Cybersecurity Manager - Vulnerability and Asset Management
Remote · Full Time
Be the first to apply
- Experience
- 12+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- Work from home
- Education
- B.Tech or M.Tech in Cybersecurity or related fields
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Join EY's Cybersecurity practice as a Manager focused on Vulnerability Management, Cybersecurity Asset Management, Policy Compliance, and Security Awareness. This role involves leading and optimizing enterprise-wide security risk reduction initiatives and managing multiple vulnerability and asset management platforms across client environments.
Key Responsibilities
- Manage and optimize vulnerability/exposure management tools including Qualys VMDR, Tenable, Rapid7 InsightVM, Microsoft Defender VM, CrowdStrike Falcon, Wiz, Orca Security, and Greenbone/OpenVAS.
- Conduct various vulnerability assessments (internal, external, authenticated, unauthenticated) and analyze related risks.
- Configure scanning schedules/profiles and oversee vulnerability validation, prioritization, and remediation tracking.
- Administer Cybersecurity Asset Management tools to maintain enterprise asset visibility across environments and identify unmanaged or unauthorized assets.
- Ensure compliance management with Qualys Policy Compliance modules and other controls aligned with regulatory standards.
- Facilitate vulnerability governance including remediation review meetings, SLA monitoring, risk prioritization, and reporting.
- Work collaboratively with security, infrastructure, cloud, and application teams to drive remediation efforts and improve cyber resilience.
- Design and manage security awareness programs using Proofpoint, KnowBe4, Microsoft Attack Simulation, Mimecast, and SANS platforms incorporating phishing and social engineering simulations.
- Develop and distribute comprehensive dashboards, reports, and metrics on vulnerability management, asset inventory, policy compliance, and human risk management.
- Maintain documentation, runbooks, and support audits and continuous improvement efforts.
Required Skills and Expertise
- Strong knowledge of vulnerability lifecycle management, risk analysis, and enterprise asset inventory management.
- Hands-on experience with Qualys VMDR, Tenable products, Rapid7 InsightVM, Microsoft Defender VM, CrowdStrike Falcon, Wiz, Orca Security, Greenbone/OpenVAS.
- Expertise in security awareness management platforms such as Proofpoint, KnowBe4, Microsoft Attack Simulation, Mimecast, and SANS.
- Familiarity with compliance frameworks like CIS Benchmarks, NIST CSF, ISO 27001, PCI-DSS.
- Proficiency interfacing with IT, cloud, and security teams to enforce remediation activities and governance.
- Ability to analyze vulnerability intelligence, CVSS, CISA KEV, and conduct risk-based prioritization.
- Experience in scripting and automation using Python, PowerShell, SQL, and APIs is advantageous.
Qualifications and Experience
- B.Tech or M.Tech in Cybersecurity, Computer Science, Information Security or related field.
- A minimum of 12 years’ experience in vulnerability management, asset management, security operations, or consulting.
Personal Attributes
- Analytical thinker with excellent reporting and problem-solving skills.
- Strong communication and stakeholder engagement abilities.
- Detail-oriented, collaborative, customer-focused, and proactive in risk mitigation.
Company Overview
EY is a global leader committed to building a better working world by enhancing client value and fostering trust in capital markets. They leverage data and technology with diverse teams in over 150 countries to drive growth, transformation, and innovative solutions.
Minimum education
Bachelor's Degree