Enter a job title or keyword

Cyber Threat Exposure Management – Lead

Version 1


Job Location:

Bengaluru - India

Monthly Salary: Not provided by the employer
Posted: 11 September 2026 (11 hours ago)
Application Deadline: 9 December 2026
Vacancies: 1 Vacancy

Job Summary

Senior technical lead to own strategy and drive maturity across attack surface management vulnerability management and cloud security posture using a continuous threat exposure management (CTEM) approach. 

Accountable for programme delivery quality tooling strategy and governance. Requires deep technical expertise combined with the ability to lead and coach a team shape a capability roadmap and influence senior stakeholders without direct supervision.

Key Responsibilities

Strategy & Programme Direction

  • Own function strategy aligned to business risk appetite and security frameworks.
  • Drive continuous improvement across all CTEM programme phases.
  • Establish governance and standards across vulnerability management ASM CSPM and secure development.
  • Own the exposure management roadmap; present evidence-based investment cases to senior stakeholders.

Tool Selection & Capability Development

  • Own toolchain selection for EASM/CAASM vulnerability management CSPM and exposure correlation.
  • Integrate exposure management platforms with SIEM SOAR and DevSecOps pipelines.
  • Monitor emerging tooling and AI-augmented triage; recommend capability investments.
  • Define coverage requirements and onboarding standards for new assets and workloads.

Attack Surface Management (ASM / EASM)

  • Run continuous discovery and attribution of all Internet-facing assets shadow IT and third-party exposure.
  • Enrich findings with threat intelligence KEV data and active exploitation trends.
  • Maintain an accurate inventory as the authoritative basis for prioritisation.
  • Continuously improve coverage reduce noise and sharpen the prioritisation model.

Vulnerability Management

  • Own the vulnerability management programme end to end: triage remediation SLA governance and closure.
  • Maintain risk-based scoring incorporating CVSS EPSS business criticality and threat context.
  • Hold remediation teams to SLAs; resolve systemic blockers across functions.

Cloud Security Posture Management (CSPM)

  • Own CSPM strategy across AWS Azure and OCI; keep visibility current with estate growth.
  • Partner with cloud platform and architecture teams to embed security posture requirements into platform design and IaC standards.
  • Eliminate recurring misconfigurations through root cause analysis; dont accept repeat findings.

Pentest & Purple Team Oversight

  • Commission and manage penetration testing and purple team engagements; QA external deliverables.
  • Translate findings into prioritised remediation and track to closure.
  • Use validation outputs to improve controls and update the exposure model.

Secure SDLC

  • Integrate security requirements threat modelling and code review into the SDLC.
  • Drive secure-by-design principles with engineering and architecture teams.
  • Measure secure development maturity and set improvement targets.

Leadership Reporting & Stakeholder Engagement

  • Deliver executive dashboards translating technical risk into business impact; represent the function in ISO 27001 Cyber Essentials Plus SOC 1 and MSP audit cycles.
  • Build credibility with senior stakeholders client security teams and third-party assessors.
  • Lead coach and develop the team; set clear goals resolve conflicts and create growth opportunities.
  • Foster a culture of learning and delivery excellence; act as escalation point for complex technical decisions.
  • Coordinate remediation owners platform teams and external parties; keep all stakeholders aligned on plans and blockers.

Qualifications :

Beneficial Qualifications & Skills

  • 6 years experience in cyber security 2 years in a senior exposure management VM or threat intelligence role; degree in Computer Science or Information Security or equivalent.
  • Relevant certifications: CISSP CISM OSCP or equivalent. CTEM-related training or Gartner CTEM methodology experience advantageous.
  • Experience evaluating and selecting security tooling across EASM/CAASM CSPM and VM platforms; hands-on with Defender XDR/CSPM Zscaler Tenable Tanium or equivalent.
  • Deep working knowledge of NIST CSF ISO 27001 MITRE ATT&CK and CTEM principles.
  • ISPM and attack path mapping experience; ability to communicate technical exposure as business risk to senior stakeholders.
  • Experience designing or maturing a CTEM programme; familiarity with AI-augmented vulnerability triage attack path analysis or BAS.
  • Exposure to audit frameworks (Cyber Essentials Plus SOC 1 FSQS) or MSP/MSSP environment.

Additional Information :

Why Version 1 

At Version 1 we believe in providing our employees with a comprehensive benefits package that prioritises their wellbeing professional growth and financial stability. 

  • Share in our success with our Quarterly Performance-Related Profit Share Scheme where employees collectivelybenefitfrom a share of our companys profits 

  • Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme 

  • Flexible/remote working Version 1 is tremendously understanding of life events and peoples individual circumstances and offer flexibility to help achieve a healthy work life balance 

  • Financial Wellbeing initiativesincluding;Pension Private Healthcare Cover Life Assurance Financialadviceand an Employee Discount scheme 

  • Employee Wellbeing schemes including Gym Discounts Bike to Work Fitness classes Mindfulness Workshops Employee Assistance Programme and much more. Generous holiday allowance enhanced maternity/paternity leave marriage/civil partnership leave and special leave policies 

  • Educationalassistance incentivised certifications and accreditations including AWS Microsoft Oracle and Red Hat 

  • Reward schemes including Version 1s Annual Excellence Awards & Call-Out platform. 

  • Environment Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity inclusion and belonging schemes. 

And many more exciting benefits drop us a note to find out more. 

Version1 is an equal opportunities employer. 

We are committed to building a diverseinclusiveand respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds identities and lived experiences and we value the different perspectives people bring including those shaped by disability and neurodiversity. 

We want every candidate to have a positive and accessible recruitment experience. If you need reasonable adjustments at any stage of the process please contact your recruiter at Version 1. We will consider all requests carefullyrespectfullyand confidentially. 

Video links: 

Work :

No


Employment Type :

Full-time


About Company

Company Logo

Version 1 has celebrated over 26 years in Technology Services and continues to be trusted by global brands to deliver solutions that drive customer success. Version 1 has several strategic technology partners including Microsoft, AWS, Oracle, Red Hat, OutSystems and Snowflake. We’re a ... View more

View Profile View Profile