Lead Engineer Vulnerability Management

2 weeks ago


Bengaluru, Karnataka, India MARMON HOLDINGS Full time ₹ 15,00,000 - ₹ 20,00,000 per year

Marmon Technologies India Private Limited

As a part of the global industrial organization Marmon Holdings—which is backed by Berkshire Hathaway— you'll be doing things that matter, leading at every level, and winning a better way. We're committed to making a positive impact on the world, providing you with diverse learning and working opportunities, and fostering a culture where everyone's empowered to be their best.

Designs and develops integrated security system solutions for the enterprise network. Responsible for designing, implementing, and testing firewalls, software, and hardware. Ensures proprietary/confidential data and systems are protected. Provides technical engineering services for the support of integrated security systems and solutions. Conducts network security audits/assessments. Provides technical direction and assistance to application areas as well as operations, coverage, and other technical support areas.

Position Overview-

We are seeking a highly skilled and experienced Vulnerability Management Engineer to lead our security efforts with a focus on integrating security practices seamlessly into our development processes. The ideal candidate will have extensive experience in both security and software development, with a deep understanding of secure coding practices, vulnerability assessments, and mitigating techniques.

Skills and Qualifications:

  • Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or other relevant certifications preferred.

Performing Secure code reviews or hands on experience in secure software development life cycle.

  • Professional Certified of Cloud, AWS, Azure.

  • Experience in (WAF, IAM - Okta, Auth 0, KMS - encryption, OpenSSL, key vault)

  • Knowledge PEN testing, Burp Suite or Metasploit, Kali Linux, Wireshark network packet analysing.

  • Aware of regulatory requirements GDPR, HIPAA


• Bachelor's degree in computer science, Information Security, or a related field.
• 6 - 8 years of experience in application security, software development, or a related field.

  • Proficiency in security testing tools such as SAST, DAST, and vulnerability scanners.

  • In-depth knowledge of secure coding practices, cryptographic protocols, and authentication mechanisms.

  • Familiarity with OWASP top 10 vulnerabilities and best practices for mitigating them.

  • Experience with DevOps, SecOps practices and tools, including CI/CD pipelines and infrastructure as code.

  • Strong communication and interpersonal skills, with the ability to collaborate effectively with cross-functional teams.

Responsibilities:

  1. Lead Security Integration: Drive the implementation of security measures throughout the software development lifecycle, ensuring that security is prioritized at every stage.

  2. SecOps Implementation: Collaborate with development and operations teams to integrate security practices into CI/CD pipelines, automating security testing and deployment processes.

  3. Vulnerability Management: Conduct regular vulnerability assessments using SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) tools, and coordinate remediation efforts with development teams.

  4. Secure Code Review: Ensure all software code, including third-party components, undergo regular code reviews and static analysis to identify and remediate security vulnerabilities. Follow secure coding practices.

  5. Security Architecture: Design and implement secure architecture patterns for applications and systems, considering factors such as encryption, authentication, and access controls.

  6. Threat Modeling: Perform threat modeling exercises to identify potential security risks and develop strategies to mitigate them effectively.

  7. Security Awareness: Educate development teams on secure coding practices, OWASP top 10 vulnerabilities, and emerging security threats to foster a security conscious culture.

  8. Incident Response: Develop and maintain incident response plans and lead investigations and post-incident reviews in the event of security breaches or incidents.

  9. Compliance and Standards: Stay updated on industry regulations and compliance requirements related to application security, ensuring that our systems adhere to relevant standards.

  10. Security Standards Documentation: Documentation of security practice and process during the development lifecycle.

  11. Cloud Security: Implement and manage security controls for cloud-based applications and services, ensuring compliance with cloud security best practices.

Following receipt of a conditional offer of employment, candidates will be required to complete additional job-related screening processes as permitted or required by applicable law .



