Senior Security Engineer – Vulnerability Management
Position Overview
We are seeking a highly skilled and forward-thinking Senior Security Engineer to join Flipkart Infosec team and lead Vulnerability Management program. In this role, the candidate will be responsible for the end-to-end lifecycle of vulnerability discovery, configuration assessment, prioritization, and remediation governance.
The ideal candidate possesses 5+ years of dedicated experience in Vulnerability Assessment (VA) and remediation governance, alongside deep technical expertise in managing enterprise-grade VA tools. Beyond traditional VM, we will leverage development skills for automation and AI-based vulnerability and patch management technologies to scale and modernize our security posture. The candidate should also champion secure configuration standards across endpoint and network environments to ensure robust compliance.
Key Responsibilities
Program & Remediation Governance
- Vulnerability Assessment: Proactive identification of security weaknesses across an organization's digital assets like network infrastructure (routers, switches, firewalls etc.,) , Cloud ecosystem and the compute infrastructure (servers, virtual machines, endpoints, applications.
- Drive Remediation: Lead governance efforts to ensure vulnerabilities are remediated within established SLAs.
- Stakeholder Collaboration: Partner with IT operations and business unit owners to track, validate, and oversee patch management and mitigation efforts.
- Risk Contextualization: Analyze vulnerability data to assess actual business risk, providing technical teams with actionable prioritization guidance beyond standard CVSS scores.
- Reporting & Metrics: Design and deliver comprehensive vulnerability dashboards and compliance reports for both technical teams and senior leadership.
- Attack Surface & Exposure Management: Leverage External Attack Surface Management (EASM) tools to identify internet-facing shadow IT assets and bring them under managed assessment scopes.
- Crisis Response: Lead the technical discovery and exposure assessment during high-profile zero-day events, providing rapid blast-radius reports to senior leadership and Incident Response teams.
VA Tool Management & Automation
- Tool Ownership: Oversee the deployment, configuration, tuning, and maintenance of enterprise Vulnerability Assessment tools (e.g., Tenable/Nessus, Manage Engine, Qualys, Rapid7).
- Automation & Development: Develop custom scripts and automation workflows (using Python, PowerShell, Bash, or APIs) to streamline scan scheduling, data extraction, ticketing, and reporting.
- Next-Gen Tech Implementation: Leverage and manage AI-based vulnerability assessment and predictive patch management tools to automate risk scoring, predict exploitability, and streamline patching workflows.
Configuration Assessment & Compliance
- Secure Baselines: Establish, define, and maintain secure configuration baselines for endpoints (Windows, macOS, Linux) and network devices (routers, switches, firewalls) based on industry frameworks.
- Compliance Auditing: Conduct continuous configuration drift and compliance assessments utilizing frameworks like CIS, NIST, ISO standards
- Governance & Enforcement: Identify misconfigurations, define remediation best practices, and work with infrastructure teams to ensure alignment with security policies.
Qualifications & Experience
Required:
- Experience:7+ years of hands-on experience in Cybersecurity, specifically focused on Vulnerability Assessment (VA) and Remediation Governance.
- Tool Expertise: Proven track record of managing enterprise-scale vulnerability scanning platforms (e.g., Qualys, Tenable, Manage Engine, Rapid7).
- Automation & Development: Practical experience in development/scripting activities (Python, PowerShell, Bash, Rest APIs) aimed at security automation.
- AI-Driven Security: Direct, hands-on experience utilizingAI/Machine Learning-based VA platforms and autonomous/predictive patch management solutions.
- Configuration Assessment: Proven experience assessing configurations for endpoints and network devices against CIS Benchmarks, NIST, or equivalent frameworks.
- Technical Knowledge: Deep understanding of operating system security, network architecture, and cloud security environments.
- Risk-Based Prioritization: Strong understanding of Risk-Based Vulnerability Management (RBVM), utilizing frameworks like EPSS and CISA KEV to prioritize remediation based on active threat intelligence rather than just CVSS scores.
- Container & Cloud VM: Experience managing vulnerabilities within modern architectures, including Docker, Kubernetes, and serverless environments.
- Team Leadership & Mentorship: Act as the technical lead for the Vulnerability Management function, mentoring junior engineers, conducting knowledge-sharing sessions, and fostering a culture of continuous learning.
- Communication: Exceptional soft skills, with the ability to translate complex technical vulnerabilities into clear business risks for both junior staff and senior executives.
Preferred / Value Added:
- Certifications: Relevant industry certifications are highly desirable:
- Vendor-Specific: Qualys Certified Specialist, Tenable Certified Engineer, or Rapid7 Certified Administrator.
- General Security: CISSP, CISM, CEH, GCIH, or GEVA (GIAC Enterprise Vulnerability Assessor).