Vulnerability & Incident Response Analyst

Posted 5 Days Ago
Be an Early Applicant
Chennai, Tamil Nadu, IND
In-Office
Mid level
Industrial • Manufacturing
The Role
Coordinate product vulnerability management and incident reporting, triage and analyze vulnerabilities, track remediation with product and DevSecOps teams, monitor threat intelligence and disclosures, support regulatory reporting (including EU CRA), and produce status metrics and governance reports.
Summary Generated by Built In
Role Summary

The Vulnerability & Incident Response Analyst will play a key role in supporting HBK's Product Security function by coordinating product vulnerability management activities, security incident reporting obligations, and cross-functional remediation efforts. The role acts as a central liaison between Product Security, Dev SecOps, and Product Teams to ensure vulnerabilities are effectively assessed, tracked, remediated, and reported in accordance with internal policies and regulatory requirements, including the EU Cyber Resilience Act (CRA).

Key Responsibilities

Vulnerability Triage & Analysis
  • Perform initial triage, validation, and analysis of product vulnerabilities identified through vulnerability disclosures, internal testing, security assessments, penetration testing, or automated scanning tools.
  • Assess vulnerability severity using CVSS, exploitability, product applicability, and business impact criteria.
  • Review vulnerability reports and collaborate with product teams to determine applicability, exploitability, and remediation requirements and help to prioritize the vulnerabilities that need to be addressed considering the Risk.
  • Maintain accurate vulnerability records, evidence, and audit trails to support governance and compliance requirements.
Incident & Regulatory Reporting Coordination
  • Support coordination of security incident and exploited vulnerability reporting activities in accordance with applicable regulatory obligations.
  • Prepare and maintain the information required for regulatory notifications, working closely with Product Security, Legal, and Product Teams.
  • Track incident reporting timelines and ensure escalation activities are completed within defined regulatory timeframes.
  • Support incident readiness exercises and reporting process validation activities.
Vulnerability Disclosure & Threat Intelligence Monitoring
  • Monitor vulnerability disclosure channels, PSIRT mailboxes, public vulnerability disclosures, security advisories, and relevant threat intelligence feeds.
  • Identify vulnerabilities and emerging threats that may impact HBK products and coordinate investigations with relevant stakeholders.
  • Track Known Exploited Vulnerabilities (KEVs), industry alerts, and security advisories relevant to HBK products and technologies.
  • Maintain awareness of evolving cybersecurity threats, attacker techniques, and regulatory developments.
  • Prior experience of Bug bounty portals will be an added advantage.
Remediation Coordination & Tracking
  • Coordinate remediation activities with Product Teams, Dev Secops, and Product Security stakeholders.
  • Track vulnerability remediation progress against defined remediation targets and service level objectives.
  • Support review of proposed security updates, patches, and mitigation plans.
  • Produce vulnerability status reports, metrics, and management updates to support governance forums and programme tracking.
Cross-Functional Collaboration
  • Serve as the operational liaison between Product Security, Dev SecOps, Customer Support, Legal, and Product Teams.
  • Facilitate communication and issue resolution across stakeholders involved in vulnerability management and incident response activities.
  • Support the implementation and continual improvement of vulnerability management and coordinated vulnerability disclosure processes.
  • Contribute to regulatory readiness initiatives associated with the EU Cyber Resilience Act and related cybersecurity requirements.

