Senior Vulnerability Management Engineer
We are a $13+ billion global technology company, home to more than 224,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud, and AI, powered by a broad portfolio of technology services and products.
HCLTech is a globally recognized leader in the Tech and IT industry, but we’ve never forgotten the startup mindset that got us here. We’ve always approached our work with an idea-first attitude because every one of our accomplishments —no matter how big or small —can be traced back to an idea’s single spark.
It’s that spark —that inner drive —that sets our people apart from our competitors. It enables us not just to pull off game-changing feat after game-changing feat but to better our world in the process. We want you to find your spark. Because that’s what drives you to be better, be more and ultimately, be more fulfilled.
To learn more about how we can supercharge progress for you, visit www.hcltech.com
Job Title: Senior Vulnerability Management Engineer
Location: London, UK (Hybrid mode at client location)
Experience: 3 – 6 years in vulnerability management / information security
ROLE SUMMARY
The L2 Senior Vulnerability Management Engineer owns the organisation's end-to-end vulnerability management programme, spanning EUC, Data Center, Network, and Application Infrastructure domains. The role is responsible for scanner architecture and tuning, risk-based prioritisation, integration with patch management and SOC functions, automation of VM workflows, and executive reporting. The engineer acts as the primary SME for vulnerability risk decisions and drives continuous improvement of the VM programme.
KEY RESPONSIBILITIES
• Own and operate the enterprise vulnerability management programme across all technology domains (endpoints, servers, network devices, web applications, cloud).
• Design and maintain scan policies, asset groups, and scanning schedules in Qualys VMDR / Tenable Security Centre / Rapid7 InsightVM to ensure full coverage.
• Perform risk-based vulnerability prioritisation: correlate CVSS scores with asset criticality, exposure, threat intelligence (EPSS, CISA KEV), and business context.
• Translate vulnerability findings into actionable remediation tasks for patch management teams across EUC, Data Center, Networks, and Application Infra; define acceptance criteria for closure.
• Define, publish, and enforce the VM SLA policy; escalate breaches to asset owners and management.
• Lead the vulnerability exception and risk acceptance process: assess compensating controls, document residual risk, and obtain formal sign-off.
• Integrate VM tooling with SIEM (Splunk, Microsoft Sentinel), ITSM (ServiceNow VR module), and CMDB for automated ticket creation and asset correlation.
• Automate vulnerability reporting and remediation tracking using Python, REST APIs (Qualys/Tenable API), or ServiceNow workflows.
• Conduct threat-informed vulnerability analysis: monitor NVD, CISA KEV, vendor security advisories, and threat intelligence feeds to identify exploitable CVEs requiring emergency response.
• Lead response to zero-day vulnerabilities: assess impact across the estate, co-ordinate emergency patching or compensating controls, and communicate status to security leadership.
• Own web application vulnerability management: integrate DAST/SAST findings (Burp Suite, Checkmarx, Veracode) into the unified VM programme.
• Manage cloud vulnerability posture: AWS Inspector, Microsoft Defender for Cloud, or Prisma Cloud for hybrid cloud environments.
• Produce monthly VM programme dashboards, KPIs, and trend analysis for CISO and management review.
• Act as L2 escalation for L1 analysts; mentor team members and review scan configurations and reports.
• Lead or support internal VM audits and contribute to ISO 27001, SOC 2, or regulatory compliance evidence.
TECHNICAL SKILLS & KNOWLEDGE
• Deep expertise in enterprise VM platforms: Qualys VMDR (including TruRisk), Tenable Security Centre / Tenable.io, or Rapid7 InsightVM.
• Strong understanding of CVE/CVSS v3.1 scoring, EPSS (Exploit Prediction Scoring), and CISA Known Exploited Vulnerabilities (KEV) catalogue.
• Experience with web application scanning: Burp Suite Pro, OWASP ZAP, Tenable Web App Scanning, or HCL AppScan.
• Cloud security posture: AWS Inspector, Microsoft Defender for Cloud, Prisma Cloud, or Wiz.
• Container and image vulnerability scanning: Trivy, Snyk, Anchore, or Aqua Security.
• Automation and API integration: Python scripting, REST API calls to Qualys/Tenable/Rapid7; ServiceNow VR module configuration.
• SIEM integration: Splunk, Microsoft Sentinel – correlating vulnerability data with threat events.
• CMDB-driven asset correlation: ServiceNow CMDB, ensuring VM data reflects accurate asset inventory.
• Network and infrastructure knowledge sufficient to assess vulnerability exploitability (firewall rules, segmentation, exposure).
• Patch management workflow knowledge across Windows (SCCM/Intune), Linux (Satellite/Ansible), and network devices – to drive effective remediation co-ordination.
• Threat intelligence: experience consuming TI feeds (MISP, OpenCTI, commercial TI platforms) to contextualise vulnerabilities.
• Familiarity with compliance frameworks: ISO 27001, NIST CSF, CIS Controls, PCI DSS, SOC 2 – as they relate to vulnerability management.
SOFT SKILLS & COMPETENCIES
• Strong risk communication skills – translates technical vulnerability data into business risk language for senior stakeholders.
• Excellent programme management skills to co-ordinate remediation across multiple infrastructure teams.
• Analytical and data-driven – builds metrics and trends to demonstrate programme maturity.
• Collaborative – works effectively with patch teams, SOC analysts, application owners, and compliance.
• Proactive threat awareness – stays current with the evolving CVE landscape and emerging exploits.
• Clear and structured documentation – programme policies, exception records, and executive reports.
PREFERRED CERTIFICATIONS
• Qualys Certified Specialist – VMDR / TruRisk
• Tenable Certified Security Engineer (TCSE)
• Certified Information Systems Security Professional (CISSP) – or working towards
• Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP)
• CompTIA CySA+ or PenTest+
• GIAC Vulnerability Assessor (GEVA)
• Microsoft Certified: Security Operations Analyst (SC-200) – advantageous for Azure environments
• ITIL 4 Foundation or Managing Professional
Benefits
- A supportive, diverse, and global team with a brilliant culture.
- Competitive compensation and benefits that includes vacation per year, various insurances like Term life and Business Travel insurance. These are apart from the statutory benefits applicable in the country. Employee benefits are regulated by an internal policy that contains full details regarding the entitlement and conditions for the benefits as per the law of the land.
- Great opportunities to make the role your own, upskill yourself and get involved with exciting projects.
- Total Wellbeing is our focus. Alongside your professional excellence, you join the likeminded colleagues to create a larger impact within the company and society at large in your chosen area of passion - CSR Council, Diversity Council, Women Connect, Sparks – Engagement Champion to name a few.
- To know more about us visit – www.hcltech.com
- For more information on how we process your personal data, please refer to HCLTech’s Candidate Data Privacy Notice.