
Vulnerability & Incident Response Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India.
• Conduct initial triage, validation, and assessment of product vulnerabilities
• Evaluate the severity of vulnerabilities utilizing CVSS, exploitability, product relevance, and business impact criteria
• Analyze vulnerability reports and collaborate with product teams to ascertain applicability, exploitability, remediation needs, and prioritization
• Maintain comprehensive records of vulnerabilities, evidence, and audit trails
• Oversee the reporting activities related to security incidents and exploited vulnerabilities
• Prepare information for regulatory notifications in conjunction with Product Security, Legal, and Product Teams
• Monitor incident reporting deadlines and ensure escalation activities are completed within regulatory timelines
• Assist in incident readiness exercises and validate reporting processes
• Keep an eye on vulnerability disclosure channels, PSIRT mailboxes, public disclosures, security advisories, and threat intelligence feeds
• Detect emerging threats impacting HBK products and coordinate investigations
• Track Known Exploited Vulnerabilities, industry alerts, and pertinent security advisories
• Collaborate with Product Teams, DevSecOps, and Product Security stakeholders to coordinate remediation actions
• Monitor the progress of remediation efforts against established targets and service level objectives
• Aid in reviewing security updates, patches, and mitigation strategies
• Generate vulnerability status reports, metrics, and management updates
• Act as an operational liaison among Product Security, DevSecOps, Customer Support, Legal, and Product Teams
• Enhance communication and resolve issues among stakeholders
• Support the implementation and ongoing enhancement of vulnerability management and coordinated vulnerability disclosure processes
• Contribute to initiatives aimed at regulatory readiness for the EU Cyber Resilience Act
• Bachelor’s or master’s degree in cybersecurity, Computer Science, Information Security, Software Engineering, or a related technical field
• Proven experience in vulnerability management, security operations, incident response, PSIRT, application security, or a related cybersecurity area
• Solid understanding of vulnerability assessment methodologies, CVSS scoring, exploitability analysis, and remediation workflows
• Familiarity with vulnerability management platforms, ticketing systems, and security scanning tools
• Knowledge of vulnerability databases and threat intelligence sources, including CVE, NVD, and KEV
• Familiarity with software development lifecycles and secure development practices
• Awareness of cybersecurity regulations and standards such as EU CRA, ISO/IEC 30111, ISO/IEC 29147, IEC 62443, NIST SP 800 series, or ISO 27001
• Strong analytical and problem-solving capabilities
• Ability to prioritize and manage several activities concurrently
• Excellent communication and stakeholder management skills across both technical and non-technical teams
• Experience in preparing security reports, metrics, and compliance documentation is desirable
• Preferred experience working within a PSIRT
• Preferred familiarity with regulatory reporting obligations and coordinated vulnerability disclosure programs
• Preferred experience with vulnerability management automation, DevSecOps pipelines, SBOM tooling, or software composition analysis platforms
• Knowledge of cloud, desktop, SaaS, embedded, or industrial control system products
• Understanding of penetration testing
• Previous experience with bug bounty platforms is an added advantage
• Competitive salary and performance-based bonuses
• Comprehensive health, dental, and vision insurance plans
• Opportunities for professional development and career advancement
• Flexible working hours and a supportive work environment
Get handpicked remote jobs straight to your inbox weekly.