Security Vulnerability Remediation Analyst

2 weeks ago


india, IN Datum Technologies Group Full time

Job Details:

Job Title: Security Vulnerability Remediation Analyst

Duration: Contract (On the Payroll of Datum Technology Group)

Location: Chennai || Mumbai || Gurugram

Interview Process: Virtual (2 Rounds) + 1 Technical screening.


Job Description:


Key Responsibilities

Vulnerability Triage:

  • Review findings from scanning tools (Burp Suite, ZAP, Mend, Snyk, JFrog XRay, Wiz, Qualys).
  • Validate severity and exploitability, prioritising overdue medium vulnerabilities. Confirm whether the finding is a true positive or false positive.


False Positive Handling:

  • Document justification for false positives (e.g., scan logs, GitHub issue link).
  • Submit exception requests via approved workflows:
  • GitHub Exception Templates for Mend, Snyk, Xray email the security team for unresolved cases route Wiz false positives to the Security Platforms team for backend review.


Remediation Coordination:

  • For confirmed vulnerabilities, create a Jira ticket in the correct team backlog.
  • Include vulnerability alert details, scanning source reference, and recommended remediation steps.
  • Link the Jira ticket to the original vulnerability alert for traceability.
  • Following sufficient progress is made triaging vulnerabilities, proceed to fix those that require a development change.


Reporting & Governance:

  • Maintain accurate records of triage decisions and false positive justifications.
  • Provide weekly updates on backlog reduction progress.
  • Ensure compliance with Risk Vulnerability Management Standards.


Required Skills & Experience

  • Strong understanding of application security principles and vulnerability types.
  • Experience developing web applications, preferably in a PHP / MySQL environment.
  • Hands-on experience with DAST, SAST, SCA, CSPM, and infrastructure scanning tools.
  • Familiarity with Jira and GitHub workflows for issue tracking and exception handling.
  • Ability to analyse scan results and differentiate between true positives and false positives.
  • Excellent communication skills for cross-team collaboration.


Performance Metrics

  • Reduction of medium vulnerabilities
  • Timely triage and accurate classification of findings.
  • Compliance with InfoSec standards and exception approval processes.



  • Gurugram, Haryana, India, IN Genpact Full time

    Threat & Vulnerability ManagementExperience: 10-15 yearsLocation: (Delhi/NCR, Hyderabad, Bangalore)About the Role:This role seeks a technically skilled leader with hands-on experience in tools like Qualys and Tenable, strong IT infrastructure knowledge, and the ability to drive cross-functional collaboration for effective risk reduction across a large...


  • india, IN DraconX Full time

    Company Description DraconX is at the forefront of transforming cutting-edge ideas into intelligent, scalable digital solutions. As pioneers in AI business automation and AI-driven SaaS platforms, we specialize in creating MVPs, custom software, and automation systems that fuel growth and innovation for startups and enterprises. By leveraging AI, data...

  • Remedy Developer

    3 weeks ago


    Gurugram, Haryana, India, IN Input Zero Technologies Full time

    •BMC Remedy Expertise: You must have a minimum of 3 years' hands-on experience in BMC Remedy, including development, implementation, configuration, and upgrades. •Integration Skills: Strong knowledge and practical experience in integrating Remedy with external systems through web services and REST APIs. •Patch and Upgrade Proficiency: Ability to...


  • india, IN KPG99 INC Full time

    Role: Application Security Engineer Skills Required:• At lease 3 years of Application Security Experience• Experience with SAST, SCA, DAST• Experience with Python, C#, or Javascript• Experience security testing for Web Applications Application Security Engineer (Analyst?) - Job DescriptionAs the Application Security Engineer (Analyst) at the...


  • Gurugram, Haryana, India, IN Unicommerce Full time

    Role:As an Application Security Engineer, you will play a pivotal role in establishing and spearheading our company's appsec program, ensuring the security of our products and services. You will be responsible for conducting comprehensive security assessments, identifying and remediating vulnerabilities, and collaborating with our product and tech teams to...


  • india, IN Recfront Full time

    Cloud Security and DevOps Engineer (GCP + AI-Driven) Location: India (Remote)Availability: 0-15 days / ImmediateTimings: EST Timezone (7PM to 4AM IST)About our client:Our client is redefining hormone health by blending clinical expertise, data-driven innovation, and a fully integrated digital platform. They empower patients and practitioners with...


  • india, IN CareerUS Solutions Full time

    Cyber Security Engineer – Job DescriptionPosition SummaryThe Cyber Security Engineer is responsible for designing, implementing, and maintaining security systems to protect the organization’s computer networks, applications, and data. This role involves identifying vulnerabilities, responding to incidents, and ensuring compliance with security best...


  • india, IN KPG99 INC Full time

    Job Title: Application Security EngineerLocation: Remote (Offshore)Contract Type: ContractJob DescriptionSkills Required: • At lease 3 years of Application Security Experience• Experience with SAST, SCA, DAST• Experience with Python, C#, or Javascript• Experience security testing for Web ApplicationsAs the Application Security Engineer (Analyst) at...


  • Gurugram, Haryana, India, IN GMG Full time

    What we do:GMG is a global well-being company retailing, distributing and manufacturing a portfolio of leading international and home-grown brands across sport, everyday goods, health and beauty, properties and logistics sectors. Under the ownership and management of the Baker family for over 45 years, GMG is a valued partner of choice for the world's most...

  • Security Engineer

    2 weeks ago


    Bhubaneswar, Odisha, India, IN Jio Platforms Limited Full time

    Security Engineer (L2) : System Compliance and Identity & Access ManagementJob Role Position: Security Engineer (L2) : System Compliance and Identity & Access ManagementWork Location: BhubaneswarEducational Qualification: Bachelor’s degree in Engineering or equivalentWork Experience: 5 +Years Certification: Azure Security certification / GCP Security...