CRISIL Ltd

Manager - Vulnerability Assessment and Penetration Testing

CRISIL Ltd
Hyderabad
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 8 yearsMin. 8 years

Job Description

Manager – VA / VAPT

Department

None

Job Description

Job Description: Manager – VA / VAPT (Vulnerability Assessment & Penetration Testing)

**Location:**  Mumbai
**Department:** Information Security
**Reports To:** Manager– Application Security

Role Overview

The Manager / Assistant Manager – VA/VAPT will be responsible for overseeing the vulnerability assessment and penetration testing program across the organization. The role includes managing external vendors performing security testing, ensuring regulatory and internal policy compliance, handling day-to-day BAU activities, and preparing reports and dashboards for senior management and regulatory bodies.

The ideal candidate will have hands-on experience in vulnerability management tools, application security scanners, and a strong understanding of the regulatory landscape in BFSI.

Key Responsibilities

1. Vulnerability Management & Testing Oversight

  • Coordinate and manage end-to-end VA/VAPT activities conducted by external vendors.
  • Review and validate test scopes, methodologies, and deliverables.
  • Track remediation progress and coordinate with application/infrastructure teams for closure of findings.
  • Ensure testing frequency aligns with regulatory, internal, and client requirements.
  • Validate false positives and maintain quality of vulnerability reports.

2. Compliance & Regulatory Alignment

  • Ensure compliance with RBI, CERT-In, PCI-DSS, and other regulatory security testing mandates.
  • Maintain audit-ready evidence and documentation for all VA/VAPT-related activities.
  • Support internal and external audits (including from parent company, clients, and regulators).
  • Track and report on compliance posture related to vulnerability management.

3. Reporting & Metrics

  • Develop and maintain vulnerability management dashboards and reports for CISO and management.
  • Generate periodic risk summaries, trend analysis, and KPI/KRI reports.
  • Maintain trackers for testing schedule, remediation status, and exceptions.

4. Process & Governance

  • Define and continuously improve the VA/VAPT governance process, including scope definition, testing frequency, and remediation SLAs.
  • Manage change requests and deviations in coordination with vendors and internal teams.
  • Ensure adherence to secure SDLC principles and coordinate with DevSecOps initiatives.

5. Tools & Technical Proficiency

  • Utilize and manage tools such as Qualys, OpenText Fortify, WebInspect, and Burp Suite Professional for internal scans and validation.
  • Correlate and prioritize vulnerabilities based on criticality, exploitability, and asset sensitivity.
  • Support automation and integration of vulnerability data into enterprise dashboards or ticketing systems.

6. Stakeholder Management

  • Collaborate with IT, applications, cloud, and business teams to ensure timely risk mitigation.
  • Act as primary liaison with VA/PT vendors and ensure SLA adherence.
  • Present security posture updates to senior management and CISO.

Qualifications & Experience

Position

Experience Range

Educational Qualification

Certifications (Preferred)

Manager – VA/VAPT

8–12 years total experience with 3+ years in vendor or team management

B.Tech / B.E. / M.Tech / MCA in Computer Science, IT, or related field

CEH, OSCP, CISSP, CISA, or equivalent

 

Key Skills & Competencies

  • Strong understanding of web, mobile, and infrastructure vulnerabilities and mitigation techniques.
  • Hands-on exposure to Qualys, Fortify, WebInspect, and Burp Suite Professional.
  • Familiarity with regulatory frameworks such as RBI, CERT-In, PCI-DSS, ISO 27001.
  • Strong analytical, documentation, and presentation skills.
  • Ability to handle multiple stakeholders and manage testing across multiple business lines.
  • Good understanding of secure SDLC and DevSecOps principles.

Soft Skills

  • Excellent communication and coordination skills.
  • Strong reporting and analytical mindset.
  • Ability to work under pressure and manage tight timelines.
  • Proven vendor and stakeholder management skills.

Open Positions

1

Mandatory Skills

Vapt,Vulnerability Assessment,Vulnerability Management,Penetration Testing,Cyber Security

Education Qualification

B.E

Experience

6 to 12 years

Job role

Work location
Work locationHyderabad, Telangana, India
Department
DepartmentIT & Information Security
Role / Category
Role / CategoryIT Security
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 8 years

About company

Name
NameCRISIL Ltd
Job posted by CRISIL Ltd

Similar jobs you can apply for

Hardware & Network Engineer
Error Kart

Server Engineer

Error Kart
Kukatpally, Hyderabad
₹18,000 - ₹30,000
Field Job
Full Time
Min. 1 year
Basic English
Medplus

Technical Support Engineer (Field)

Medplus
Moosapet, Hyderabad
₹15,000 - ₹22,000
Work from Office
Full Time
Any experience
Basic English
Suchirindia

System Administrator

Suchirindia
Banjara Hills, Hyderabad
₹35,000 - ₹40,000
Work from Office
Full Time
Min. 5 years
Good (Intermediate / Advanced) English
Concord Drugs

Maintenance Engineer

Concord Drugs
Turkayamjal, Hyderabad
₹20,000 - ₹30,000
Work from Office
Full Time
Min. 3 years
Basic English
Kexlin Software Solutions Private Limited

Telecaller

Kexlin Software Solutions Private Limited
Madhapur, Hyderabad
₹10,000 - ₹15,000
Work from Office
Full Time
Min. 1 year
Basic English

Graduate Engineer Trainee

Orissa Hydel Power Balimela Ltd.
Khairatabad, Hyderabad
₹25,000 - ₹30,000
Work from Office
Full Time
Freshers only
Good (Intermediate / Advanced) English

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 8 to 12 years are eligible to apply for this job. You can apply for more jobs in Hyderabad to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Hyderabad at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Hyderabad . Through apna, you can find jobs in 64 cities across India. Join NOW!