HimalayasHimalayas logo
SailPointSA

Vulnerability Management Analyst

SailPoint is an identity security company that helps organizations manage and secure access to their applications and data. They utilize AI and machine learning to automate and streamline identity governance.

SailPoint

Employee count: 1001-5000

India only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Cybersecurity Vulnerability Management Analyst

SailPoint’s Cybersecurity organization is seeking a Cybersecurity
Vulnerability Management Analyst with a passion for cybersecurity.This
role ensures the continuous discovery, accurate assessment, risk-based
prioritization, and successful remediation of vulnerabilities and
misconfigurations across all IT assets, directly reducing the organization's
exposure and maintaining regulatory compliance.
We are seeking a colleague with demonstrabletechnical expertise, strong
business acumen, and a proven track record of working in security
programs in complex environments. The ideal candidate will bepart ofthe
team securing SailPoint’s production environments from misconfigurations
and software vulnerabilities, cross-functional collaboration, and ensuring
that products meet the highest standards of security, availability, and trust.
Our new Vulnerability Management Analyst will join a growing and capable
threat and vulnerability management team of both emerging and
established talent. This potential team member will be comfortable with the
4 I’s at SailPoint (individual, Impact, Innovation, and Integrity) even if
they’re new to the concept. They will embrace new challenges, and by being
their authentic self they will be a positive contributor to an already positive

work culture and environment.

This is a challenging and impactful role where you will have the opportunity
to work with a variety of stakeholders, including our fantastic colleagues in
IT, DevOps, Product engineering, Security engineering, and Compliance.
This role reports directly to the Head of Vulnerability Management and will
be remote. Candidae must go to Pune office once a quarter.
Key Requirements:
3-5 years experience, preferably in vulnerability management.
Strong engineering experience with cloud, containers, open-source
code, deployment and misconfigurations.
Intermediate experience with scripting languages (e.g., Python,
PowerShell) for automating data ingestion, reporting, or integrating
VM data into other security tools (SIEM/SOAR).
Experience with regulatory frameworks (e.g., NIST, ISO 27001, SOC,
GDPR) and providing evidence for compliance and audit needs.
Experience tracking trends and configure systems as required to
reduce false positives from true events.
Process Improvement: Drive continuous improvement in the efficiency
of vulnerability remediation through automation, ticketing system
integration (e.g., Jira), and process streamlining.
Influence & Collaboration – Demonstrable experience building strong
partnerships in a matrixed organization.
Technical– Intermediate understanding of product security issues
(like XXE, SSRF, Injections, etc.), modern software development (fully
automated CI/CD, REST, OAuth2) including multi-cloud (AWS, Azure,
GCP, Containers, Kubernetes) architectures, particularly Amazon Web
Services, Kubernetes, and Docker.
Risk-Based Decision Making – Experience making informed decisions
through balancing business priorities, technical constraints, and risk
exposure.
Certifications like CISSP, CISA,CySA+, AWS Certs,or CCNSE, or
other relevant certifications are preferred.
If the candidate does not have the AWS Certified Cloud Practitioner or
AWS Certified Cloud Security – Specialty, they must take these
certifications within first year of employment.
Core Responsibilities:
Collaborating in the enterprise-wide product security and resilience
strategy, aligning with business goals and regulatory requirements.
Partnering with Dev/Ops, engineering, product management, and
infrastructure teams to integrate vulnerability management practices
into production environments.
Identifying risk in a production environment comprised of a
sophisticated SaaS architecture consisting of dozens of microservices
Maintain knowledge of the threat landscape for prioritization of
vulnerabilities, attack techniques, tool/exploit development, cyber
threat intelligence analysis and adversarial tactics.
Explaining risks, identifing dependencies, and facilitating the
remediation process by providing necessary details and context.
Enforce a prioritization framework that utilizes risk context beyond
standard CVSS scores, factoring in asset criticality, exposure to the
public internet, and internal threat intelligence (e.g., active
exploitation in the wild).
Drive the adoption of security automation, vulnerability management
with product teams.
Providing program performance reporting and metrics per business
unit and product.
First 30 Days
Learn the landscape, processes and technologies.
Complete all tooling platform specific training assigned.
60 Days
Take ownership of vulnerability analysis and reporting for a
designated environment
Establish communication and follow-up cadence with the remediation
teams
Identify and document an opportunity to improve the efficiency of the
current process
90 Days
Manage full lifecycle for all production environment
Collaborate with respective teams to address specific, frequent
occurring vulnerability, insecure coding, etc
Have deep understanding of all core technologies, environments and
our cloud architecture.
Contribute to the team internal knowledgebase on lessons learned

SailPoint is an equal opportunity employer and we welcome all qualified candidates to apply to join our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other category protected by applicable law.

Alternative methods of applying for employment are available to individuals unable to submit an application through this site because of a disability. Contact applicationassistance@sailpoint.com or mail to 11120 Four Points Dr, Suite 100, Austin, TX 78726, to discuss reasonable accommodations. NOTE: Any unsolicited resumes sent by candidates or agencies to this email will not be considered for current openings at SailPoint.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Location requirements

Hiring timezones

India +/- 0 hours

About SailPoint

Learn more about SailPoint and their company culture.

View company profile

At the heart of SailPoint's operations is a culture deeply rooted in its 'Four I's': Innovation, Integrity, Impact, and Individuals. This philosophy guides every aspect of the company, from developing creative solutions for complex identity security challenges to fostering a collaborative and caring work environment. SailPoint believes that its people are its single greatest asset, and this is reflected in a workplace culture that is responsive to the needs of its employees, both professionally and personally. The company takes its business of securing the modern enterprise very seriously, yet it also champions a healthy work-life balance for its 'Crew' members.

SailPoint's mission is to equip every enterprise to effortlessly manage and secure access to applications and data through the lens of identity, operating at any speed and any scale. As pioneers in harnessing AI and machine learning for identity security, SailPoint automates and streamlines the complexities of ensuring the right access for the right identities at the right time. This commitment to innovation is matched by a profound sense of integrity; the company strives to deliver on its commitments to customers, partners, and its own team. The 'Individuals' aspect of their core values underscores a commitment to valuing every person within the company, fostering an environment where people feel welcome, cared for, and proud to work. This supportive and inclusive culture extends globally, with efforts to ensure consistency across all its offices. Furthermore, SailPoint is dedicated to making a positive impact, not only through its cutting-edge identity security solutions but also through philanthropic efforts via the SailPoint Gives Back Foundation. This holistic approach, combining technological leadership with a strong, people-centric culture, defines SailPoint's identity in the enterprise security landscape.

Employee benefits

Learn about the employee benefits and perks provided at SailPoint.

View benefits

401(K)

SailPoint offers a 401(K) plan.

Company sponsored family events

SailPoint sponsors family events.

Paid holidays

SailPoint provides paid holidays.

Life insurance

SailPoint provides life insurance.

View SailPoint's employee benefits
Claim this profileSailPoint logoSA

SailPoint

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

79 remote jobs at SailPoint

Explore the variety of open remote roles at SailPoint, offering flexible work options across multiple disciplines and skill levels.

View all jobs at SailPoint

Remote companies like SailPoint

Find your next opportunity by exploring profiles of companies that are similar to SailPoint. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan