Cyber Security Analyst
Role:Vulnerability Management Analyst – Qualys VM
Location: London/Bristol/Norwich (any- hybrid role)
Experience in pure hands‐on Vulnerability Management experience mandatory
Role Summary
We are looking for a hands‐on Vulnerability Management professional with strong operational experience on Qualys VM / VMDR to support BAU vulnerability operations for large enterprise environments.
The role is execution‐heavy and requires day‐to‐day ownership of scanning, validation, remediation tracking, reporting, and stakeholder coordination, rather than advisory or governance‐only work.
Key Responsibilities
Qualys VM Operations
- Perform authenticated and unauthenticated vulnerability scans using Qualys VM / VMDR across:
- Servers (Windows & Linux)
- Network devices
- Endpoints
- Cloud workloads (AWS / Azure)
- Manage asset discovery, tagging, and grouping within Qualys.
- Configure and maintain scan profiles, schedules, and exclusions based on environment and risk.
- Troubleshoot scan failures, authentication issues, and agent‐related problems.
Vulnerability Analysis & Validation
- Analise Qualys scan results and:
- Validate true positives
- Identify and eliminate false positives
- Apply risk‐based prioritization using CVSS, exploitability, asset criticality, and threat context.
- Track zero‐day and high‐severity vulnerabilities and support expedited remediation.
Remediation & Stakeholder Coordination
- Create, track, and manage remediation tickets using:
- ServiceNow / Jira or equivalent ITSM tools
- Work closely with:
- Infrastructure teams
- Application owners
- Cloud and platform teams
- Follow up on remediation SLAs and perform re‐scans to confirm closure.
Reporting & BAU Governance
- Prepare and publish:
- Weekly / Monthly vulnerability reports
- Executive summaries and dashboards
- Support compliance and audit requirements (ISO 27001, CIS benchmarks, etc.).
- Maintain SOPs, runbooks, and BAU documentation.
Mandatory Skills & Experience
- Strong hands‐on experience with Qualys VM / Qualys VMDR (mandatory)
- Solid understanding of:
- Vulnerability lifecycle (identify → assess → remediate → validate)
- CVE, CVSS, exploitability, patching concepts
- Experience with:
- Windows & Linux OS
- Networking fundamentals (TCP/IP, ports, firewalls)
- Exposure to cloud vulnerability scanning (AWS / Azure) is highly desirable.
- Qualys VM / VMDR
- ITSM tools: ServiceNow / Jira
- Supporting tools: Nessus / Rapid7 (good to have, not mandatory)
- Reporting tools: Excel / Power BI (basic to intermediate)
Wipro is an exciting organization to work for. We ranked as a “Top Employer” as part of the Top Employer Institute annual listings. We were assessed on several key HR practices including Diversity and Inclusion.
Benefits: You will receive a competitive salary, a generous benefits package, training, and development, as well as an exciting career within a fast paced and dynamic business. Your benefits include
- Contributory pension of up to 5%
- Extra holiday purchase
- 4x life insurance policy
- Private medical insurance (50)
Equal Opportunities:
Wipro is an advocate for positive change and conscious inclusion. As a global employer, we strive to create a diverse Wipro family by remaining committed to the development of our culture, diversity, equality, and inclusion in the workplace. All applicants welcome.