience with Rapid7, Tenable, or cloud security is a plus.
- Strong analytical and critical thinking abilities to identify root causes and solutions for vulnerabilities.
- Excellent verbal and written communication skills to effectively communicate with stakeholders.
- Experience in risk assessment methodologies and patch management best practices.
- Automation skills and experience with scripting languages (e.g., Python, PowerShell) are a plus.
- Relevant certifications (e.g., CISSP, CEH, OSCP) are highly desirable.