
Expert: Cybersecurity, Vulnerability Operations Center
1 day ago
Key Job Responsibilities:
VOC - VI (Vulnerability Intelligence), ASM (Attack Surface Management) & VM (Vulnerability Management) Expert.
Environment / Context
Saint Gobain, world leader in the habitat and construction market, is one of the top 100 global industrial groups. Saint-Gobain is present in 68 countries with employees. They design, manufacture and distribute materials and solutions which are key ingredients in the wellbeing of each of us and the future of all. They can be found everywhere in our living places and our daily life: in buildings, transportation, infrastructure and in many industrial applications. They provide comfort, performance and safety while addressing the challenges of sustainable construction, resource efficiency and climate change
Saint-Gobain GDI Grou
p (250 persons at the head office, including 120 that are internal) is responsible for defining, setting up and managing the Group's Information Systems (IS) and Telecom policy with its 1,000 subsidiaries in 6,500 sites worldwide. The GDI Groupe also carries the common means (infrastructures, telecoms, digital platforms, cross-functional applications
).
IN
DEC, the IT Development Centre of Saint-Gobain, is an entity with a vision to leverage India's technical skills in the Information Technology domain to provide timely, high-quality and cost-effective IT solutions to Saint-Gobain businesses globally.Within the Cybersecurity Department, t
he Cybersecurity Vulnerability Operations Cent
er mission is to Identify, assess and confirm vulnerability and threats that can affect the Group. The CyberVOC teams are based out of Paris and Mumbai and consist of skilled persons working in different Service Lines.
Mission
We are seeking a highly experienced cybersecurity professional to serve as an VOC Expert supporting the Vulnerability Intelligence (VI), Attack Surface Management (ASM), and Vulnerability Management (VM) teams. This role is pivotal in shaping the strategy, defining technical approaches, and supporting day-to-day operations—particularly complex escalations and automation efforts.
The ideal candidate will combine technical mastery in offensive security with practical experience in vulnerability lifecycle management and external attack surface discovery. The expert will act as a senior advisor and technical authority for the analyst teams, while also contributing to the design, scripting, and documentation of scalable security proceess.
The VOC Expert is responsible for:
- Vulnerability Intelligence (VI)
- Drive the qualification and risk analysis of newly disclosed vulnerabilities.
- Perform exploit PoC validation when needed to assess practical risk.
- Maintain and enhance the central VI database, enriched with (EPSS, CVSS, QVS, SG-specific scoring models, and EUVD)
Define and automate workflows for:
- Vulnerability qualification, exposure analysis, and prioritization
- Ingestion of qualified vulnerability data into the enterprise Data Lake
- Collaborate on documentation of VI methodology and threat intelligence integration
- Support proactive communication of high/critical vulnerabilities to asset and application owners
Attack Surface Management (ASM):
- Operate and enhance external asset discovery and continuous monitoring using ASM tools
- Integrate asset coverage data from CMDB, and other internal datasets
Design and implement scripts for:
- WHOIS/ASN/banner correlation Data enrichment and alert filtering
- Deploy and maintain custom scanning capabilities (e.g., Nuclei integrations)
- Provide expert input on threat modeling based on exposed assets and external footprint
BlackBox Pentesting:
- Maintain the service delivery of the BlackBox Pentesting platform
- Automate the export of pentest data and integrate into Data Lake and Power BI dashboards
- Define and document onboarding workflows for new applications
- Actively guide analysts in prioritizing pentest requests and validating results.
Vulnerability Management:
- Vulnerability review, recategorization, and false positive identification
- Proactive vulnerability testing and replay
- Pre-analyze and consolidate vulnerability data from various scanning tools
- Prepare concise syntheses of available vulnerabilities
- Offer guidance to the SO and CISO on vulnerabilities
- Collaborate with key stakeholders to develop strategies for vulnerability management
- Assist in defining vulnerability management KPIs and strategic goals
- Prepare concise, actionable summaries for high-risk vulnerabilities and trends
Automate testing actions:
- Develop scripts and tooling to automate repetitive and complex tasks across VI, ASM
and VM. Implement data pipelines to sync outputs from ASM/VI tools to dashboards and reporting
engines. Design streamlined workflows for vulnerability lifecycle—from detection to
closure. Collaborate with both offensive and defensive teams to support App managers and Asset managers in remediating vulnerabilities and issues.
Skills and Qualifications:
- Bachelor's degree in Computer Science, Information Security, EXTC or related field; relevant certifications (e.g., CISSP, CCSP, CompTIA Security+) are a plus
- Proven experience (10+ years) working within the Cybersecurity field, with a focus on offensive security, vulnerability intelligence and attack surface analysis.
- Proven experience on Penetration testing actions (web application, infrastructure, …)
- Proven expertise in: CVE analysis, exploit development/validationExternal asset discovery & mapping
Threat modeling and prioritizationAdvanced knowledge of tooling such as:
- ASM platforms Nuclei, Shodan, Open Source CTI, vulnerability scanners (Qualys, Tenable, …)
- Pentester tools (Burp, SQLmap, Responder, IDA and Kali environment)
- Experience in investigating newly published vulnerabilities, assessing their risks, severity.
