Experience
7 - 12 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Vulnerability Analyst
Job Type
Not specified
Job Description
Job Summary
Job Title: Principal Endpoint Vulnerability Management Engineer
Location: Bangalore (Hybrid)
Shift: Afternoon Shift (02:00 PM - 10:00 PM IST)
Experience: 7-10 years of overall experience. 5+ years of relevant experience.
Primary Skills: Endpoint Vulnerability Management, Patch Management, JAMF, Intune, PowerShell, Microsoft Defender
Secondary Skills: Linux, AWS, Qualys, PatchMyPC, Automox
Responsibilities
- Own the enterprise vulnerability management strategy and roadmap for endpoints, aligning with overall security architecture and business risk tolerance.
- Define and evolve organizational SLAs, risk scoring methodology, and prioritization frameworks (CVSS, EPSS, exploit intelligence, asset criticality) at a policy level.
- Establish the long-term toolchain strategy - evaluate, select, and architect vulnerability scanning and endpoint management platforms (Qualys, Rapid7, Microsoft Defender, Jamf, Intune) to scale with organizational growth.
- Act as the final escalation point and decision-maker for high-risk exceptions, complex remediation conflicts, and cross-team prioritization disputes.
- Manage operating system and application patching across Windows, macOS, virtual machines, cloud platforms, firmware, and third-party software.
- Coordinate emergency patch deployments for zero-day vulnerabilities and critical / high security incidents.
- Lead root-cause analysis for systemic or recurring vulnerability trends across the endpoint fleet (e.g., patch failures, EOL software sprawl, configuration drift) and drive engineering-level fixes.
- Define technical standards, playbooks, and reference architectures for endpoint vulnerability management, patch orchestration, and exception governance.
- Partner with Infrastructure, Cloud, Platform Engineering, and Application teams to reduce remediation timelines.
- Design and implement automated patch deployment pipelines using scripting and configuration management tools.
- Monitor patch compliance, remediation SLAs, and vulnerability trends through dashboards and executive reporting.
- Support audits and regulatory compliance requirements including ISO 27001, SOC 2, PCI DSS, HIPAA, NIST, Cyber Essentials Plus and CIS Controls.
- Mentor engineers and provide technical leadership across the organization.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, Information Technology, or related field.
- 7-10 years of experience in Infrastructure, Systems Engineering, Cybersecurity, or Vulnerability Management.
- 5+ years leading enterprise patch management programs.
- Deep knowledge of Windows Client OS, Linux, VMware, cloud platforms (AWS, Azure, GCP), and enterprise endpoint management.
- Experience with vulnerability management tools such as Qualys, Rapid7, Microsoft Defender Vulnerability Management.
- Experience with enterprise patch management solutions such as Microsoft Intune.
- With any one of the below: Automox, PatchMyPC, NinjaOne, Patch Manage.
- Strong scripting skills using PowerShell, Python, Bash.
- Experience automating operational processes using Infrastructure as Code and configuration management tools.
- Solid understanding of vulnerability scoring (CVSS), MITRE ATT&CK, and threat intelligence.
- Experience supporting large-scale enterprise environments with thousands of endpoints.
Technical Skills
- Vulnerability Management
- Patch Management
- Microsoft Intune
- JAMF
- PowerShell
- Python
- Bash
- Azure Active Directory
- Microsoft Defender
- Qualys
- Rapid7
- Automation
- Risk Management
Key Competencies
- Technical Leadership
- Strategic Planning
- Risk Assessment
- Problem Solving
- Cross-functional Collaboration
- Incident Response
- Support
- Process Improvement
- Communication and Executive Reporting
- Decision Making
- Mentoring and Coaching
