The Senior Solution Architect – Vulnerability Management is responsible for defining, designing, and governing the enterprise vulnerability management architecture across infrastructure, applications, cloud, container, and emerging technology landscapes.
This role bridges security strategy, engineering execution, and business risk, ensuring vulnerabilities are continuously identified, prioritized, remediated, and reported in alignment with regulatory, risk, and resilience objectives.
The role partners closely with Cyber Defense, Application Security, Cloud Security, IT Infrastructure, DevSecOps, and Risk teams to embed vulnerability management as a core security capability, not just a scanning function
Strategy & Architecture : Define the enterprise vulnerability management reference architecture covering: ,Infrastructure (on-prem, cloud, hybrid) ,Applications (SAST, DAST, SCA) ,Containers, Kubernetes, serverless ,Network, endpoint, databases, and middleware ,Establish capability roadmaps aligned with Zero Trust, Secure SDLC, and Continuous Controls Monitoring. Ensure alignment with enterprise security architecture, threat models, and risk frameworks.
Solution Design & Engineering Leadership : Design scalable solutions for: Vulnerability discovery, validation, and de-duplication .Risk-based prioritization (CVSS + threat intelligence + asset criticality) .Remediation orchestration and automation .Drive tool integrations with: CMDB / asset inventory, CI/CD pipelines ,Ticketing and workflow systems ,Cloud-native services and APIs .Define secure-by-design patterns for development and infrastructure teams.
DevSecOps & Automation :Embed vulnerability scanning into CI/CD pipelines with shift-left and shift-right controls. Enable policy-as-code and automated guardrails. Reduce false positives and noise through contextual analysis and tuning. Promote remediation automation using SOAR, scripts, and infrastructure-as-code.
Governance, Risk & Compliance: Define vulnerability management standards, policies, and architectural guardrails.Map vulnerability management controls to regulatory and audit requirements. Support risk acceptance, exception handling, and executive reporting. Partner with Risk and Audit teams to demonstrate control effectiveness.
Stakeholder Engagement & Advisory : Act as a trusted security advisor to engineering, platform, and business teams. Translate technical vulnerabilities into business risk language for leadership. Influence architecture decisions without direct authority Mentor security engineers and architects.
10+ years in Cyber Security / Security Architecture, with deep focus on VulnerabilityManagement.
Strong hands-on knowledge of:
Infrastructure and application vulnerability scanning
Secure SDLC and DevSecOps practices
Cloud security (IaaS, PaaS, containers, Kubernetes)
CVE, CVSS, CWE, OWASP Top 10
Experience integrating vulnerability tools with:
CI/CD pipelines
CMDB, ticketing, and workflow platforms
Proven experience creating enterprise-scale security architectures.
Ability to balance risk reduction, usability, scalability, and cost.
Strong understanding of threat modeling and attack paths.
Experience designing risk-based prioritization frameworks.

HCLTech is a global technology company, home to more than 226,600 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending September 2025 totaled $14.2 billion. To learn how we can supercharge progress for you, visit hcltech.com.