Manager- Threat and Vulnerability Management

Posted 13 Hours Ago
Be an Early Applicant
Hyderabad, Telangana, IND
In-Office
Expert/Leader
Fintech • Insurance • Agriculture
The Role
Leads the enterprise threat and vulnerability management program, including vulnerability scanning, risk-based prioritization, remediation governance, threat intelligence, cloud and application security integration, penetration testing, threat modeling, metrics, reporting, audits, and stakeholder coordination. The role partners with IT, engineering, cloud, SOC, risk, and compliance teams to reduce exposure across infrastructure, applications, cloud environments, and third-party ecosystems.
Summary Generated by Built In

Role: Manager- Threat & Vulnerability Management 


Role Summary
The Threat & Vulnerability Management Lead will be responsible for establishing and driving the organization’s end-to-end vulnerability management and threat intelligence program. This role ensures proactive identification, assessment, prioritization, and remediation of security weaknesses across infrastructure, applications, cloud environments, and third-party ecosystems. The position requires a strong risk-based approach, deep understanding of the evolving threat landscape, and the ability to integrate vulnerability insights with enterprise risk, SOC operations, and business priorities.

Key Responsibilities

1. Vulnerability Management Program Leadership

  • Design, implement, and mature the enterprise-wide Vulnerability Management Program aligned with business risk appetite.
  • Establish standardized processes for vulnerability identification, assessment, prioritization, remediation, and validation.
  • Define and enforce risk-based remediation SLAs based on asset criticality and exposure.
  • Oversee vulnerability scanning across networks, endpoints, databases, applications, APIs, and cloud platforms.
  • Ensure coverage across internal assets, internet-facing systems, and third-party integrations.

2. Threat Intelligence & Threat Management

  • Establish and operationalize a Threat Intelligence capability to monitor emerging threats, attack vectors, and adversary tactics.
  • Correlate threat intelligence with internal vulnerabilities to identify exploitable risks.
  • Track global threat trends (e.g., ransomware, zero-day exploits, supply chain risks) and assess organizational exposure.
  • Provide actionable threat insights to SOC, incident response, and leadership teams.

3. Risk-Based Prioritization & Remediation Governance

  • Drive risk-based vulnerability prioritization using CVSS, exploitability, threat context, and business impact.
  • Integrate vulnerability data with enterprise risk registers and GRC platforms.
  • Work closely with IT, DevOps, cloud, and application teams to ensure timely remediation.
  • Track remediation progress, exceptions, and compensating controls.
  • Establish governance forums to review vulnerability posture and drive accountability.

4. Application & Cloud Security Integration

  • Collaborate with DevSecOps teams to embed vulnerability management into CI/CD pipelines.
  • Oversee SAST, DAST, SCA, and container security scanning practices.
  • Ensure cloud-native vulnerability management across IaaS, PaaS, and SaaS environments.
  • Support secure configuration baselines and continuous posture management.

5. Metrics, Reporting & Continuous Improvement

  • Define and track key metrics such as vulnerability aging, remediation SLAs, exposure trends, and risk reduction.
  • Develop dashboards and reports for senior leadership and board-level visibility.
  • Conduct periodic program reviews, maturity assessments, and benchmarking against industry standards.
  • Continuously enhance tools, processes, and automation capabilities.

6. Red Teaming, Threat Modeling & Proactive Testing

  • Drive periodic penetration testing, red teaming, and adversary simulation exercises.
  • Conduct threat modeling for critical applications, systems, and new initiatives.
  • Validate effectiveness of security controls against real-world attack scenarios.

7. Stakeholder Management & Collaboration

  • Partner with IT, Engineering, Cloud, SOC, Risk, and Compliance teams to ensure alignment.
  • Act as a subject matter expert on vulnerability and threat management for internal stakeholders.
  • Support audits, regulatory requirements, and third-party risk assessments.

Preferred Certifications

  • CISSP / CISM / CRISC
  • CEH / OSCP (preferred for technical depth)
  • GIAC certifications (e.g., GPEN, GWAPT, GCIH)
  • ISO 27001 Lead Auditor / Implementer

Key Competencies

  • Risk-based decision-making and prioritization
  • Strong analytical and problem-solving skills
  • Deep understanding of threat landscape and attack methodologies
  • Ability to translate technical risk into business impact
  • Strong stakeholder management and influencing skills
  • High ownership, accountability, and execution focus


Requirements
  • 8–12+ years of experience in cybersecurity, with strong focus on vulnerability management and threat intelligence.
  • Experience in BFSI / Insurance sector preferred.
  • Hands-on experience with vulnerability management tools (e.g., Qualys, Tenable, Rapid7, etc.).
  • Strong understanding of enterprise architecture, cloud platform (Azure), and application security.
  • Familiarity with regulatory expectations (e.g., IRDAI, RBI, ISO 27001, NIST CSF).


Skills Required

  • 8–12+ years of cybersecurity experience, with a strong focus on vulnerability management and threat intelligence
  • Hands-on experience with vulnerability management tools such as Qualys, Tenable, or Rapid7
  • Strong understanding of enterprise architecture
  • Strong understanding of cloud platforms, particularly Azure
  • Strong understanding of application security
  • Familiarity with regulatory expectations including IRDAI, RBI, ISO 27001, and NIST CSF
  • Experience in the BFSI or insurance sector
  • CISSP, CISM, or CRISC certification
  • CEH or OSCP certification
  • GIAC certification such as GPEN, GWAPT, or GCIH
  • ISO 27001 Lead Auditor or Lead Implementer certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
643 Employees
Year Founded: 2018

What We Do

Kshema General Insurance Limited is a fully digital insurance provider in India focused on making farmers financially resilient and independent. It develops and delivers crop and agricultural insurance coverage for cultivators in the agriculture and food sectors, including protection against natural perils and climate-related risks. Through digital platforms, customers can buy or renew policies, file claims, and track claim status.

Similar Jobs

Hybrid
Hyderabad, Telangana, IND
289097 Employees
Hybrid
2 Locations
289097 Employees

Wise Logo Wise

Country Risk Officer

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
Hyderabad, Telangana, IND
9000 Employees
Hybrid
Hyderabad, Telangana, IND
289097 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account