The Vulnerability Management Analyst is responsible for managing the end‑to‑end vulnerability lifecycle across enterprise environments using Qualys VMDR and External Attack Surface Management (EASM). The role focuses on identifying, prioritizing, and driving remediation of vulnerabilities across on‑premise, cloud, and internet‑facing assets, while ensuring compliance with defined SLAs and governance standards.rnThis position plays a critical role in external attack surface visibility, discovering unknown or unmanaged internet‑exposed assets, tracking ownership, and identifying exposure risks such as open ports, misconfigurations, expired certificates, and typo‑squatted domains. The analyst works closely with infrastructure, cloud, application, and business teams to assign accountability, validate remediation, manage exceptions, and reduce overall exposure risk.rnThe role also produces clear technical and executive‑level reports, communicates security risks effectively to stakeholders, and supports continuous attack surface reduction and vulnerability governance initiatives. Strong hands‑on expertise in Qualys VMDR, EASM, vulnerability prioritization, and stakeholder coordination is essential for success in this client‑facing, security‑critical role.
Manage end-to-end vulnerability lifecycle using Qualys VMDRrn• Configure and execute authenticated/unauthenticated scans across on‑prem, cloud, and external assetsrn• Prioritize vulnerabilities using risk-based scoring (TruRisk/CVSS/exploitability)rn• Coordinate remediation with infrastructure, cloud, and application teamsrn• Validate fixes, manage exceptions, and ensure SLA adherencern• Produce clear technical and executive-level reportsrn• Operate Qualys EASM to discover and track internet-facing/unknown assetsrn• Configure and maintain authorized domains, sub‑domains, and IP ranges in Qualys EASM to ensure accurate external attack surface discoveryrn• Identify misconfigurations such as open ports, expired certificates, typo squatted domain and exposed servicesrn• Track asset ownership and work with business/IT teams to assign accountability for external assetsrn• Ensure adherence to defined remediation SLAs and governance requirements for external exposure risksrn• Support attack surface reduction initiatives through remediation tracking and exposure trend analysisrn
Must have strong knowledge of External Attack Surface Management, how to track down ownership for EASM finding and ensure closure.rn• Strong hands-on experience with:rno Qualys VMDR (asset inventory, scanning, prioritization, reporting)rno Authenticated scan troubleshooting and false-positive analysisrn• Solid understanding of vulnerability governance, remediation tracking, and metricsrn• Experience with ITSM tools (e.g., ServiceNow)rn• Ability to communicate security risks to technical and business stakeholdersrnGood to Havern• Qualys certificationsrn• Exposure to threat intelligence feedsrn
Soft Skillsrn• Shall have good verbal/written communication skillsrn• Good problem-solving capability, team player, good communication and documentation skills.rn• Should have client facing technical analysis report representation skillrn

HCLTech is a global technology company, home to more than 226,600 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending September 2025 totaled $14.2 billion. To learn how we can supercharge progress for you, visit hcltech.com.