Remotery

Vulnerability & Incident Response Analyst

Posted 1 day ago

This is a fully remote position, open to applicants in India.

📋 Description

• Conduct initial triage, validation, and assessment of product vulnerabilities

• Evaluate the severity of vulnerabilities utilizing CVSS, exploitability, product relevance, and business impact criteria

• Analyze vulnerability reports and collaborate with product teams to ascertain applicability, exploitability, remediation needs, and prioritization

• Maintain comprehensive records of vulnerabilities, evidence, and audit trails

• Oversee the reporting activities related to security incidents and exploited vulnerabilities

• Prepare information for regulatory notifications in conjunction with Product Security, Legal, and Product Teams

• Monitor incident reporting deadlines and ensure escalation activities are completed within regulatory timelines

• Assist in incident readiness exercises and validate reporting processes

• Keep an eye on vulnerability disclosure channels, PSIRT mailboxes, public disclosures, security advisories, and threat intelligence feeds

• Detect emerging threats impacting HBK products and coordinate investigations

• Track Known Exploited Vulnerabilities, industry alerts, and pertinent security advisories

• Collaborate with Product Teams, DevSecOps, and Product Security stakeholders to coordinate remediation actions

• Monitor the progress of remediation efforts against established targets and service level objectives

• Aid in reviewing security updates, patches, and mitigation strategies

• Generate vulnerability status reports, metrics, and management updates

• Act as an operational liaison among Product Security, DevSecOps, Customer Support, Legal, and Product Teams

• Enhance communication and resolve issues among stakeholders

• Support the implementation and ongoing enhancement of vulnerability management and coordinated vulnerability disclosure processes

• Contribute to initiatives aimed at regulatory readiness for the EU Cyber Resilience Act


⛳️ Requirements

• Bachelor’s or master’s degree in cybersecurity, Computer Science, Information Security, Software Engineering, or a related technical field

• Proven experience in vulnerability management, security operations, incident response, PSIRT, application security, or a related cybersecurity area

• Solid understanding of vulnerability assessment methodologies, CVSS scoring, exploitability analysis, and remediation workflows

• Familiarity with vulnerability management platforms, ticketing systems, and security scanning tools

• Knowledge of vulnerability databases and threat intelligence sources, including CVE, NVD, and KEV

• Familiarity with software development lifecycles and secure development practices

• Awareness of cybersecurity regulations and standards such as EU CRA, ISO/IEC 30111, ISO/IEC 29147, IEC 62443, NIST SP 800 series, or ISO 27001

• Strong analytical and problem-solving capabilities

• Ability to prioritize and manage several activities concurrently

• Excellent communication and stakeholder management skills across both technical and non-technical teams

• Experience in preparing security reports, metrics, and compliance documentation is desirable

• Preferred experience working within a PSIRT

• Preferred familiarity with regulatory reporting obligations and coordinated vulnerability disclosure programs

• Preferred experience with vulnerability management automation, DevSecOps pipelines, SBOM tooling, or software composition analysis platforms

• Knowledge of cloud, desktop, SaaS, embedded, or industrial control system products

• Understanding of penetration testing

• Previous experience with bug bounty platforms is an added advantage


🏝️ Benefits

• Competitive salary and performance-based bonuses

• Comprehensive health, dental, and vision insurance plans

• Opportunities for professional development and career advancement

• Flexible working hours and a supportive work environment

People also viewed

iFood6 days ago

Cybersecurity Incident Response Analyst – Mid-Level

BR flagBrazil OnlyFull-timeIncident Response Analyst
ApplyView job
SophosJul 4

Incident Response Analyst 1

AU flagAustralia OnlyFull-timeIncident Response Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers