Apply now »

EY-Cybersecurity-Vulnerability Management And Cybersecurity Asset Management-Manager

Location:  Kochi
Other locations:  Anywhere in Country
Salary: Competitive
Date:  Sep 28, 2026

Job description

Requisition ID:  1746189

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

EY – Cybersecurity Manager, Vulnerability Management & Cybersecurity Asset Management

Overview

As a Manager in EY’s Cybersecurity practice, you will play a key role in delivering Enterprise Vulnerability Management, Security Exposure Management, Cybersecurity Asset Management, Policy Compliance, and Security Awareness services across multiple client environments. We are seeking cybersecurity professionals with expertise in vulnerability identification, risk assessment, remediation governance, asset discovery, compliance monitoring, human risk reduction, and security posture management using industry-leading platforms.

The role involves administration, optimization, and operation of vulnerability and exposure management platforms such as Qualys VMDR, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, CrowdStrike Falcon Exposure Management, Wiz, Orca Security, and Greenbone/OpenVAS. It also includes leading security awareness and phishing-simulation programs using platforms such as Proofpoint Security Awareness Training, KnowBe4, Microsoft Attack Simulation Training, Mimecast Awareness Training, and SANS Security Awareness. The successful candidate will work closely with security, infrastructure, cloud, application, teams to drive risk reduction and improve cyber resilience.

 

The Opportunity

We are seeking cybersecurity professionals with 12+ years of experience in Vulnerability Management, Cybersecurity Asset Management, Security Operations, Exposure Management, or Cybersecurity Consulting.

The ideal candidate will possess strong experience in vulnerability lifecycle management, security risk analysis, asset inventory management, compliance reporting, and stakeholder engagement while supporting enterprise-wide security improvement initiatives.

 

Key Responsibilities

 

Vulnerability Management Operations

  • Administer and manage enterprise vulnerability and exposure management solutions, such us Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, CrowdStrike Falcon Exposure Management, Wiz, Orca Security, and Greenbone/OpenVAS, across multiple client environments.
  • Perform internal, external, authenticated, and unauthenticated vulnerability assessments.
  • Configure and manage vulnerability scanning schedules, scan profiles, and scanning appliances.
  • Analyze vulnerability findings and assess potential business and security risks.
  • Perform vulnerability validation, prioritization, and risk-based remediation recommendations.
  • Track remediation activities and validate vulnerability closure.
  • Support vulnerability exception and risk acceptance processes.
  • Develop and maintain vulnerability management dashboards, reports, and metrics.
  • Collaborate with infrastructure, cloud, and application teams to drive timely remediation activities.
  • Support major vulnerability response efforts related to critical CVEs and emerging threats.

 

Cybersecurity Asset Management (CSAM)

  • Administer Qualys CyberSecurity Asset Management capabilities.
  • Maintain accurate visibility of enterprise assets across on-premises, cloud, and hybrid environments.
  • Monitor asset discovery activities and improve inventory completeness.
  • Identify unmanaged, unauthorized, and unknown assets.
  • Perform asset classification and criticality assessments.
  • Support asset ownership validation and governance processes.
  • Generate asset inventory reports and security posture metrics.
  • Collaborate with asset owners and technology teams to improve inventory accuracy.

 

Policy Compliance Management

  • Administer Qualys Policy Compliance modules and compliance controls.
  • Configure compliance policies aligned with regulatory, industry, and organizational requirements.
  • Conduct compliance assessments for servers, endpoints, databases, and network devices.
  • Analyze compliance gaps and provide actionable remediation recommendations.
  • Support security baseline validation and configuration assessments.
  • Produce compliance scorecards and executive reporting.
  • Assist clients in maintaining continuous compliance monitoring programs.

 

Vulnerability Governance & Risk Management

  • Support enterprise vulnerability management governance frameworks.
  • Facilitate remediation review meetings with technology stakeholders.
  • Monitor SLA compliance and remediation performance metrics.
  • Develop risk-based prioritization models for vulnerabilities and assets.
  • Track Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs).
  • Support audit activities and regulatory compliance requirements.
  • Maintain vulnerability management documentation, procedures, and operational runbooks.
  • Contribute to continuous improvement initiatives within the vulnerability management program.

 

Security Operations & Stakeholder Engagement

  • Perform vulnerability trend analysis and reporting.
  • Support security assessments and cyber risk reviews.
  • Engage with IT, security, cloud, and application teams to facilitate risk remediation.
  • Assist in responding to security incidents involving vulnerable assets.
  • Support executive reporting and management presentations.
  • Participate in service reviews and performance reporting activities.
  • Contribute to automation and process optimization initiatives.

 

Security Awareness & Human Risk Management

  • Design, operate, and continuously improve enterprise security awareness and human risk management programs.
  • Administer platforms such as Proofpoint Security Awareness Training, KnowBe4, Microsoft Attack Simulation Training, Mimecast Awareness Training, and SANS Security Awareness.
  • Plan and execute phishing, smishing, vishing, and social-engineering simulations using role-based and risk-based campaigns.
  • Develop awareness content covering phishing, business email compromise, password security, data protection, acceptable use, remote working, insider risk, and emerging AI-enabled threats.
  • Define and monitor metrics including completion rate, simulation failure rate, repeat susceptibility, reporting rate, and mean time to report.
  • Coordinate targeted training for high-risk users, privileged users, executives, developers, new joiners, and third parties.
  • Collaborate with HR, communications, legal, privacy, compliance, and security operations teams to align awareness initiatives with organizational policies and threat trends.
  • Prepare campaign dashboards, audit evidence, executive reporting, and improvement plans based on awareness and user-risk outcomes.

 

Skills and Attributes for Success

  • Strong understanding of Vulnerability Management and Exposure Management programs.
  • Deep knowledge of vulnerability assessment methodologies and remediation practices.
  • Experience with Cybersecurity Asset Management and asset discovery technologies.
  • Experience with multiple vulnerability and exposure management technologies across endpoint, network, cloud, container, web application, and external attack surface environments.
  • Understanding of security awareness, phishing simulation, behavioral risk indicators, role-based learning, and program effectiveness measurement.
  • Understanding of CVSS, CISA KEV, risk-based prioritization, and threat intelligence integration.
  • Strong knowledge of operating systems, networks, cloud platforms, and enterprise infrastructure.
  • Knowledge of compliance frameworks such as CIS Benchmarks, NIST CSF, ISO 27001, PCI-DSS, and regulatory requirements.
  • Strong analytical, reporting, and problem-solving skills.
  • Excellent communication and stakeholder management capabilities.
  • Ability to manage multiple client environments and remediation programs simultaneously.

 

To Qualify for the Role, You Must Have

  • B. Tech or M. Tech in Cybersecurity, Computer Science, Information Security, or related disciplines.
  • 12+ years of relevant experience in Vulnerability Management, Asset Management, Security Operations, or Cybersecurity Consulting.
  • Hands-on experience with:
    • Qualys VMDR, Policy Compliance, CyberSecurity Asset Management, and TotalCloud
    • Tenable Vulnerability Management, Tenable One, Nessus, Tenable Security Center, and Tenable Cloud Security
    • Rapid7 InsightVM, Nexpose, and InsightCloudSec
    • Microsoft Defender Vulnerability Management and Microsoft Defender for Cloud
    • CrowdStrike Falcon Exposure Management, Spotlight, and Falcon Cloud Security
    • Wiz, Orca Security, Palo Alto Prisma Cloud, Greenbone/OpenVAS, Nucleus, and Vulcan Cyber
    • Proofpoint Security Awareness Training, KnowBe4, Microsoft Attack Simulation Training, Mimecast Awareness Training, and SANS Security Awareness
    • ServiceNow Vulnerability Response, Jira, Power BI, Splunk, and APIs for workflow integration, orchestration, reporting, and automation
  • Strong understanding of vulnerability scanning technologies and remediation processes.
  • Experience working with enterprise infrastructure, cloud environments, and security operations teams.
  • Knowledge of vulnerability intelligence, CVE management, and risk assessment methodologies.
  • Experience in vulnerability reporting and executive dashboard preparation.
  • Strong verbal and written communication skills.
  • Experience with scripting or automation using Python, PowerShell, SQL, or APIs is a plus.

 

What We Look For

Professionals who are passionate about cybersecurity risk reduction and vulnerability management, possess strong analytical and technical capabilities, and demonstrate a proactive approach to identifying and mitigating security risks. Successful candidates will be highly collaborative, detail-oriented, customer-focused, and committed to delivering high-quality cybersecurity services while helping organizations improve their security posture and resilience.

 

EY | Building a better working world 


 
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  


 
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  


 
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Apply now »