Cyber Security Analyst-VM
Job Summary
Role Purpose
The purpose of this role is to analyze attack patterns develop incident response plans ensure audit readiness and implement disaster recovery measures to ensure adherence to cyber security regulatory frameworks.
Â
Areas of responsibility
Monitoring and Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection to ensure compliance with security frameworks and regulatory standards.
Incident Handling and Analysis-Perform root cause analysis create incident response plans and implement disaster recovery measures to minimize business disruption
Threat Assessment and Analytics-Undertake forensic analysis using advanced analytics tools and implement mitigation measures to align with compliance requirements.
Stakeholder Coordination and Audit Assistance-Liaise with cross functional teams external vendors and auditors to ensure compliance with security frameworks.
Maintain audit documentation and ensure its accuracy while implementing processes that support audit readiness and continuous compliance.
Training and Awareness-Assist in creating and delivering cybersecurity awareness sessions including guidance on phishing and malicious emails.
Role: Vulnerability Management Analyst Qualys VM
Role Summary
We are looking for a handson Vulnerability Management professional with strong operational experience on Qualys VM / VMDR to support BAU vulnerability operations for large enterprise environments.
The role is executionheavy and requires daytoday ownership of scanning validation remediation tracking reporting and stakeholder coordination rather than advisory or governanceonly work.
Key Responsibilities
Qualys VM Operations
- Perform authenticated and unauthenticated vulnerability scans using Qualys VM / VMDR across:
- Servers (Windows & Linux)
- Network devices
- Endpoints
- Cloud workloads (AWS / Azure)
- Manage asset discovery tagging and grouping within Qualys.
- Configure and maintain scan profiles schedules and exclusions based on environment and risk.
- Troubleshoot scan failures authentication issues and agentrelated problems.
Vulnerability Analysis & Validation
- Analyze Qualys scan results and:
- Validate true positives
- Identify and eliminate false positives
- Apply riskbased prioritization using CVSS exploitability asset criticality and threat context.
- Track zeroday and highseverity vulnerabilities and support expedited remediation.
Remediation & Stakeholder Coordination
- Create track and manage remediation tickets using:
- ServiceNow / Jira or equivalent ITSM tools
- Work closely with:
- Infrastructure teams
- Application owners
- Cloud and platform teams
- Follow up on remediation SLAs and perform rescans to confirm closure.
Reporting & BAU Governance
- Prepare and publish:
- Weekly / Monthly vulnerability reports
- Executive summaries and dashboards
- Support compliance and audit requirements (ISO 27001 CIS benchmarks etc.).
- Maintain SOPs runbooks and BAU documentation.
Tooling & Automation (Good to Have)
- Support Qualys API integrations with ServiceNow SIEM or reporting tools.
- Basic scripting exposure (Python / PowerShell / Bash) for automation and data handling.
Mandatory Skills & Experience
Core Technical Skills
- Strong handson experience with Qualys VM / Qualys VMDR (mandatory)
- Solid understanding of:
- Vulnerability lifecycle (identify assess remediate validate)
- CVE CVSS exploitability patching concepts
- Experience with:
- Windows & Linux OS
- Networking fundamentals (TCP/IP ports firewalls)
- Exposure to cloud vulnerability scanning (AWS / Azure) is highly desirable.
Tools & Platforms
- Qualys VM / VMDR
- ITSM tools: ServiceNow / Jira
- Supporting tools: Nessus / Rapid7 (good to have not mandatory)
- Reporting tools: Excel / Power BI (basic to intermediate)
Soft Skills (Important for BAU Success)
- Strong operational ownership mindset
- Ability to manage multiple remediation streams in parallel
- Clear communication with technical and nontechnical stakeholders
- Comfortable handling escalations and SLAdriven delivery
- Good documentation and reporting discipline
Preferred / Nice to Have
- Experience in managed security services
- Exposure to:
- Policy compliance scanning
- Cloud posture / infrastructure security
- Certifications (preferred not mandatory):
- Qualys certification
- CEH / Security / ISO 27001 awareness
Role Type
- Handson BAU / Run Operations
- Not a consultingonly or GRConly role
- Ideal for candidates who enjoy daytoday vulnerability operations and execution
Required Experience:
IC
About Company
As a global leader, Wipro blends consulting and AI expertise across design, engineering and operations to accelerate business transformation and deliver future-ready technology.