30 ago
|
Genpact
|
Guadalajara
30 ago
Genpact
Guadalajara
About the Company: Genpact (NYSE: G) is a global professional services and solutions firm delivering outcomes that shape the future. Our 125,000+ people across 30+ countries are driven by our innate curiosity, entrepreneurial agility, and desire to create lasting value for clients.
Powered by our purpose the relentless pursuit of a world that works better for people we serve and transform leading enterprises, including the Fortune Global 500, with our deep business and industry knowledge, digital operations services, and expertise in data, technology, and AI.
About the Role: Genpact is urgently looking for a strong Consultant for one of our precious clients in USA. If you are interested kindly share profile a
About the Company: Genpact (NYSE: G) is a general professional services and solutions firm delivering outcomes that shape the future. Our 125,000+ people across 30+ countries are driven by our innate curiosity, entrepreneurial agility, and desire to create lasting value for clients.
Powered by our purpose the relentless pursuit of a world that works better for people we serve and transform leading enterprises, including the Fortune Global 500, with our deep business and industry knowledge, digital operations services, and expertise in data, technology, and AI.
About the Role: Genpact is urgently looking for a strong Consultant for one of our precious clients in USA. If you are interested kindly share profile a
Title: Threat and Vulnerability Management Consultant
Location: Guadalajara, Mexico
Duration: Fulltime
Job Summary:
The Senior Security Analyst (TVM Operations) ensures the organization maintains a comprehensive and real-time view of its security posture. This operational role manages the daily execution of the Qualys platform, utilizing VMDR, CSAM, and EASM to detect vulnerabilities, discover unmanaged assets, and monitor our external attack surface.
You will not be patching systems yourself; rather, you will be the "source of truth" for partner teams. Your goal is to deliver accurate, actionable data into Jira, collaborate with System Administrators to prioritize fixes, and validate that remediation has occurred.
Who you are:[AO1]
- Operational Specialist: You enjoy the rhythm of daily operations—ensuring scans run, agents report, and data flows correctly.
- The "Radar Operator": You are vigilant about the External Attack Surface (EASM), spotting exposed services or forgotten subdomains before adversaries do.
- Collaborative Influencer: Since you do not apply the patches,
you rely on building strong relationships with IT partner teams to drive remediation action.
- Data Steward: You understand that a Vulnerability Management program is only as good as its asset inventory (CSAM), and you relentlessly chase down "unknown" assets.
- Ticket Master: You are comfortable working in Jira, ensuring that security findings don't get lost in the backlog.
Responsibilities include:
- Qualys Operations: Manage the daily health of the Qualys subscription, specifically VMDR (Vulnerability Management), CSAM (Cyber Security Asset Management), and EASM (External Attack Surface Management).
- Asset Discovery & Hygiene (CSAM): continuously monitor the network for unmanaged devices and unauthorized software. Work with IT to install agents or decommission shadow IT.
- External Exposure (EASM): Monitor the organization’s external footprint. Identify and alert on unexpected public-facing assets, open ports, or expired certificates.
- Vulnerability Remediation Management: Translate scan findings into actionable Jira tickets. Assign tasks to appropriate partner teams (Server, Network, Cloud) and participate in sprint planning/backlog reviews to advocate for security tasks.
- Remediation Verification: Execute validation scans (re-scans) once partner teams mark Jira tickets as "Resolved" to confirm the vulnerability is truly closed.
- Scanning Execution: Configure and schedule discovery and vulnerability scans. Manage scanner appliances and exclude lists to prevent operational disruption.
- False Positive Analysis: Review technical evidence provided by partner teams to validate "False Positive" or "Risk Acceptance" requests.
- Reporting & Metrics: Generate weekly operational reports on "Open Vulnerabilities vs. Closed," Remediation SLAs, and Agent Health.
- Agent Health: Troubleshoot Qualys Cloud Agents on endpoints that have stopped reporting or are failing to authenticate.
- Threat Triage: When high-profile vulnerabilities (e.g., Log4j, HTTP/2 Rapid Reset) are announced, use VMDR and CSAM to provide immediate impact assessments to leadership.
Experience you’ll need:
- Bachelor’s degree in information security, computer science, or equivalent operational experience.
- Qualys Power User: Proven operational experience with VMDR (running scans,
analyzing results).
- Asset Management Experience: Experience using Qualys CSAM or similar tools to reconcile asset inventories and identify "blind spots" in coverage.
- Attack Surface Knowledge: Experience with EASM concepts—understanding DNS, public IP ranges, and how to identify assets that shouldn't be on the internet.
- Jira Proficiency: Strong working knowledge of Jira for ticket management. Ability to use JQL (Jira Query Language) to search for issues and create dashboards.
- Partner Collaboration: A track record of successfully working with System Administrators and Dev Ops teams. You know how to "speak their language" to get patches prioritized.
- Network & OS Fundamentals: Sufficient knowledge of Windows, Linux, and Networking to help partner teams understand where a vulnerability is located and why it needs fixing.
- Troubleshooting Skills: Ability to diagnose why a scanner can't reach a host or why an agent is offline.
- Analytical Mindset: Ability to correlate an external finding (EASM) with an internal vulnerability (VMDR) to determine true risk.
Preferred Experience:
- Qualys Certified Specialist in CSAM or VMDR.
- Knowledge of Cloud (AWS/Azure) asset discovery and vulnerability/misconfiguration remediation.
- Experience with risk-based prioritization (focusing on what is exploitable vs. just high severity).
Suggestion: order these logically in some way, perhaps by Vail competencies: [AO1]
"The Vail Resorts Leadership Competencies are based on our company's core values: Leadership-Based Competencies Article"
Connect
Develop
Drive
Out Front
Re-imagine
- Elevate
Why join Genpact?
- Lead AI-first transformation – Build and scale AI solutions that redefine industries
- Make an impact – Drive change for global enterprises and solve business challenges that matter
- Accelerate your career—Gain hands-on experience, world-class training, mentorship, and AI certifications to advance your skills
- Grow with the best – Learn from top engineers, data scientists, and AI experts in a dynamic, fast-moving workplace
- Committed to ethical AI – Work in an environment where governance, transparency, and security are at the core of everything we build
- Thrive in a values-driven culture – Our courage, curiosity, and incisiveness
- built on a foundation of integrity and inclusion
- allow your ideas to fuel progress Come join the 140,000+ coders, tech shapers, and growth makers at Genpact and take your career in the only direction that matters: Up.
Let’s build tomorrow together.
📌 Vulnerability Management Consultant (Guadalajara)
🏢 Genpact
📍 Guadalajara