- Strong scripting languages (e.g., Python, Bash, Powershell, C#, …) for automation and customization
- Experience with Pentester tools (Burp, SQLmap and Kali environment)
- Strong technical skills with an interest in open-source intelligence investigations
- Experience building dashboards in Power BI or similar tools.
- Familiarity with data lakes, API integrations, and ETL processes.
- Knowledge of NIST CVE database, OWASP Top 10, Microsoft security bulletins
- Excellent writing skills in English and ability to communicate complicate technical challenges in a business language to a range of stakeholders.
Personal Skills:
- Has a systematic, disciplined, and analytical approach to problem solving with Thorough leadership skills & experience
- Excellent ability to think critically underpressure
- Strong communication skills to convey technical concepts clearly to both technical and non-technical stakeholders
- Willingness to stay updated with evolving cyber threats, technologies, and industry trends
- Capacity to work collaboratively with cross-functional teams, developers, and management to implement robust security measures
Additional Information:
- The position is based in Mumbai (India)
-
Cybersecurity Expert
7 hours ago
Navi Mumbai, Maharashtra, India beBeePenetration Full time ₹ 6,00,000 - ₹ 10,00,000Cybersecurity Expert JobJob Description:We are seeking a highly motivated and technically skilled Cybersecurity Expert to join our cybersecurity team.The ideal candidate should have hands-on experience in Vulnerability Assessment and Penetration Testing (VA/PT) across web applications, infrastructure, and cloud platforms.Network & Infrastructure Security...
-
Mumbai, Maharashtra, India beBeeCybersecurity Full time ₹ 1,50,00,000 - ₹ 2,50,00,000About UsWe are looking for an experienced Security Operations Center Analyst to join our cybersecurity team.
-
Cyber Security Specialist
2 days ago
Mumbai, Maharashtra, India beBeeVulnerability Full time ₹ 2,00,00,000 - ₹ 2,50,00,000Job Overview:This role requires a deep understanding of software security and operating systems. You will be responsible for ensuring the safety and integrity of our products by identifying and mitigating vulnerabilities.The ideal candidate will have experience with threat modeling, risk assessment, and regulatory submissions. Additionally, they should be...
-
Chief Vulnerability Intelligence Specialist
6 days ago
Mumbai, Maharashtra, India beBeeCybersecurity Full time ₹ 9,00,000 - ₹ 12,00,000Our organization is seeking a seasoned Vulnerability Intelligence and Attack Surface Management (ASM) expert to enhance its cybersecurity posture. This critical role involves identifying vulnerabilities, monitoring attack surfaces, and driving remediation efforts.The ideal candidate will possess a strong understanding of vulnerability intelligence, ASM...
-
Cyber Security Consultant
1 day ago
Mumbai, Maharashtra, India DarkNext Cybersecurity Full time US$ 90,000 - US$ 1,20,000 per yearCompany DescriptionDarkNext Cybersecurity is an enterprise-focused cybersecurity company based in Mumbai, India. We specialize in Application Security Audits, Vulnerability and Penetration Testing, Wireless Security, Information Security Reviews, and more. Our team is dedicated to helping clients achieve business success through Performance, Persistence, and...
-
Cybersecurity Specialist
2 days ago
Mumbai, Maharashtra, India beBeecybersecurity Full time ₹ 9,00,000 - ₹ 12,00,000Cybersecurity Expert WantedWe're looking for an experienced cybersecurity professional to join our team. The ideal candidate will have a strong background in threat intelligence, vulnerability management, and incident response.
-
Mumbai, Maharashtra, India beBeeCybersecurity Full time ₹ 1,39,00,000 - ₹ 2,09,00,000Job Title:A Cybersecurity Professional Leading Vulnerability Management and Risk ComplianceResponsibilities:Develop and implement a comprehensive vulnerability management lifecycle to mitigate risks.Design and execute vulnerability scans, risk-based prioritization, and remediation strategies using industry-leading tools.Provide executive-level reporting on...
-
Urgent: Vulnerability Intelligence Threat
6 days ago
Mumbai, Maharashtra, India Talentmatics Full timeWe are looking for a highly skilled Vulnerability Intelligence & ASM Analyst to join our Cybersecurity team. This role is critical in strengthening our security posture by identifying vulnerabilities, monitoring attack surfaces, and driving remediation efforts. You will play a key role in Vulnerability Intelligence, Attack Surface Management, Penetration...
-
Vulnerability Analysis Expert
5 days ago
Mumbai, Maharashtra, India beBeevulnerability Full time ₹ 1,04,000 - ₹ 1,30,878Job Description:As a skilled Vulnerability Analysis Expert, you will play a pivotal role in safeguarding our organization's digital assets. This challenging position demands expertise in vulnerability assessment tools, penetration testing, and remediation coordination.
-
Vulnerability Management Specialist
6 days ago
Mumbai, Maharashtra, India beBeeCybersecurity Full time ₹ 15,00,000 - ₹ 20,00,000Job OverviewSeeking a seasoned Vulnerability Assessor to spearhead our cybersecurity efforts. This role entails identifying and mitigating potential vulnerabilities in our systems.Key Responsibilities:Expertise in security tools, including Wallix Bastion, Microsoft PKI, Qualys Vulnerability Scanner, and Qualys Cloud Agent is required.Maintaining a strong...