VI
VI, ASM and VM Expert
VARITE INDIA PRIVATE LIMITED
🇮🇳 India
On-site
7 months ago
- CVSS
- Threat Intelligence
- Threat Modeling
- Penetration Testing
- Power BI
- Vulnerability Management
- CISSP
- CCSP
- CompTIA Security+
- Qualys
- Tenable
- Burp
- Python
- Bash
- PowerShell
- C#
- ETL
- NIST
- OWASP
7 months ago
About The Client:
A global professional services network and part of the Big Four, along with Client, EY, and KPMG, operating across 149 countries worldwide.
Essential Job Functions:
- Vulnerability Intelligence (VI):
- Drive the qualification and risk analysis of newly disclosed vulnerabilitie
- Perform exploit PoC validation when needed to assess practical risk
- Maintain and enhance the central VI database, enriched with (EPSS, CVSS, QVS, SG-specific scoring models, and EUVD)
- Define and automate workflows for:
- Vulnerability qualification, exposure analysis, and prioritization
- Ingestion of qualified vulnerability data into the enterprise Data Lake
- Collaborate on documentation of VI methodology and threat intelligence integration
- Support proactive communication of high/critical vulnerabilities to asset and application owners
- Attack Surface Management (ASM):
- Operate and enhance external asset discovery and continuous monitoring using ASM tools
- Integrate asset coverage data from CMDB, and other internal datasets
- Design and implement scripts for:
- WHOIS/ASN/banner correlation
- Data enrichment and alert filtering
- Deploy and maintain custom scanning capabilities (e.g., Nuclei integrations)
- Provide expert input on threat modeling based on exposed assets and external footprint
- BlackBox Pentesting:
- Maintain the service delivery of the BlackBox Pentesting platform
- Automate the export of pentest data and integrate into Data Lake and Power BI dashboards
- Define and document onboarding workflows for new applications
- Actively guide analysts in prioritizing pentest requests and validating results.
- Vulnerability Management:
- Vulnerability review, recategorization, and false positive identification
- Proactive vulnerability testing and replay
- Pre-analyze and consolidate vulnerability data from various scanning tools
- Prepare concise syntheses of available vulnerabilities
- Offer guidance to the SO and CISO on vulnerabilities
- Collaborate with key stakeholders to develop strategies for vulnerability management
- Assist in defining vulnerability management KPIs and strategic goals
- Prepare concise, actionable summaries for high-risk vulnerabilities and trends
- Automate testing actions:
- Develop scripts and tooling to automate repetitive and complex tasks across VI, ASM, and VM
- Implement data pipelines to sync outputs from ASM/VI tools to dashboards and reporting engines
- Design streamlined workflows for vulnerability lifecycle—from detection to closure
- Collaborate with both offensive and defensive teams to support App managers and Asset managers in remediating vulnerabilities and issues
- Experience 10+
Skills
- Bachelor's degree in Computer Science, Information Security, EXTC or related field; relevant certifications (e.g., CISSP, CCSP, CompTIA Security+) are a plus
- Proven experience (10+ years) working within the Cybersecurity field, with a focus on offensive security, vulnerability intelligence and attack surface analysis.
- Proven experience on Penetration testing actions (web application, infrastructure, ...)
- Proven expertise in:
- CVE analysis, exploit development/validation
- External asset discovery & mapping
- Threat modeling and prioritization
- Advanced knowledge of tooling such as:
- ASM platforms
- Nuclei, Shodan, Open Source CTI, vulnerability scanners (Qualys, Tenable, ...)
- Pentester tools (Burp, SQLmap, Responder, IDA and Kali environment)
- Experience in investigating newly published vulnerabilities and assessing their risks and severity
- Strong scripting languages (e.g., Python, Bash, Powershell, C#, ...) for automation and customization
- Experience with Pentester tools (Burp, SQLmap and Kali environment)
- Strong technical skills with an interest in open-source intelligence investigations
- Experience building dashboards in Power BI or similar tools.
- Familiarity with data lakes, API integrations, and ETL processes.
- Knowledge of NIST CVE database, OWASP Top 10, Microsoft security bulletins
- Excellent writing skills in English and ability to communicate complicate technical challenges in a business language to a range of stakeholders.
Personal Skills
- Has a systematic, disciplined, and analytical approach to problem solving with Thorough leadership skills & experience
- Excellent ability to think critically under pressure
- Strong communication skills to convey technical concepts clearly to both technical and non-technical stakeholders
- Willingness to stay updated with evolving cyber threats, technologies, and industry trends
- Capacity to work collaboratively with cross-functional teams, developers, and management to implement robust security measures
Shift Timing 9am-6pm
How to Apply:Interested candidates are encouraged to respond/submit their updated resumes, and for additional job opportunities, please visit Jobs In India – VARITE.Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this opportunity, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the referred candidate completes a three-month assignment with VARITE.
Experience Level Bonus Referral:
| 0-2 years | INR 5,000 |
| 2-6 years | INR 7,500 |
| 6+ years | INR 10,000 |
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.
VI, ASM and VM Expert · VARITE INDIA PRIVATE LIMITED