
At Virtusa, we combinelogic,creativity,andcuriosity to solve from the inside out. Who we are. In an ever-evolving digital landscape, businesses need a partner to help them solve complex challenges and navigate the environment of today and tomorrow. Virtusa is that partner.
The Head of Threat and Vulnerability Management will lead the organizations efforts to identify, assess, and mitigate security threats and vulnerabilities. This role will be responsible for overseeing internal and external penetration testing (PT), red teaming exercises, vulnerability management, system hardening, and application and API security. The ideal candidate will have a strong technical background, leadership experience, and a strategic vision for improving the organization s security posture.
Key
1. Leadership and Strategy
Develop and implement a comprehensive threat and vulnerability management strategy.
Lead and manage a team of security professionals, providing guidance, mentorship, and performance evaluations.
Collaborate with other departments to integrate security best practices into all business processes.
2. Penetration Testing and Red Teaming
Plan, execute, and oversee internal and external penetration tests and red team exercises.
Identify vulnerabilities and weaknesses in systems, networks, and applications.
Develop and present detailed reports on findings, including risk assessments and recommendations for remediation.
3. Vulnerability Management
Establish and maintain a robust vulnerability management program.
Identify and reconcile the scope of vulnerability assessment
Conduct regular vulnerability assessments and scans.
Track and prioritize vulnerabilities for remediation based on risk and impact.
Work with IT and development teams to ensure timely and effective vulnerability remediation.
Ensure 100% coverage of assets for vulnerability assessment
4. System Hardening
Develop and implement system hardening guidelines and best practices.
Ensure all systems are configured securely and in compliance with industry standards and regulatory requirements.
Conduct regular audits to verify compliance and identify areas for improvement.
5. Application and API Security
Lead efforts to secure applications and APIs throughout the development lifecycle.
Collaborate with development teams to integrate security into the software development process.
Conduct code reviews, security testing, and vulnerability assessments of applications and APIs.
Reconcile and ensure 100% coverage of applications and APIs for vulnerability assessment
6. Third party Cyber Risk management
Establish and maintain a robust vulnerability remediation identified by third parties
Lead efforts to secure organisation external interface and support mitigate risks from the TPRM view
Ensure complete coverage of Organisation external IT infrastructure by these third party scanners
Qualifications
Bachelors degree in computer science, Information Security, or a related field. Master s degree preferred.
Minimum of 15-18 years of experience in information security, with at least 5 years in a leadership role.
Strong technical expertise in penetration testing, red teaming, vulnerability management, system hardening, and application security.
Relevant certifications such as CISSP, CISM, OSCP, CEH, or similar.
Excellent understanding of security frameworks and standards (e.g., NIST, ISO 27001, OWASP).
Proven ability to lead and manage a team of security professionals.
Strong analytical, problem-solving, and decision-making skills.
Excellent communication and interpersonal skills.
Preferred Skills
Experience with security tools and technologies (e.g., SIEM, IDS/IPS, vulnerability scanners, etc.).
Knowledge of regulatory requirements and industry standards (e.g., GDPR, HIPAA, PCI-DSS).
Familiarity with cloud security, container security and DevSecOps practices.
NA
Similar jobs
Were back with another edition of our hackathon hiring event: Code Rush 2025 - Your Gateway for a Career at Indium. Not Disclosed 12th April , 9.30 AM - 6.00 PM Indium Pvt Ltd, Bagmane Laurel, 502, 5th Floor, Southern Wing, Dr APJ Abdul Kalam Rd, C V Raman Nagar, Bengaluru, Karnataka 560093 Dear Candidate, We are Organizing a walk-in Drive at Bangalore Location. Please find details below: Skills... Expand Not Disclosed 15th February , 9.30 AM - 1.00 PM Walk in venue :Tata Consultancy Services Limited Global Axis, Gopalan Enterprises Pvt Ltd SEZ H Block, No. 152 (Sy No. 147,157 & 158), Hoody Village, EPIP Zone, (II Stage), Whitefield, K.R. Puram Hobli, Bengaluru - 560066, Karnataka NA NA We are seeking a Sr. Developer with 8 to 10 years of experience in AEM support engineering... Expand NA We are seeking a highly skilled Sr. Developer with 8 to 10 years of experience in AEM support... Expand NA We are seeking a Sr. Developer with 8 to 10 years of experience in AEM support engineering... Expand NA NA NA
This isnt your... Expand
Work closely with other engineers... Expand