  • Bengaluru, Karnataka, India Acesoft Labs Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Role & responsibilitiesDescription: Infrastructure Vulnerability Management Engineer:Job Description:3 to 6 years technical expert in c. Extensive experience in managing and mitigating infrastructure vulnerabilities, with a strong background in using Microsoft Defender for Endpoint and ServiceNow tools.Expertise:Good technical understanding of infrastructure...


  • Bengaluru, Karnataka, India ITC Infotech Full time

    Vulnerability Management - L3Location : BangaloreMode : Hybrid- On the portal where vulnerabilities are listed, each vulnerability must be analyzed;- Within each record of each vulnerability, analyze the required fixes and the vendor involved- Contact the vendor to discuss the vulnerability fix (usually the vendor applies the fix in a test environment)- If...


  • Bengaluru, Karnataka, India beBeeVulnerability Full time ₹ 15,00,000 - ₹ 28,00,000

    Job Title:Vulnerability Management SpecialistJob Description:We are seeking a skilled Vulnerability Management Specialist to join our team. In this role, you will be responsible for developing hardening standards and translating them into tool-recognized formats.You will have the opportunity to work with leading vulnerability scanning solutions like Qualys,...


  • Bengaluru, Karnataka, India ITC Infotech Full time

    Vulnerability Management - L3Location : BangaloreMode : HybridOn the portal where vulnerabilities are listed, each vulnerability must be analyzed; Within each record of each vulnerability, analyze the required fixes and the vendor involvedContact the vendor to discuss the vulnerability fix (usually the vendor applies the fix in a test environment)If there is...


  • Bengaluru, Karnataka, India ITC Infotech Full time

    Vulnerability Management - L3 Location : Bangalore Mode : Hybrid On the portal where vulnerabilities are listed, each vulnerability must be analyzed; Within each record of each vulnerability, analyze the required fixes and the vendor involved Contact the vendor to discuss the vulnerability fix (usually the vendor applies the fix in a test...


  • Bengaluru, Karnataka, India ITC Infotech Full time

    Vulnerability Management - L3 Location : Bangalore Mode : Hybrid On the portal where vulnerabilities are listed, each vulnerability must be analyzed; Within each record of each vulnerability, analyze the required fixes and the vendor involved Contact the vendor to discuss the vulnerability fix (usually the vendor applies the fix in a test environment) If...


  • Bengaluru, Karnataka, India Bounteous Full time

    We are seeking a skilled and experienced Vulnerability Management process to join our dynamic team. Location: Bangalore & Pune (Hybrid Model) Experience: 5 - 8 Years NP: Immediate joiners Requirement: Perform Vulnerability assessment & Policy Compliance using leading Vulnerability Scanning solutions like Qualys etc. Perform Vulnerability assessments &...


  • Bengaluru, Karnataka, India Bounteous Full time

    We are seeking a skilled and experienced Vulnerability Management process to join our dynamicteam.Location: Bangalore & Pune (Hybrid Model)Experience: 5 - 8 YearsNP: Immediate joiners Requirement:Perform Vulnerability assessment & Policy Compliance using leading Vulnerability Scanning solutions like Qualys etc.Perform Vulnerability assessments & Policy...


  • Bengaluru, Karnataka, India Bounteous Full time

    We are seeking a skilled and experienced Vulnerability Management process to join our dynamicteam.Location: Bangalore & Pune (Hybrid Model)Experience: 5 - 8 YearsNP: Immediate joiners Requirement:Perform Vulnerability assessment & Policy Compliance using leading Vulnerability Scanning solutions like Qualys etc.Perform Vulnerability assessments & Policy...


  • Bengaluru, Karnataka, India Triune Infomatics Inc Full time

    Role: Cybersecurity Vulnerability & Patch Management Engineer (India – U.S. Shift)Working Hours: Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours)Reporting To: Security Operations (SecOps) Leader – USARole Overview: We are hiring a skilled Cybersecurity Vulnerability Management Engineer based in India to support our U.S. Security Operations team....