Lead enterprise vulnerability management: analyze scanner and cloud security findings, prioritize risks using threat intelligence, drive remediation governance, design automation and reporting, mentor analysts, and advise on remediation across on-prem and cloud environments.
Job Purpose and Impact
The Senior Vulnerability Management Analyst safeguards the organization's digital assets by leading the identification, assessment, prioritization, and remediation of cybersecurity vulnerabilities across the global enterprise. This role serves as a trusted advisor and technical leader, driving enterprise vulnerability management strategy, governance, and continuous improvement initiatives. With minimal supervision, the Senior Analyst partners with cybersecurity, infrastructure, cloud, engineering, risk, and business leaders to reduce organizational exposure and improve cyber resilience.
Key Accountabilities
-Leading enterprise-wide vulnerability management and exposure reduction programs.
-Performing advanced analysis of vulnerability data from tools such as Tenable, Qualys, Rapid7, Wiz, and cloud-native security platforms.
-Establishing risk-based prioritization methodologies that incorporate threat intelligence, exploit activity, business criticality, and compensating controls.
-Driving remediation accountability and governance across technology and business stakeholders.
-Developing executive-level reporting, metrics, and risk insights for leadership and governance forums.
-L-eading major vulnerability response efforts related to zero-day threats, actively exploited vulnerabilities, and high-profile CVEs.
-Identifying systemic vulnerability trends and recommending strategic improvements to reduce recurring risk.
-Partnering with Threat Intelligence, Threat Hunting, Red Team, Incident Response, and Security Architecture teams to validate and enrich findings.
-Leading continuous improvement efforts related to scanning coverage, asset visibility, attack surface management, and remediation effectiveness.
-Designing and implementing dashboards, automation, and integrations to improve program efficiency and reporting.
-Consulting on security architecture, cloud adoption, and remediation strategies across on-premises and cloud environments.
-Mentoring junior analysts and providing technical leadership during complex investigations and remediation efforts.
-Staying current on threat actor behaviors, emerging attack techniques, exploit trends, and industry best practices.
-Demonstrating deep expertise in CVSS, EPSS, MITRE ATT&CK, threat modeling, and cyber risk management frameworks.
-Providing strategic guidance for remediation across Windows, Linux, networking, cloud platforms (AWS, Azure, GCP, OCI), containers, and modern enterprise technologies.
ESSENTIAL FUNCTIONS
-VULNERABILITY MANAGEMENT STRATEGY & GOVERNANCE: Leads the design, implementation, operation, and continuous improvement of enterprise vulnerability management capabilities. Establishes standards, governance processes, performance metrics, and risk management practices to reduce organizational exposure.
-EXTERNAL ATTACK SURFACE MANAGEMENT: Provides strategic oversight of the organization's external attack surface, identifying emerging risks, prioritizing remediation efforts, and guiding improvements to overall exposure management practices.
-RISK-BASED PRIORITIZATION & REMEDIATION: Develops and maintains enterprise risk models for vulnerability prioritization, ensuring remediation efforts focus on the most significant business and cybersecurity risks.
-THREAT-INFORMED VULNERABILITY MANAGEMENT :Integrates vulnerability management with threat intelligence, threat hunting, offensive security, and incident response capabilities to improve detection, prioritization, and remediation outcomes.
-PROGRAM LEADERSHIP & CONTINUOUS IMPROVEMENT: Leads cross-functional initiatives that improve scanning coverage, asset visibility, remediation performance, governance processes, and overall program maturity.
-EXECUTIVE COMMUNICATION & STAKEHOLDER MANAGEMENT: Communicates complex technical risks to executive leadership and business stakeholders, influencing strategic decisions and prioritization of remediation activities.
Qualifications
The Senior Vulnerability Management Analyst safeguards the organization's digital assets by leading the identification, assessment, prioritization, and remediation of cybersecurity vulnerabilities across the global enterprise. This role serves as a trusted advisor and technical leader, driving enterprise vulnerability management strategy, governance, and continuous improvement initiatives. With minimal supervision, the Senior Analyst partners with cybersecurity, infrastructure, cloud, engineering, risk, and business leaders to reduce organizational exposure and improve cyber resilience.
Key Accountabilities
-Leading enterprise-wide vulnerability management and exposure reduction programs.
-Performing advanced analysis of vulnerability data from tools such as Tenable, Qualys, Rapid7, Wiz, and cloud-native security platforms.
-Establishing risk-based prioritization methodologies that incorporate threat intelligence, exploit activity, business criticality, and compensating controls.
-Driving remediation accountability and governance across technology and business stakeholders.
-Developing executive-level reporting, metrics, and risk insights for leadership and governance forums.
-L-eading major vulnerability response efforts related to zero-day threats, actively exploited vulnerabilities, and high-profile CVEs.
