Back to offers

Cyber Security Senior Analyst - Qualys Vulnerability Management

IT (Information Technology)
Apply

Permanent contract
Bangalore, India
Hybrid

Reference 25000L3R
Start date Immediately
Publication date 2025/12/10

Responsibilities

MSA Designation : Vulnerability Management Specialist - Qualys ( Cyber security -Tool) - L2

As an vulnerability management specialist, you will support the SOC team in their daily activity and administrating Operational Security Processes. You will be asked to identify improvements in current processes and formalize it through clear documentation.

Among the ongoing administration of Processes, your main responsibilities will be to manage the vulnerability scan process. The process is based on Qualys Tools.

  • Perform global infra vulnerability scanning along with change management process
  • Help system administrators to deploy and troubleshoot Qualys agent on different operating systems (Windows, Linux, AIX, etc)
  • Analyze scan results and deploy Qualys appliances(virtual and physical) to enhance scan coverage
  • Responsible for understanding, reviewing, and interpreting assessment and scanning results, reducing false positive findings, and acting as a trusted security advisor to the client.
  • Identify and prioritize all vulnerabilities in client environments and provide timely vulnerability assessment reports to key stakeholders
  • Develop and report enterprise-level metrics for vulnerabilities and remediation progress
  • User requests administration: manage users request on the platforms. Add Hosts, Assets Groups, create scan, report or Dashboard (using the standard and process delivered by SOC SG). Including Emergency stop of scan.
  • Manage Vulnerability Scan for GTS: Manage the Change management process to request a scan on GTS infrastructure. Manage the change creation, the achievement of the change process following by the job creation on Qualys platform.
  • Present Vulnerability Assessment Scanning and guidance, False Positive Validation, Compliance Scanning and, scan profile and policy creation.
  • Analysis of vulnerability: based on group standards, manage the alerting on critical vulnerability found by a vulnerability scan and follow the mitigation with remediation teams
  • Ability to identify false positives
  • Knowledge of vulnerability management frameworks and concepts such as CVE, and CVSS scoring systems and attacking vectors
  • Dashboard: generate monthly and quarterly reports and dashboards.
  • Understanding of Qualys tags
  • Manage Internal Qualys infrastructure: survey the status of Qualys appliances and manage the RMA process and deployment of new appliances.
  • Implement automated, proactive security measures
  • Hands on Qualys modules – Vulnerability Management, Security Configuration Assessment(SCA)/Policy Compliance, Container Security, Cloud Agent, Container Security, Cloud security
  • Knowledge and experience on Terraform, python and any scripting is required

Profile required

  • End to end understanding of Vulnerability management (scanning, remediation follow-up, false positive verification)
  • Conduct Network and System Vulnerability assessments and documentation of corrective/remediation actions
  • Drive the end-to-end vulnerability lifecycle from discovery to closure
  • Identify internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer’s information assets
  • Identify and prioritize all vulnerabilities in client environments and provide timely vulnerability assessment reports to key stakeholders

Ensure timely follow up with patch management and vulnerability remediation in coordination with Countermeasures personnel

Why join us

“We are committed to creating a diverse environment and are proud to be an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status”.

Business insight

At Société Générale, we are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious. Whether you’re joining us for a period of months, years or your entire career, together we can have a positive impact on the future. Creating, daring, innovating, and taking action are part of our DNA. If you too want to be directly involved, grow in a stimulating and caring environment, feel useful on a daily basis and develop or strengthen your expertise, you will feel right at home with us!

Still hesitating? 
You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices, and sharing their skills with charities. There are many ways to get involved.

We are committed to support accelerating our Group’s ESG strategy by implementing ESG principles in all our activities and policies. They are translated in our business activity (ESG assessment, reporting, project management or IT activities), our work environment and in our responsible practices for environment protection.

Diversity and Inclusion

We are an equal opportunities employer and we are proud to make diversity a strength for our company. Societe Generale is committed to recognizing and promoting all talents, regardless of their beliefs, age, disability, parental status, ethnic origin, nationality, gender identity, sexual orientation, membership of a political, religious, trade union or minority organisation, or any other characteristic that could be subject to discrimination.
Share

Titre
Similar jobs

Titre
Jobs & contracts