We are seeking a Senior Product Security & Vulnerability Management Engineer to lead vulnerability management, application security testing, and product security operations across the enterprise. This role will serve as the primary security partner to Product Engineering, DevOps, and Cloud teams, helping identify, prioritize, remediate, validate, and report security risks across applications, cloud environments, infrastructure, and software development pipelines.
The ideal candidate combines hands-on technical expertise with strong program coordination skills. The role requires someone who can operate security tooling, challenge and validate findings, work effectively with engineering teams, and maintain enterprise-level visibility of remediation performance and risk.
About You – experience, education, skills, and accomplishments
- Minimum five years of experience in cybersecurity, product security, application security, vulnerability management, DevSecOps, or a closely related discipline.
- Hands-on experience operating an enterprise vulnerability management platform such as Qualys, Tenable, Rapid7, or an equivalent solution.
- Experience with application security testing, including SAST, DAST, SCA, secrets scanning, and Infrastructure as Code scanning.
- Experience with GitHub Advanced Security, Checkmarx, Burp Suite, or comparable technologies.
- Demonstrated ability to work directly with software engineering, DevOps, Cloud, and technology operations teams to triage and remediate findings.
- Working knowledge of secure software development, OWASP guidance, cloud security, modern CI/CD practices, and vulnerability remediation workflows.
- Experience coordinating third-party penetration tests and tracking findings through validation and closure.
- Ability to communicate technical risk clearly to engineering teams, control owners, GRC stakeholders, and leadership.
- Strong organizational skills and the ability to oversee multiple workstreams across a distributed enterprise.
It would be great if you also had . . .
- Experience supporting AWS environments, containerized workloads, Kubernetes, and cloud-native application architectures.
- Experience with EASM, exposure management, attack-path analysis, or continuous threat exposure management capabilities.
- Experience designing or improving security checks in GitHub Actions or comparable CI/CD platforms.
- Familiarity with ISO 27001, SOC 2, PCI DSS, secure development controls, risk exceptions, and audit evidence requirements.
- Experience developing vulnerability management dashboards and metrics for both engineering and executive audiences.
- Experience or demonstrated interest in using AI, APIs, scripting, and workflow automation to improve vulnerability management reporting and operations.
- Relevant certifications such as CISSP, CSSLP, GIAC, OSCP, cloud security, or comparable credentials are beneficial but not required.
What will you be doing in this role?
- Conduct in-depth analysis of security alerts and incidents to determine the root cause and impact.
- Utilize incident response plans, including containment, eradication, and recovery strategies.
- Lead investigations into security breaches and incidents, documenting findings and recommendations for remediation.
- Assist in the development and enforcement of security policies, procedures, and best practices.
- Collaborate with cross-functional teams to assess security risks associated with new projects and initiatives.
- Provide guidance and mentorship to Level 1 Security Analysts, helping them enhance their skills and knowledge.
- Monitor and analyze security logs and data sources to proactively identify emerging threats and vulnerabilities.
- Stay abreast of industry trends, emerging threats, and best practices in cybersecurity.
- Play a key role in the creation and maintenance of playbooks and SOPs.
Job Location: Bangalore
Work Mode: Hybrid (Monday to Friday)
At Clarivate, we are committed to providing equal employment opportunities for all qualified persons with respect to hiring, compensation, promotion, training, and other terms, conditions, and privileges of employment. We comply with applicable laws and regulations governing non-discrimination in all locations.
Skills Required
- At least five years of experience in cybersecurity, product security, application security, vulnerability management, DevSecOps, or a related discipline
- Hands-on experience with an enterprise vulnerability management platform such as Qualys, Tenable, Rapid7, or equivalent
- Experience with application security testing, including SAST, DAST, SCA, secrets scanning, and Infrastructure as Code scanning
- Experience with GitHub Advanced Security, Checkmarx, Burp Suite, or comparable technologies
- Experience collaborating with software engineering, DevOps, Cloud, and technology operations teams to triage and remediate findings
- Working knowledge of secure software development, OWASP guidance, cloud security, CI/CD practices, and vulnerability remediation workflows
- Experience coordinating third-party penetration tests and tracking findings through validation and closure
- Ability to communicate technical risk to engineering teams, control owners, GRC stakeholders, and leadership
- Strong organizational skills and ability to oversee multiple workstreams across a distributed enterprise
- Experience supporting AWS environments, containerized workloads, Kubernetes, and cloud-native application architectures
- Experience with EASM, exposure management, attack-path analysis, or continuous threat exposure management
- Experience designing or improving security checks in GitHub Actions or comparable CI/CD platforms
- Familiarity with ISO 27001, SOC 2, PCI DSS, secure development controls, risk exceptions, and audit evidence requirements
- Experience developing vulnerability management dashboards and metrics for engineering and executive audiences
- Experience or demonstrated interest in AI, APIs, scripting, and workflow automation for vulnerability management
- Relevant certifications such as CISSP, CSSLP, GIAC, OSCP, cloud security, or comparable credentials
Clarivate Analytics Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Clarivate Analytics and has not been reviewed or approved by Clarivate Analytics.
-
Strong & Reliable Incentives — Incentives in sales and select product/tech roles provide meaningful upside for high performers, with commission structures boosting total compensation when targets are exceeded. Role-linked variable pay is a clear strength in revenue-driving positions.
-
Leave & Time Off Breadth — PTO is ample in the U.S., with paid parental leave available, making time-off policies a notable part of the package. Generous vacation and holiday allowances stand out as positives.
-
Wellbeing & Lifestyle Benefits — Hybrid and remote options are common and paired with a formal wellbeing framework and EAP, supporting work–life balance. Core medical, dental, and vision coverage is broadly available in the U.S., reinforcing everyday wellbeing support.
Clarivate Analytics Insights
What We Do
Clarivate™ is a global leader in providing solutions to accelerate the lifecycle of innovation. Our bold mission is to help customers solve some of the world’s most complex problems by providing actionable information and insights that reduce the time from new ideas to life-changing inventions in the areas of science and intellectual property. We help customers discover, protect and commercialize their inventions using our trusted subscription and technology-based solutions coupled with deep domain expertise. For more information, please visit clarivate.com.

.png)






