Job Description: Vulnerability Management
Role Overview
We are seeking a highly skilled Vulnerability Management Specialist responsible for driving end-to-end vulnerability lifecycle management, patch compliance, and security posture optimization. The role requires strong expertise in Qualys, remediation governance, and coordination with cross-functional teams to ensure proactive risk mitigation aligned with enterprise security standards.
Key Responsibilities
1. Vulnerability Management & Scanning
- Manage Qualys agent deployment and lifecycle in collaboration with the IT Asset Management (ITAM) team
- Conduct and govern scheduled vulnerability scans:
- Weekly internal scans
- Monthly external scans
- Ensure scan coverage, accuracy, and alignment with organizational policies
2. Remediation Governance & Execution
- Drive wave-based remediation pipeline, including:
- Planning and prioritization
- Validation in test environments
- Defined acceptance criteria before production rollout
- Lead criticality-based remediation strategy:
- Prioritize Critical → High → Medium vulnerabilities
- Conduct post-remediation validation through Qualys re-scanning
3. Risk & Exception Management
- Manage exceptions and compensating controls with proper documentation and approvals
- Coordinate risk acceptance processes with stakeholders and security leadership
- Ensure audit readiness and compliance with internal and regulatory standards
4. Patch & Compliance Monitoring
- Track and enforce patch compliance across systems
- Publish monthly security posture and compliance reports to the CISO office
- Identify trends, gaps, and improvement areas in patching and vulnerability closure
5. System Hardening & Security Improvements
- Drive hardening initiatives for system images and configurations
- Support manual remediation and configuration-fix workflows where automation is not feasible
- Collaborate with engineering teams to institutionalize secure baselines
6. Segmentation & Security Posture Management
- Implement and manage asset segmentation (Red / Yellow / Green classification)
- Enable lab manager and environment-level security controls
- Establish and maintain audit cadence for continuous improvement
Required Skills & Qualifications
- Strong hands-on experience with Qualys Vulnerability Management platform
- Deep understanding of vulnerability lifecycle management and remediation frameworks
- Experience with patch management, OS hardening, and security configurations
- Knowledge of risk management, exception handling, and compliance reporting
- Familiarity with enterprise IT infrastructure (servers, networks, endpoints)
Preferred Qualifications
- Certifications such as CISSP, CEH, CompTIA Security+, or equivalent
- Experience working with CISO office or security governance teams
- Exposure to audit frameworks (ISO 27001, NIST, CIS benchmarks)
Key Competencies
- Strong analytical and problem-solving ability
- Stakeholder management and cross-functional coordination
- Structured and process-oriented mindset
- Ability to drive execution under tight timelines
Responsibilities
Key Responsibilities
1. Vulnerability Management & Scanning
- Manage Qualys agent deployment and lifecycle in collaboration with the IT Asset Management (ITAM) team
- Conduct and govern scheduled vulnerability scans:
- Weekly internal scans
- Monthly external scans
- Ensure scan coverage, accuracy, and alignment with organizational policies
2. Remediation Governance & Execution
- Drive wave-based remediation pipeline, including:
- Planning and prioritization
- Validation in test environments
- Defined acceptance criteria before production rollout
- Lead criticality-based remediation strategy:
- Prioritize Critical → High → Medium vulnerabilities
- Conduct post-remediation validation through Qualys re-scanning
3. Risk & Exception Management
- Manage exceptions and compensating controls with proper documentation and approvals
- Coordinate risk acceptance processes with stakeholders and security leadership
- Ensure audit readiness and compliance with internal and regulatory standards
4. Patch & Compliance Monitoring
- Track and enforce patch compliance across systems
- Publish monthly security posture and compliance reports to the CISO office
- Identify trends, gaps, and improvement areas in patching and vulnerability closure
5. System Hardening & Security Improvements
- Drive hardening initiatives for system images and configurations
- Support manual remediation and configuration-fix workflows where automation is not feasible
- Collaborate with engineering teams to institutionalize secure baselines
6. Segmentation & Security Posture Management
- Implement and manage asset segmentation (Red / Yellow / Green classification)
- Enable lab manager and environment-level security controls
- Establish and maintain audit cadence for continuous improvement
Required Skills & Qualifications
- Strong hands-on experience with Qualys Vulnerability Management platform
- Deep understanding of vulnerability lifecycle management and remediation frameworks
- Experience with patch management, OS hardening, and security configurations
Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. Explore Life at Zensar and join us to Grow. Own. Achieve. Learn. to be the best version of yourself.
We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.
Skills Required
- Hands-on experience with Qualys Vulnerability Management platform
- Manage Qualys agent deployment and lifecycle in collaboration with ITAM
- Deep understanding of vulnerability lifecycle management and remediation frameworks
- Experience with patch management, OS hardening, and security configurations
- Knowledge of risk management, exception handling, and compliance reporting
- Familiarity with enterprise IT infrastructure (servers, networks, endpoints)
- Certifications such as CISSP, CEH, CompTIA Security+ or equivalent
- Experience working with CISO office or security governance teams
- Exposure to audit frameworks (ISO 27001, NIST, CIS benchmarks)
Zensar Technologies Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Zensar Technologies and has not been reviewed or approved by Zensar Technologies.
-
Retirement Support — A 401(k) with company match and immediate vesting is highlighted, with broad fund options available.
-
Wellbeing & Lifestyle Benefits — Work-life balance, remote/hybrid flexibility, and supportive teams are emphasized as strengths that enhance the overall experience.
-
Parental & Family Support — Inclusive policies such as parental leave and access to EAP and dependent medical coverage are promoted across regions.
Zensar Technologies Insights
What We Do
Zensar is a leading experience, engineering, and technology solutions company. We conceptualize, build, and manage digital products for Forbes Global 2000 clients across the hi-tech engineering, banking and financial services, insurance, manufacturing and consumer services verticals. With proven excellence across five core areas, including experience services, advanced engineering services, data engineering and analytics, foundation services, and application services, our solutions leverage industry-leading platforms to help our clients be competitive, agile, and disruptive while moving with velocity through change and opportunity. Zensar’s expansive ecosystem of 60+ technology partners, including Oracle, Salesforce, SAP, Guidewire, Automation Anywhere, Adobe, and UiPath, enables us to deliver comprehensive solutions to clients, facilitating seamless integration and allowing them to leverage cutting-edge technologies and tools for enhanced business outcomes. Zensar is part of the USD 4.4 billion RPG Group. With headquarters in Pune, India, our 10,500+ employees, representing over 50 nationalities, work from 30+ locations across North America, UK/Europe, and South Africa. Visit us at www.zensar.com









