Job Description
Job Summary
Radancy is looking for a Vulnerability Management Engineer to strengthen vulnerability identification, prioritization, and remediation across our global SaaS product and corporate IT environments.
Based in our Bengaluru office, you will work with infrastructure, security, and engineering teams to ensure vulnerabilities are identified, routed to the correct owners, remediated appropriately, and validated through closure. You will also coordinate with external penetration-testing providers and technical service partners when their work contributes to vulnerability identification or remediation.
This role combines vulnerability platform engineering, operational vulnerability management, and process automation. You will help integrate tools and workflows across application, cloud, infrastructure, and external-facing environments while creating repeatable processes that reduce manual effort and improve visibility.
What does a great Vulnerability Management Engineer do
- Administer and improve vulnerability-management tools and integrations across application, cloud, infrastructure, network, and external-facing environments.
- Configure and maintain scanning coverage, schedules, asset inventories, authenticated scanning, integrations, and related workflows.
- Create scalable and automated processes to route findings to the correct teams, track remediation, support risk and exception workflows, and validate closure.
- Integrate vulnerability data with ticketing, reporting, cloud, and security platforms, including tools such as Burp Suite, Akamai, and applicable AWS and Azure services.
- Monitor externally exposed assets and public-facing applications for vulnerabilities, coverage gaps, and changes in exposure.
- Partner with infrastructure, security, and engineering teams to investigate findings, clarify risk, support remediation, and reduce recurring vulnerabilities.
- Coordinate vulnerability-related activities and findings from external penetration tests, security assessments, and technical service partners.
- Prioritize findings using exploitability, asset criticality, exposure, threat intelligence, and business context rather than severity scores alone.
- Monitor vulnerability and asset coverage, resolve scanning or integration gaps, and maintain metrics on exposure, remediation performance, exceptions, recurring issues, and overall program health.
Qualifications
- 4 or more years of experience in vulnerability management, security engineering, application security operations, cloud security, or a related technical security role.
- Hands-on experience administering vulnerability-assessment or application-security tools such as Burp Suite Enterprise, Qualys, InsightVM, Veracode, or comparable platforms.
- Experience managing the vulnerability lifecycle from discovery and prioritization through remediation, validation, exception handling, and closure.
- Experience integrating security tools with ticketing systems, APIs, cloud platforms, or other operational workflows.
- Working knowledge of vulnerabilities affecting cloud infrastructure, operating systems, networks, web applications, and common enterprise technologies.
- Understanding of CVSS, CISA Known Exploited Vulnerabilities, threat intelligence, and risk-based vulnerability prioritization.
- Familiarity with AWS environments and cloud vulnerability findings affecting services such as EC2, containers, networking, identity, and managed services.
- Strong troubleshooting, documentation, analytical, automation, and cross-functional communication skills.
Preferred Qualifications
- Experience with Burp Suite Enterprise and Akamai security products.
- Experience supporting external penetration tests and incorporating findings into vulnerability-management workflows.
- Experience with AWS-native vulnerability and security services, container or Kubernetes environments, and cloud asset inventories.
- Experience using scripting, APIs, Python, PowerShell, Terraform, or similar tools to automate vulnerability-management workflows.
- Familiarity with OWASP, NIST, ISO 27001, secure development practices, and compliance requirements related to vulnerability management.
- Experience working with distributed global engineering teams and external technical service providers.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.