Security Vulnerability Remediation Analyst
2 weeks ago
Job Details:
Job Title: Security Vulnerability Remediation Analyst
Duration: Contract (On the Payroll of Datum Technology Group)
Location: Chennai || Mumbai || Gurugram
Interview Process: Virtual (2 Rounds) + 1 Technical screening.
Job Description:
Key Responsibilities
Vulnerability Triage:
- Review findings from scanning tools (Burp Suite, ZAP, Mend, Snyk, JFrog XRay, Wiz, Qualys).
- Validate severity and exploitability, prioritising overdue medium vulnerabilities. Confirm whether the finding is a true positive or false positive.
False Positive Handling:
- Document justification for false positives (e.g., scan logs, GitHub issue link).
- Submit exception requests via approved workflows:
- GitHub Exception Templates for Mend, Snyk, Xray email the security team for unresolved cases route Wiz false positives to the Security Platforms team for backend review.
Remediation Coordination:
- For confirmed vulnerabilities, create a Jira ticket in the correct team backlog.
- Include vulnerability alert details, scanning source reference, and recommended remediation steps.
- Link the Jira ticket to the original vulnerability alert for traceability.
- Following sufficient progress is made triaging vulnerabilities, proceed to fix those that require a development change.
Reporting & Governance:
- Maintain accurate records of triage decisions and false positive justifications.
- Provide weekly updates on backlog reduction progress.
- Ensure compliance with Risk Vulnerability Management Standards.
Required Skills & Experience
- Strong understanding of application security principles and vulnerability types.
- Experience developing web applications, preferably in a PHP / MySQL environment.
- Hands-on experience with DAST, SAST, SCA, CSPM, and infrastructure scanning tools.
- Familiarity with Jira and GitHub workflows for issue tracking and exception handling.
- Ability to analyse scan results and differentiate between true positives and false positives.
- Excellent communication skills for cross-team collaboration.
Performance Metrics
- Reduction of medium vulnerabilities
- Timely triage and accurate classification of findings.
- Compliance with InfoSec standards and exception approval processes.
-
Threat & Vulnerability Management
3 weeks ago
Gurugram, Haryana, India, IN Genpact Full timeThreat & Vulnerability ManagementExperience: 10-15 yearsLocation: (Delhi/NCR, Hyderabad, Bangalore)About the Role:This role seeks a technically skilled leader with hands-on experience in tools like Qualys and Tenable, strong IT infrastructure knowledge, and the ability to drive cross-functional collaboration for effective risk reduction across a large...
-
Cyber Security Analyst
3 weeks ago
india, IN DraconX Full timeCompany Description DraconX is at the forefront of transforming cutting-edge ideas into intelligent, scalable digital solutions. As pioneers in AI business automation and AI-driven SaaS platforms, we specialize in creating MVPs, custom software, and automation systems that fuel growth and innovation for startups and enterprises. By leveraging AI, data...
-
Remedy Developer
3 weeks ago
Gurugram, Haryana, India, IN Input Zero Technologies Full time•BMC Remedy Expertise: You must have a minimum of 3 years' hands-on experience in BMC Remedy, including development, implementation, configuration, and upgrades. •Integration Skills: Strong knowledge and practical experience in integrating Remedy with external systems through web services and REST APIs. •Patch and Upgrade Proficiency: Ability to...
-
Application Security Engineer
1 day ago
india, IN KPG99 INC Full timeRole: Application Security Engineer Skills Required:• At lease 3 years of Application Security Experience• Experience with SAST, SCA, DAST• Experience with Python, C#, or Javascript• Experience security testing for Web Applications Application Security Engineer (Analyst?) - Job DescriptionAs the Application Security Engineer (Analyst) at the...
-
Application Security Engineer
1 day ago
Gurugram, Haryana, India, IN Unicommerce Full timeRole:As an Application Security Engineer, you will play a pivotal role in establishing and spearheading our company's appsec program, ensuring the security of our products and services. You will be responsible for conducting comprehensive security assessments, identifying and remediating vulnerabilities, and collaborating with our product and tech teams to...
-
Cloud Security and DevOps Engineer
3 weeks ago
india, IN Recfront Full timeCloud Security and DevOps Engineer (GCP + AI-Driven) Location: India (Remote)Availability: 0-15 days / ImmediateTimings: EST Timezone (7PM to 4AM IST)About our client:Our client is redefining hormone health by blending clinical expertise, data-driven innovation, and a fully integrated digital platform. They empower patients and practitioners with...
-
Cyber Security Engineer
3 weeks ago
india, IN CareerUS Solutions Full timeCyber Security Engineer – Job DescriptionPosition SummaryThe Cyber Security Engineer is responsible for designing, implementing, and maintaining security systems to protect the organization’s computer networks, applications, and data. This role involves identifying vulnerabilities, responding to incidents, and ensuring compliance with security best...
-
Application Security Engineer
1 day ago
india, IN KPG99 INC Full timeJob Title: Application Security EngineerLocation: Remote (Offshore)Contract Type: ContractJob DescriptionSkills Required: • At lease 3 years of Application Security Experience• Experience with SAST, SCA, DAST• Experience with Python, C#, or Javascript• Experience security testing for Web ApplicationsAs the Application Security Engineer (Analyst) at...
-
Senior Security Analyst
3 weeks ago
Gurugram, Haryana, India, IN GMG Full timeWhat we do:GMG is a global well-being company retailing, distributing and manufacturing a portfolio of leading international and home-grown brands across sport, everyday goods, health and beauty, properties and logistics sectors. Under the ownership and management of the Baker family for over 45 years, GMG is a valued partner of choice for the world's most...
-
Security Engineer
2 weeks ago
Bhubaneswar, Odisha, India, IN Jio Platforms Limited Full timeSecurity Engineer (L2) : System Compliance and Identity & Access ManagementJob Role Position: Security Engineer (L2) : System Compliance and Identity & Access ManagementWork Location: BhubaneswarEducational Qualification: Bachelor’s degree in Engineering or equivalentWork Experience: 5 +Years Certification: Azure Security certification / GCP Security...