Key Responsibilities
Vulnerability Response Management
• Assume operational ownership of notable vulnerabilities following VA assessment and prioritisation.
• Drive end-to-end response activities for zero-day, out-of-band (OOB), actively exploited, and other high-profile vulnerabilities.
• Coordinate cross-functional stakeholders to execute mitigation and remediation activities.
• Establish and lead vulnerability response bridges, action tracking, and escalation activities.
• Drive execution of vulnerability response playbooks and response procedures
• Maintain continuous oversight of vulnerability response activities until risk mitigation or remediation is completed.
Incident Management & Stakeholder Coordination
• Leverage Incident Management processes to accelerate remediation and stakeholder mobilisation.
• Coordinate Cyber Defence, Platform Teams, Asset Owners, Technology SMEs, and Incident Management teams during vulnerability events.
• Drive stakeholder communications, executive updates, situation reporting, and escalation activities.
• Escalate critical risks, blockers, and delayed remediation activities through appropriate governance channels.
• Support post-incident reviews and continuous improvement initiatives.
Remediation Oversight
• Drive remediation activities through to closure, ensuring accountability and timely execution.
• Track remediation commitments, milestones, dependencies, and residual risks.
• Challenge and escalate overdue actions where required.
• Validate completion of agreed mitigation and remediation actions.
• Support management reporting on remediation progress and risk reduction outcomes.
24x7 Vulnerability Response Coverage
• Participate in on-call, weekend, after-hours, and follow-the-sun support arrangements.
• Provide operational coordination during high-severity vulnerability events outside standard business hours.
• Support continuous vulnerability response coverage for critical cyber threats.
• Ensure timely stakeholder mobilisation during active exploitation and major vulnerability incidents.
Key Skills & Experience
Vulnerability Management
• Strong understanding of vulnerability management concepts, CVE, CVSS, exploitability assessment, threat intelligence, and cyber risk management.
• Ability to understand vulnerability assessments and translate risk into actionable remediation plans.
• Knowledge of vulnerability prioritisation, attack surface exposure, and threat landscape trends.
Incident & Crisis Management
• Experience coordinating Major Incident, Cyber Incident, or Technology Incident response activities.
• Strong understanding of escalation management, crisis communications, and stakeholder coordination.
• Experience leading bridge calls, action tracking, executive reporting, and operational response activities
Remediation Governance & Oversight
• Experience driving remediation activities across multiple technology and infrastructure teams.
• Understanding of remediation governance, risk reduction strategies, compensating controls, and risk treatment plans.
• Ability to influence stakeholders and drive accountability for remediation outcomes.
Professional Competencies
• Strong problem-solving skills with the ability to analyse complex cyber risk scenarios, identify response strategies, and drive issues to resolution.
• Excellent communication and stakeholder management skills with the ability to engage technical teams,
senior management, and incident stakeholders during high-pressure situations.
• Strong analytical capability with experience interpreting and correlating large volumes of vulnerability, threat intelligence, asset inventory, remediation, and operational data to support risk-based decision making.
• Ability to translate technical vulnerability information into clear business risk, operational impact, and remediation priorities.
• Up-to-date knowledge of vulnerability management practices, emerging threats, vulnerability intelligence, exploit trends, and cyber threat landscape developments.
• Self-driven, proactive, and capable of operating independently within a fast-paced 24x7 response
environment.
• Strong execution focus with the ability to coordinate multiple stakeholders and drive timely remediation outcomes.
• Ability to remain calm under pressure and make sound decisions during critical cyber events.
• Comfortable working in ambiguous situations and making risk-based decisions with incomplete
information.
• Highly collaborative with a strong sense of ownership and accountability.
Preferred Experience
• 5–8 years of experience in Vulnerability Management, Security Operations, Incident Response,
Technology Risk, Cyber Defence, or related cyber security disciplines.
• Experience supporting 24x7 security operations, on-call rotations, or major incident management
activities.
• Experience managing critical cyber incidents, zero-day vulnerabilities, and actively exploited threats.
• Experience working within a highly regulated environment such as financial services.
Skills Required
- Strong understanding of vulnerability management concepts, CVE, CVSS, exploitability assessment, and cyber risk management
- Ability to translate vulnerability assessments into actionable remediation plans
- Knowledge of vulnerability prioritisation, attack surface exposure, and threat landscape trends
- Experience coordinating Major Incident, Cyber Incident, or Technology Incident response activities
- Experience leading bridge calls, action tracking, executive reporting, and operational response activities
- Experience driving remediation across multiple technology and infrastructure teams with governance oversight
- Understanding of remediation governance, risk reduction strategies, compensating controls, and risk treatment plans
- Strong stakeholder management and communication skills for engaging technical teams and senior management during incidents
- Ability to analyse complex cyber risk, correlate vulnerability and threat data, and make risk-based decisions
- Capability to operate in a 24x7 response environment including on-call, weekend, and after-hours support
- 5-8 years of experience in Vulnerability Management, Security Operations, Incident Response, Technology Risk, or related discipline
- Experience managing zero-day vulnerabilities, actively exploited threats, and critical cyber incidents
- Experience supporting 24x7 security operations, on-call rotations, or major incident management activities
- Experience working within a highly regulated environment (e.g., financial services)
What We Do
Two95 International Inc., is a global technology firm specializing in enterprise solutions that evolves over BPM, Mobility, Cloud, Analytics, E-commerce & Social Business. Our client base includes several Fortune 500 and mid-market companies across industries and varying geographies. With vast knowledge and knowhow of 20 years in the IT field, we have been chosen as INC500 fastest growing company in North America in 2013. With the accolade of being ranked 11th in Human Resources by INC500, we have also been nominated as the 3rd fastest growing company in South Jersey by SJBM. We are ranked among the Top 20 IT Companies in New Jersey based on the year-on-year growth for the last 3 years. With a seasoned team of highly qualified personnel, our offices are located in New Jersey, Canada and India.









