**Job Title:** Threat and Vulnerability Management (TVM) Manager **Location:** Hyderabad, Telangana, India **Employment Type:** Full-Time, Onsite **Department:** Information Security / Cyber Defense
---
### About the Role
We are seeking an experienced, proactive, and strategic **Threat and Vulnerability Management (TVM) Manager** to lead and scale our enterprise vulnerability management program. Based on-site at our Hyderabad office, you will play a critical role in safeguarding our digital assets, minimizing our external and internal attack surfaces, and orchestrating robust vulnerability remediation workflows across hybrid, cloud, and on-premises environments.
As the TVM Manager, you will bridge the gap between technical threat intelligence and operational remediation. You will partner closely with Infrastructure, DevOps, Application Security, and IT Operations teams to identify, prioritize, and drive the resolution of critical security vulnerabilities before they can be exploited.
---
### Key Responsibilities
- **Program Leadership & Strategy:** Define, implement, and continuously mature the enterprise Threat and Vulnerability Management (TVM) lifecycle, including discovery, assessment, prioritization, reporting, and remediation verification.- **Vulnerability Assessment & Scanning:** Oversee automated vulnerability scans across networks, endpoints, cloud infrastructure (AWS/Azure/GCP), containerized environments, and applications using enterprise scanning platforms (e.g., Qualys, Tenable/Nessus, Rapid7).- **Risk-Based Prioritization:** Analyze threat intelligence feeds, zero-day alerts, and active exploit trends (leveraging CVSS, EPSS, and CISA KEV) to contextualize and prioritize vulnerabilities based on actual risk to the business.- **Cross-Functional Remediation Governance:** Establish and enforce Patch and Vulnerability SLAs. Collaborate with system administrators, engineering teams, and service owners to ensure timely patching and risk mitigation.- **Exception & Risk Acceptance Management:** Oversee the security exception workflow, evaluating business justifications, compensating controls, and residual risks for unpatched assets.- **Threat Intelligence Integration:** Monitor global cyber threat landscapes and proactively assess the organization's exposure to emerging threats, threat actors, and Tactics, Techniques, and Procedures (TTPs).- **Metrics, Reporting & Auditing:** Develop and present executive-level dashboards, KPIs/KRIs, and operational metrics illustrating program effectiveness, posture trends, and SLA adherence for leadership and compliance audits (e.g., ISO 27001, SOC 2, PCI-DSS).
---
### Qualifications & Requirements
- **Experience:** 8+ years of experience in Information Security, with at least 3–5 years dedicated to leading vulnerability management, threat intelligence, or incident response programs.- **Education:** Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).- **Technical Expertise:** - In-depth mastery of enterprise vulnerability scanners (Qualys, Tenable.io/Nessus, Rapid7 InsightVM, or Microsoft Defender for Endpoint). - Strong understanding of operating systems (Windows, Linux), cloud architectures (AWS, Azure), network protocols, containers (Docker, Kubernetes), and Active Directory. - Familiarity with vulnerability scoring frameworks (CVSS v3/v4, EPSS) and industry standards (NIST CSF, CIS Benchmarks, OWASP Top 10, MITRE ATT&CK). - Working knowledge of scripting languages (Python, PowerShell, or Bash) and REST APIs for scanning workflow automation and tool integration.- **Leadership & Communication:** Exceptional stakeholder management and communication skills, with the ability to explain complex technical vulnerabilities to non-technical business leaders.- **Certifications (Preferred):** One or more industry-recognized certifications such as CISSP, CISM, CEH, CRISC, GMON, GEVA, or cloud-specific security certifications (AWS Certified Security, Azure Security Engineer).
---
### What We Offer
- **Competitive Compensation:** Attractive salary package with annual performance-based incentives.- **Comprehensive Healthcare:** Premium health, dental, and vision insurance for you and your dependents.- **Career Development:** Generous budget and support for continuous learning, advanced security certifications, and global industry conferences.- **Modern Work Environment:** State-of-the-art office facilities located in Hyderabad's premier IT hub, equipped with ergonomic workspaces and collaborative zones.- **Paid Time Off:** Comprehensive annual leave, public holidays, and wellness days to ensure work-life balance.