Experience
3 - 8 yrs
Job Location
Hyderabad, India
Vacancy
4
Designation
Vulnerability Analyst
Job Type
Not specified
Job Description
Role & responsibilities
Vulnerability Management (VulnOps)
- Analyze, prioritize, and track security vulnerabilities identified across applications, APIs, cloud environments, operating systems, databases, and infrastructure components.
- Correlate vulnerability findings with active threats, attack patterns, threat intelligence, and security monitoring data.
- Assess vulnerability exploitability, business impact, and remediation priorities.
- Validate remediation efforts through retesting and verification activities.
- Perform root cause analysis (RCA) for recurring vulnerabilities and security issues.
- Maintain end-to-end vulnerability lifecycle management, including:
- Discovery
- Assessment
- Triage
- Prioritization
- Remediation
- Validation
- Closure tracking
- Generate vulnerability reports, dashboards, metrics, and risk summaries for stakeholders.
- Collaborate with application development, infrastructure, DevOps, and cloud teams to drive timely remediation and secure configurations.
WAF Monitoring & Threat Investigation
- Monitor and investigate Web Application Firewall (WAF) alerts and events for real-time threat detection and response.
- Analyze HTTP requests and responses, headers, parameters, payloads, session information, and user behavior patterns.
- Investigate and respond to web-based attacks including:
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Command Injection
- Local/Remote File Inclusion
- API Abuse
- Credential Stuffing
- Bot Attacks
- Directory Traversal
- Web Scanning Activities
- OWASP Top 10 attack patterns
- Correlate WAF alerts with the below by collaborating with different teams:
- SIEM events
- Application logs
- Infrastructure logs
- Threat intelligence feeds
- Endpoint security alerts
- Identify false positives and false negatives and recommend rule optimization.
- Support incident response activities involving web application security events.
- Recommend and implement WAF rule tuning, custom signatures, and policy enhancements.
Preferred candidate profile
- Strong understanding of Web Application Security concepts and OWASP Top 10.
- Experience working with WAF technologies such as:
- F5 ASM/AWAF
- Imperva
- Akamai Kona
- Knowledge of HTTP/HTTPS protocols, REST APIs, web application architecture, and authentication mechanisms.
- Understanding of common web application attack techniques and threat actor methodologies.
- Familiarity with CVSS scoring, vulnerability prioritization, and risk assessment methodologies.
- Ability to perform log analysis, attack investigation, and threat correlation.
- Experience working with development and DevOps teams in remediation activities.
Preferred Skills
- Hands-on experience with Burp Suite, OWASP ZAP, Postman, or similar tools.
- Knowledge of WAF and cloud security (AWS, Azure, GCP).
- Familiarity with threat intelligence platforms and ATT&CK framework.
- Understanding of CI/CD security practices and secure SDLC.
Qualifications
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, Engineering, or related field.
- 3- 8 years of experience in Application Security, Vulnerability Management, Threat Detection, or WAF Operations.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
