Data Analyst Vulnerability Management Analyst
Dear Aspirant!
We empower our people to stay resilient and relevant in a constantly changing world. We’re looking for people who are always searching for creative ways to grow and learn. People who want to make a real impact, now and in the future. Does that sound like you? Then it seems like you’d make a great addition to our vibrant international team.
We are looking for: Data Analyst - Vulnerability Management Analyst
You’ll make an impact by:
- Review vulnerability scan results from enterprise vulnerability management tools and identify affected assets and systems.
- Analyze vulnerabilities using severity, exploitability, asset criticality, exposure, business impact, and available compensating controls.
- Classify and prioritize vulnerabilities using defined risk-based criteria and organizational remediation SLAs.
- Create, assign, and track remediation tickets with clear technical details, affected assets, severity, remediation guidance, and due dates.
- Coordinate with infrastructure, application, cloud, network, and product teams to drive remediation activities.
- Track remediation progress, overdue findings, aging, exceptions, and recurring vulnerabilities.
- Escalate critical and high-risk vulnerabilities and blockers to appropriate stakeholders.
- Validate remediation evidence through rescans, configuration checks, patch verification, or other approved validation methods.
- Confirm vulnerability closure and maintain accurate records for audit and governance purposes.
- Generate weekly and periodic vulnerability management reports covering risk posture, SLA compliance, backlog, aging, and remediation trends.
- Identify recurring vulnerability patterns and recommend preventive actions and process improvements.
- Identify appropriate compensating controls for vulnerabilities that cannot be patched immediately because of legacy systems, vendor restrictions, safety requirements, or operational dependencies.
- Coordinate OT vulnerability remediation with asset owners, engineering teams, vendors, and plant/utility operations while considering operational and availability constraints.
- Review and analyze vulnerability scan results for both IT and OT assets, including SCADA, substation, utility, HMI, PLC, RTU, and industrial control environments.
Use your skills to move the world forward!
- B.E./B.Tech./MCA/M.Sc. in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- 6–8 years of experience in vulnerability management, security operations, infrastructure security, or a related cybersecurity domain.
- Experience working with enterprise-scale vulnerability assessment and remediation processes.
- Experience performing vulnerability management for OT/ICS environments such as SCADA, substations, utilities, HMI, PLC, RTU, DCS, or industrial control systems.
- Understanding of OT-specific vulnerability management challenges, including legacy assets, vendor-managed systems, passive scanning, maintenance windows, availability constraints, and compensating controls.
- Knowledge of industrial protocols and technologies such as IEC 61850, Modbus, DNP3, OPC/OPC UA, PROFINET, Ethernet/IP, or similar is desirable.
- Knowledge of IEC 62443 and OT/critical-infrastructure security practices is preferred.
- Strong understanding of vulnerability management lifecycle and risk-based vulnerability prioritization.
- Hands-on experience with vulnerability scanners such as Tenable, Qualys, Wiz, Rapid7, or equivalent.
- Good understanding of CVE, CWE, CVSS, exploitability, remediation, and compensating controls.
- Working knowledge of Windows and Linux operating systems, network devices, databases, cloud infrastructure, and enterprise applications.
- Ability to interpret vulnerability scan results and distinguish false positives, accepted risks, and actionable findings.
- Experience with ticketing/workflow tools such as ServiceNow, Jira, or equivalent.
- Basic scripting or automation knowledge using Python, PowerShell, Bash, or similar is desirable.
- Good analytical, documentation, communication, and stakeholder coordination skills.
- Certifications such as Security+, CEH, CySA+, GIAC, or equivalent are preferred.
- Preferred Certifications: Security+, CySA+, CEH, GIAC, or equivalent vulnerability/security certifications.
Create a better #TomorrowWithUs!
This role is based in Chennai, where you’ll get the chance to work with teams impacting entire cities, countries - and the shape of things to come.
We value your unique identity and perspective and are fully committed to providing equitable opportunities and building a workplace that reflects the diversity of society. Come bring your authentic self and create a better tomorrow with us.
We’re Siemens. A collection of over 312,000 minds building the future, one day at a time in over 200 countries. We're dedicated to equality, and we encourage applications that reflect the diversity of the communities we work in. All employment decisions at Siemens are based on qualifications, merit and business need. Bring your curiosity and imagination and help us shape tomorrow.
Find out more about Siemens careers at: www.siemens.com/careers
Find out more about the Digital world of Siemens here: www.siemens.com/careers/digitalminds

