Cyber Security Analyst-VM

Company: Wipro
Apply for the Cyber Security Analyst-VM
Location: Norwich
Job Description:

Overview

As a hands-on Vulnerability Management Analyst, you will own day-to-day vulnerability operations for large enterprise environments, focusing on Qualys VM/VMDR. You will perform scans, validate findings, drive remediation and report progress to stakeholders, ensuring compliance with security standards. You’ll collaborate with infrastructure, application, cloud teams and auditors to sustain audit readiness and continuous improvement. The role offers a practical, execution-focused path to strengthen our security posture in BAU operations.

Responsibilities

  • Operate authenticated and unauthenticated Qualys VM/VMDR scans across servers (Windows & Linux), network devices, endpoints, and cloud workloads
  • Manage asset discovery, tagging, grouping, and scan profiles/schedules; troubleshoot scan issues
  • Analyze scan results, validate true positives, and reduce false positives
  • Prioritize remediation using CVSS, exploitability, asset criticality, and threat context; track zero-day/high-severity vulnerabilities
  • Create and manage remediation tickets in ServiceNow/Jira; coordinate with infrastructure, app owners, and cloud teams; monitor SLAs and perform re-scans
  • Prepare weekly/monthly vulnerability reports and executive dashboards; support ISO 27001, CIS benchmarks; maintain SOPs and runbooks
  • Offer automation support via Qualys API integrations with ServiceNow/SIEM; basic scripting in Python/PowerShell/Bash to assist data handling
  • Ensure continuous compliance and audit readiness through documentation and cross-functional coordination

Key requirements

  • Strong hands-on experience with Qualys VM/VMDR (mandatory)
  • Knowledge of vulnerability lifecycle and CVE/CVSS concepts
  • Experience with Windows/Linux OS, networking fundamentals; cloud vulnerability scanning desirable
  • Experience with ITSM tools: ServiceNow/Jira; familiarity with Nessus/Rapid7 is a plus
  • Excellent stakeholder communication and ability to manage multiple remediation streams
  • BAU/Run operations mindset with a bias for action and compliance support
  • Strong operational ownership
  • Effective communication with technical and non-technical stakeholders
  • Capability to handle escalations and meet SLAs
  • Qualys VM/VMDR hands-on expertise
  • Vulnerability management lifecycle
  • Cloud vulnerability scanning (AWS/Azure)

…

Posted: September 14th, 2026