Vulnerability Management Consultant
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
About the Company
Genpact (NYSE: G) is a global professional services and solutions firm delivering outcomes that shape the future. Our 125,000+ people across 30+ countries are driven by our innate curiosity, entrepreneurial agility, and desire to create lasting value for clients. Powered by our purpose the relentless pursuit of a world that works better for people we serve and transform leading enterprises, including the Fortune Global 500, with our deep business and industry knowledge, digital operations services, and expertise in data, technology, and AI.
About the Company
Genpact (NYSE: G) is a global professional services and solutions firm delivering outcomes that shape the future. Our 125,000+ people across 30+ countries are driven by our innate curiosity, entrepreneurial agility, and desire to create lasting value for clients. Powered by our purpose the relentless pursuit of a world that works better for people we serve and transform leading enterprises, including the Fortune Global 500, with our deep business and industry knowledge, digital operations services, and expertise in data, technology, and AI.
About the Role
Genpact is urgently looking for a strong Consultant for one of our precious clients in USA.
Title: Threat and Vulnerability Management Consultant
Job Summary
The Senior Security Analyst (TVM Operations) ensures the organization maintains a comprehensive and real-time view of its security posture. This operational role manages the daily execution of the Qualys platform, utilizing VMDR, CSAM, and EASM to detect vulnerabilities, discover unmanaged assets, and monitor our external attack surface.
You will not be patching systems yourself; rather, you will be the "source of truth" for partner teams. Your goal is to deliver accurate, actionable data into Jira, collaborate with System Administrators to prioritize fixes, and validate that remediation has occurred.
Who you are:[AO1]
- Operational Specialist: You enjoy the rhythm of daily operations—ensuring scans run, agents report, and data flows correctly.
- The "Radar Operator": You are vigilant about the External Attack Surface (EASM), spotting exposed services or forgotten subdomains before adversaries do.
- Collaborative Influencer: Since you do not apply the patches, you rely on building strong relationships with IT partner teams to drive remediation action.
- Data Steward: You understand that a Vulnerability Management program is only as good as its asset inventory (CSAM), and you relentlessly chase down "unknown" assets.
- Ticket Master: You are comfortable working in Jira, ensuring that security findings don't get lost in the backlog.
Responsibilities include
- Qualys Operations: Manage the daily health of the Qualys subscription, specifically VMDR (Vulnerability Management), CSAM (CyberSecurity Asset Management), and EASM (External Attack Surface Management).
- Asset Discovery & Hygiene (CSAM): continuously monitor the network for unmanaged devices and unauthorized software. Work with IT to install agents or decommission shadow IT.
- External Exposure (EASM): Monitor the organization’s external footprint. Identify and alert on unexpected public-facing assets, open ports, or expired certificates.
- Vulnerability Remediation Management: Translate scan findings into actionable Jira tickets. Assign tasks to appropriate partner teams (Server, Network, Cloud) and participate in sprint planning/backlog reviews to advocate for security tasks.
- Remediation Verification: Execute validation scans (re-scans) once partner teams mark Jira tickets as "Resolved" to confirm the vulnerability is truly closed.
- Scanning Execution: Configure and schedule discovery and vulnerability scans. Manage scanner appliances and exclude lists to prevent operational disruption.
- False Positive Analysis: Review technical evidence provided by partner teams to validate "False Positive" or "Risk Acceptance" requests.
- Reporting & Metrics: Generate weekly operational reports on "Open Vulnerabilities vs. Closed," Remediation SLAs, and Agent Health.
- Agent Health: Troubleshoot Qualys Cloud Agents on endpoints that have stopped reporting or are failing to authenticate.
- Threat Triage: When high-profile vulnerabilities (e.g., Log4j, HTTP/2 Rapid Reset) are announced, use VMDR and CSAM to provide immediate impact assessments to leadership.
Experience you’ll need
- Bachelor’s degree in information security, computer science, or equivalent operational experience.
- Qualys Power User: Proven operational experience with VMDR (running scans, analyzing results).