JobTarget Logo

Vulnerability Engineer in India at Jobgether

NewJob Function: Engineering
Jobgether
India, India
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Vulnerability Engineer

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Vulnerability Engineer based in India.

This role offers the opportunity to strengthen the security posture of a large-scale software platform used by organizations with demanding compliance and risk requirements.
You will play a key part in identifying, assessing, validating, and reducing security vulnerabilities across applications, infrastructure, containers, and dependencies.
The position combines technical investigation, automation, and collaboration with engineering teams to ensure risks are understood and addressed effectively.
You will contribute to building a mature vulnerability management function by improving processes, tooling, and security practices.
The ideal candidate is passionate about cybersecurity, enjoys solving complex problems, and can translate technical findings into actionable recommendations.
Working in a remote environment, you will collaborate with security and engineering professionals to protect critical AI and data science solutions.
This is an impactful opportunity for a security professional who wants ownership, technical depth, and the ability to influence security outcomes.

Accountabilities:

The Vulnerability Engineer will support vulnerability management activities by identifying security risks, validating findings, improving detection processes, and partnering with engineering teams to drive remediation. The role requires strong technical expertise, analytical thinking, and the ability to communicate security risks clearly.

  • Manage vulnerability assessments across operating systems, containers, dependencies, and application environments.
  • Perform vulnerability triage by reviewing scan results, analyzing severity, assessing exploitability, and prioritizing remediation efforts.
  • Conduct validation and reproduction of reported vulnerabilities, including customer disclosures and penetration testing findings.
  • Perform proof-of-concept testing and exploit validation to determine real-world security impact.
  • Maintain and improve vulnerability scanning processes using tools such as Prisma Cloud/Twistlock, JFrog, Trivy, and similar platforms.
  • Support SAST and DAST automation pipelines, troubleshoot scanning issues, and improve the reliability of vulnerability data.
  • Collaborate with engineering teams to communicate risks, support remediation planning, and ensure security fixes are properly prioritized.
  • Develop security insights and risk assessments that help teams make informed decisions.
  • Apply CVSS scoring methodologies while using security judgment to evaluate business impact beyond severity ratings.
  • Contribute to improving vulnerability management processes, documentation, and security practices.
  • Communicate security findings effectively to both technical and non-technical stakeholders.
  • Operate effectively in an evolving environment where security challenges require investigation, creativity, and adaptability.
Requirements:

The ideal candidate has hands-on experience in vulnerability management, application security, and security assessment within modern software environments. You should have strong technical fundamentals, experience working with engineering teams, and the ability to investigate and communicate security risks effectively.

  • Experience managing vulnerabilities for SaaS products, including operating systems, containers, and software dependencies.
  • Proven experience analyzing CVEs, reviewing vulnerability reports, prioritizing risks, and tracking remediation activities.
  • Experience validating vulnerabilities through reproduction, testing, or proof-of-concept analysis.
  • Familiarity with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, Trivy, or similar solutions.
  • Experience building or maintaining SAST/DAST security automation workflows.
  • Strong scripting skills, preferably with Python.
  • Working knowledge of CVSS v3.1/v4.0 scoring and vulnerability risk assessment practices.
  • Experience with exploit validation techniques and security testing tools such as Burp Suite.
  • Understanding of OWASP Top 10 principles and application security testing methodologies.
  • Knowledge of containers, Kubernetes, Linux environments, AWS, and networking fundamentals.
  • Understanding of authentication and authorization concepts, including tokens, sessions, API security, and common attack patterns.
  • Familiarity with basic threat modeling concepts and attack path analysis.
  • Strong communication skills with the ability to explain security risks clearly to engineering teams and business stakeholders.
  • Ability to work independently, manage ambiguity, and take ownership of security initiatives.
  • Experience working in regulated industries or fast-paced technology environments is preferred.
  • Security certifications such as OSWA, OSWE, GWAPT, GPEN, or similar are a plus.
  • Familiarity with technologies such as Airflow and Snowflake is advantageous.
Benefits:
  • Fully remote working environment.
  • Opportunity to work on security challenges for a large-scale AI and data science platform.
  • High level of ownership and impact within a growing security function.
  • Collaboration with experienced security engineers and technical teams.
  • Opportunity to deepen expertise across vulnerability management, cloud security, application security, and automation.
  • Learning-focused environment that encourages continuous improvement and professional development.
  • Culture that values innovation, transparency, collaboration, and personal growth.
  • Inclusive workplace that welcomes professionals from diverse backgrounds and experiences.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Job Location

India, India

Frequently asked questions about this position

Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.
By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.