-Identifying systemic vulnerability trends and recommending strategic improvements to reduce recurring risk.
-Partnering with Threat Intelligence, Threat Hunting, Red Team, Incident Response, and Security Architecture teams to validate and enrich findings.
-Leading continuous improvement efforts related to scanning coverage, asset visibility, attack surface management, and remediation effectiveness.
-Designing and implementing dashboards, automation, and integrations to improve program efficiency and reporting.
-Consulting on security architecture, cloud adoption, and remediation strategies across on-premises and cloud environments.
-Mentoring junior analysts and providing technical leadership during complex investigations and remediation efforts.
-Staying current on threat actor behaviors, emerging attack techniques, exploit trends, and industry best practices.
-Demonstrating deep expertise in CVSS, EPSS, MITRE ATT&CK, threat modeling, and cyber risk management frameworks.
-Providing strategic guidance for remediation across Windows, Linux, networking, cloud platforms (AWS, Azure, GCP, OCI), containers, and modern enterprise technologies.
ESSENTIAL FUNCTIONS
-VULNERABILITY MANAGEMENT STRATEGY & GOVERNANCE: Leads the design, implementation, operation, and continuous improvement of enterprise vulnerability management capabilities. Establishes standards, governance processes, performance metrics, and risk management practices to reduce organizational exposure.
-EXTERNAL ATTACK SURFACE MANAGEMENT: Provides strategic oversight of the organization's external attack surface, identifying emerging risks, prioritizing remediation efforts, and guiding improvements to overall exposure management practices.
-RISK-BASED PRIORITIZATION & REMEDIATION: Develops and maintains enterprise risk models for vulnerability prioritization, ensuring remediation efforts focus on the most significant business and cybersecurity risks.
-THREAT-INFORMED VULNERABILITY MANAGEMENT :Integrates vulnerability management with threat intelligence, threat hunting, offensive security, and incident response capabilities to improve detection, prioritization, and remediation outcomes.
-PROGRAM LEADERSHIP & CONTINUOUS IMPROVEMENT: Leads cross-functional initiatives that improve scanning coverage, asset visibility, remediation performance, governance processes, and overall program maturity.
-EXECUTIVE COMMUNICATION & STAKEHOLDER MANAGEMENT: Communicates complex technical risks to executive leadership and business stakeholders, influencing strategic decisions and prioritization of remediation activities.
Qualifications
- Minimum requirement of 5 years of relevant cybersecurity, vulnerability management, attack surface management, or exposure management experience.
- Typically reflects 7+ years of relevant experience.
- Experience leading enterprise-scale vulnerability management, exposure management, or cyber risk reduction initiatives preferred.
- Demonstrated experience influencing senior leaders and driving cross-functional remediation efforts.
- Relevant industry certifications such as CISSP, GSEC, GIAC, Security+, CySA+, AWS Security, Azure Security Engineer, or equivalent are preferred
Similar Jobs at Cargill
Food • Greentech • Logistics • Sharing Economy • Transportation • Agriculture • Industrial
Lead global carrier strategy and service integration for enterprise mobility. Manage carrier/vendor relationships, optimize mobile costs and plans, drive incident management and continuous improvement, and enable automation and reporting for usage, cost visibility, and service performance across regions.
Top Skills:
Carrier Activation WorkflowsDual SimEsimPower BIScriptingZero-Touch Enrollment
Food • Greentech • Logistics • Sharing Economy • Transportation • Agriculture • Industrial
Manage end-to-end PR/PO/GR/IR lifecycle for IT suppliers to ensure timely, accurate, and compliant payments. Resolve exceptions and blocked invoices, coordinate with Finance/R2R/I2P/AP/Procurement, maintain audit-ready documentation, lead root-cause analysis, drive process improvements and automation (RPA/workflows), and perform process audits and SOP governance.
Top Skills:
AribaCoupaOracleRpaSap (Mm/Fi)Workflow Engines
Food • Greentech • Logistics • Sharing Economy • Transportation • Agriculture • Industrial
Lead architecture, implementation, integration, modernization, and operational support for OpenText xECM and Content Server in SAP environments. Design and maintain platform components, security, cloud migration, high availability, ArchiveLink and REST integrations, metadata/workspace configuration, and develop technical specs while mentoring teams and engaging stakeholders to drive enterprise-scale solutions.
Top Skills:
Active DirectoryAWSContent Lifecycle ManagementLdapAzureOpentext Archive CenterOpentext BravaOpentext Business WorkspacesOpentext CloudOpentext Content ServerOpentext Enterprise SearchOpentext OtdsOpentext XecmRecords ManagementRest ApisSAMLSap ArchivelinkSap EccSap FioriSap S/4HanaSap WorkflowSsoWeb Services
What you need to know about the Pune Tech Scene
Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.
.png)
.png)