Experience
4 - 9 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Vulnerability Analyst
Job Type
Not specified
Job Description
Quantify security effectiveness by moving from qualitative assessments to data-driven risk modeling
You will bridge the gap between technical vulnerability data and financial risk, ensuring that control failures and security gaps are measured, prioritized, and remediated based on their actual business impact
Key Responsibilities
Quantitative Risk Modeling: Run Monte Carlo simulations to calculate Annual Loss Expectancy (ALE) and use Bayesian inference to update risk probabilities based on internal vulnerability telemetry and external evidence
Vulnerability Life Cycle & Analysis: Collate and track vulnerabilities in a centralized platform, mapping them directly to the corporate security risk register across all divisions
Perform multi-dimensional analysis to determine prioritization scores, determining which vulnerabilities require immediate correction based on Threat Intelligence, vulnerability intelligence, and aggregated incident response data
Streamline and optimize various vulnerability management processes to reduce "Mean Time to Remediate" (MTTR)
Governance & Escalation: Support the Security Governance Department with remediation follow-up; continuously monitor risk posture and escalate major risks that exceed the companys risk appetite
Control Efficacy: Use Linear Regression to correlate vulnerability metrics (eg patch latency) with business downtime and financial loss
AI Automation: Apply AI Prompt Engineering to automate KRI/KPI generation using Python/SQL and to interpret complex statistical outputs for executive reporting
Required Qualifications
Experience: 4+ years in Cybersecurity, Vulnerability Management, or Quantitative Risk
Statistics: Understanding of probability distributions (Lognormal, Poisson, Beta) and statistical significance (p-values, $R^2$)
Technical Skills: Proficiency in Python or R for data modeling and SQL for querying security telemetry
Vulnerability Expertise: Deep understanding of the vulnerability management life cycle, prioritization frameworks (CVSS, EPSS), and technical control failure modes
Preferred Qualifications
Frameworks: Proficiency with FAIR (Factor Analysis of Information Risk)
Cloud: Experience managing security controls in AWS, Azure, or GCP
Certifications: CRISC, CISM, or CISSP
Expected Attributes in a potential Candidate:
Adaptive Flexibility: Pivots effectively in response to shifting priorities and organizational change
Intellectual Humility: Values external expertise and prioritizes the best solution over personal ego
Accountability: Takes full ownership of outcomes and focuses on remediation rather than excuses
Critical Thinking: Analyzes objective data to make informed, logical business decisions
Resiliency: Maintains consistent performance and a solution-oriented mindset under high pressure
Effective Communication: Distills complex ideas into clear, actionable information for all stakeholders
Collaborative Orientation: Prioritizes cross-functional goals and team success over individual recognition
Solution-Focused Initiative: Proactively identifies challenges and presents viable resolutions independently
Emotional Intelligence: Navigates interpersonal dynamics with self-awareness and professional tact
Continuous Improvement: Actively seeks feedback and upskilling opportunities to refine performance
You will bridge the gap between technical vulnerability data and financial risk, ensuring that control failures and security gaps are measured, prioritized, and remediated based on their actual business impact
Key Responsibilities
Quantitative Risk Modeling: Run Monte Carlo simulations to calculate Annual Loss Expectancy (ALE) and use Bayesian inference to update risk probabilities based on internal vulnerability telemetry and external evidence
Vulnerability Life Cycle & Analysis: Collate and track vulnerabilities in a centralized platform, mapping them directly to the corporate security risk register across all divisions
Perform multi-dimensional analysis to determine prioritization scores, determining which vulnerabilities require immediate correction based on Threat Intelligence, vulnerability intelligence, and aggregated incident response data
Streamline and optimize various vulnerability management processes to reduce "Mean Time to Remediate" (MTTR)
Governance & Escalation: Support the Security Governance Department with remediation follow-up; continuously monitor risk posture and escalate major risks that exceed the companys risk appetite
Control Efficacy: Use Linear Regression to correlate vulnerability metrics (eg patch latency) with business downtime and financial loss
AI Automation: Apply AI Prompt Engineering to automate KRI/KPI generation using Python/SQL and to interpret complex statistical outputs for executive reporting
Required Qualifications
Experience: 4+ years in Cybersecurity, Vulnerability Management, or Quantitative Risk
Statistics: Understanding of probability distributions (Lognormal, Poisson, Beta) and statistical significance (p-values, $R^2$)
Technical Skills: Proficiency in Python or R for data modeling and SQL for querying security telemetry
Vulnerability Expertise: Deep understanding of the vulnerability management life cycle, prioritization frameworks (CVSS, EPSS), and technical control failure modes
Preferred Qualifications
Frameworks: Proficiency with FAIR (Factor Analysis of Information Risk)
Cloud: Experience managing security controls in AWS, Azure, or GCP
Certifications: CRISC, CISM, or CISSP
Expected Attributes in a potential Candidate:
Adaptive Flexibility: Pivots effectively in response to shifting priorities and organizational change
Intellectual Humility: Values external expertise and prioritizes the best solution over personal ego
Accountability: Takes full ownership of outcomes and focuses on remediation rather than excuses
Critical Thinking: Analyzes objective data to make informed, logical business decisions
Resiliency: Maintains consistent performance and a solution-oriented mindset under high pressure
Effective Communication: Distills complex ideas into clear, actionable information for all stakeholders
Collaborative Orientation: Prioritizes cross-functional goals and team success over individual recognition
Solution-Focused Initiative: Proactively identifies challenges and presents viable resolutions independently
Emotional Intelligence: Navigates interpersonal dynamics with self-awareness and professional tact
Continuous Improvement: Actively seeks feedback and upskilling opportunities to refine performance
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.