Skip to main content
Posted 17 July, 2026

Vulnerability Management Analyst

Diversity Nexus
Gurgaon, IN Full Time
Reference: 26-00180-2458-1

Onsite role in Cyber City, Gurgaon India
Duration: 6 months contract with possibility of conversion afterwards
Years of experience: 6-10 years' experience
About the job
We are looking to hire a Vulnerability Management Analyst II to join our Vulnerability Management team. The Vulnerability Management Analyst II is a hands-on practitioner who identifies, analyzes, and drives remediation of vulnerabilities across our IT and OT environments. This role focuses on turning scan results into clear, prioritized actions for technology and business teams, ensuring that high-risk issues are understood, owned, and resolved within agreed timelines.

You will partner closely with infrastructure, application, cloud, and supply chain teams, as well as our cyber threat management functions, to reduce our attack surface and improve our overall security posture.

Responsibilities
  1. Run regular vulnerability scans across servers, endpoints, applications, cloud, and OT where in scope.
  2. Validate and triage findings, remove false positives, and prioritize issues based on risk.
  3. Create and manage remediation tickets, working with system and application owners to drive fixes.
  4. Track remediation progress against SLAs and escalate when deadlines or risk levels are not met.
  5. Prepare simple reports and dashboards that show trends, risk hot spots, and SLA performance.
  6. Recommend improvements to scanning scope, schedules, and processes to reduce blind spots and noise.
  7. Partner with security operations, threat Client, and incident response teams to connect vulnerabilities to real-world threats.
  8. Educate IT and OT partners on what needs to be fixed, why it matters, and how to prevent repeat issues.

Required Qualifications
  1. Bachelor's degree in computer science, information security, related degree, or measurable knowledge from serving in industry/military/government unit.
  2. Security+, Network+, GSEC, CySA+ or other relevant professional certifications
  3. 6+ years' professional experience working in cybersecurity or information technology
  4. Working knowledge of MITRE Telecommunication&CK, common attack techniques, and control families
  5. Hands on use of at least two tool categories such as Vuln Management, SIEM, EDR, NDR, IDS, DLP, SOAR, or cloud security tools
  6. Ability to read common log sources such as Windows events, Linux logs, proxy, DNS, and authentication logs
  7. Scripting or automation experience to pull data, parse outputs, or enrich cases
  8. Strong written and verbal communication tailored to the audience

Sign up for Job Alerts