Qualifications

Education
  • Bachelor’s or master’s degree in cyber security, Computer Science, Information Security, Software Engineering, or a related technical discipline.
Required Experience & Skills
  • Experience in vulnerability management, security operations, incident response, PSIRT, application security, or a related cybersecurity discipline.
  • Understanding of vulnerability assessment methodologies, CVSS scoring, exploitability analysis, and remediation workflows.
  • Familiarity with vulnerability management platforms, ticketing systems, and security scanning tools.
  • Knowledge of common vulnerability databases and threat intelligence sources (e.g., CVE, NVD, KEV).
  • Understanding of software development lifecycles and secure development practices.
  • Familiarity with cybersecurity regulations and standards such as EU CRA, ISO/IEC 30111, ISO/IEC 29147, IEC 62443, NIST SP 800 series, or ISO 27001.
  • Strong analytical and problem-solving skills with the ability to prioritise and manage multiple activities simultaneously.
  • Excellent stakeholder management and communication skills, with the ability to work effectively across technical and non-technical teams.
  • Experience preparing security reports, metrics, and compliance evidence is desirable.
Preferred Experience
  • Experience working within a Product Security Incident Response Team (PSIRT).
  • Exposure to regulatory reporting obligations and coordinated vulnerability disclosure programmes.
  • Experience with vulnerability management automation, DevSecOps pipelines (SAST, DAST integration), SBOM tooling, or software composition analysis platforms.
  • Familiarity with cloud, desktop, SaaS, embedded, or industrial control system products.
  • Knowhow on Penetration testing

Skills Required

  • Bachelor's or master's degree in Cyber Security, Computer Science, Information Security, Software Engineering, or related discipline
  • Experience in vulnerability management, security operations, incident response, PSIRT, or application security
  • Understanding of vulnerability assessment methodologies, CVSS scoring, exploitability analysis, and remediation workflows
  • Familiarity with vulnerability management platforms, ticketing systems, and security scanning tools
  • Knowledge of common vulnerability databases and threat intelligence sources (CVE, NVD, KEV)
  • Understanding of software development lifecycles and secure development practices
  • Familiarity with cybersecurity regulations and standards (EU CRA, ISO/IEC 30111, ISO/IEC 29147, IEC 62443, NIST SP 800 series, ISO 27001)
  • Strong analytical, prioritization, stakeholder management and communication skills
  • Experience preparing security reports, metrics, and compliance evidence
  • Experience working within a Product Security Incident Response Team (PSIRT)
  • Exposure to regulatory reporting obligations and coordinated vulnerability disclosure programmes
  • Experience with vulnerability management automation, DevSecOps pipelines (SAST, DAST integration), SBOM tooling, or software composition analysis platforms
  • Familiarity with cloud, desktop, SaaS, embedded, or industrial control system products
  • Experience or knowhow in penetration testing

HBK - Hottinger Brüel & Kjær Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about HBK - Hottinger Brüel & Kjær and has not been reviewed or approved by HBK - Hottinger Brüel & Kjær.

  • Leave & Time Off Breadth Time off is portrayed as generous, including PTO and paid holidays, with mentions of four weeks of vacation for new U.S. hires.
  • Healthcare Strength Core health coverage is present, including medical and dental plans, with HSA options noted in some U.S. contexts.
  • Parental & Family Support Parental leave is highlighted positively, with maternity and paternity leave called out as a strength in multiple public materials.

HBK - Hottinger Brüel & Kjær Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Egham
1,244 Employees
Year Founded: 1942

What We Do

Hottinger Brüel & Kjær was founded in 2019, when HBM and Brüel & Kjær merged their activities into a new company. Both companies are market leaders in their respective disciplines – Brüel & Kjær in sound and vibration and HBM in reliability, durability, propulsion efficiency and weighing. Together, they cover the complete product physics domain. In technical terms, Brüel & Kjær is the frequency domain expert and HBM the time domain expert. HBK helps its customers reduce time-to-market by simultaneously performing tests, retrieving and analyzing data, aiding decision-making

Similar Jobs

Comcast Logo Comcast

Development Engineer

Digital Media • Information Technology • News + Entertainment
Hybrid
Chennai, Tamil Nadu, IND
115000 Employees

Comcast Logo Comcast

Development Engineer

Digital Media • Information Technology • News + Entertainment
Hybrid
Chennai, Tamil Nadu, IND
115000 Employees

Capco Logo Capco

Credit Risk BA

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

The Aerospace Corporation Logo The Aerospace Corporation

Information Technology Engineer

Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Remote or Hybrid
India
4600 Employees

Similar Companies Hiring

Fortune Brands Innovations Thumbnail
Manufacturing
Deerfield, IL
10000 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account