Cyber Threat Exposure Management Lead @Version 1
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 3wks ago

[Hiring] Cyber Threat Exposure Management Lead @Version 1

3wks ago - Version 1 is hiring a remote Cyber Threat Exposure Management Lead. 💸 Salary: unspecified 📍Location: India

Role Description

Senior technical lead to own strategy and drive maturity across attack surface management, vulnerability management, and cloud security posture using a continuous threat exposure management (CTEM) approach. Accountable for programme delivery quality, tooling strategy, and governance. Requires deep technical expertise combined with the ability to lead and coach a team, shape a capability roadmap, and influence senior stakeholders without direct supervision.

Key Responsibilities

  • Strategy & Programme Direction
    • Own function strategy aligned to business risk appetite and security frameworks.
    • Drive continuous improvement across all CTEM programme phases.
    • Establish governance and standards across vulnerability management, ASM, CSPM, and secure development.
    • Own the exposure management roadmap; present evidence-based investment cases to senior stakeholders.
  • Tool Selection & Capability Development
    • Own toolchain selection for EASM/CAASM, vulnerability management, CSPM, and exposure correlation.
    • Integrate exposure management platforms with SIEM, SOAR, and DevSecOps pipelines.
    • Monitor emerging tooling and AI-augmented triage; recommend capability investments.
    • Define coverage requirements and onboarding standards for new assets and workloads.
  • Attack Surface Management (ASM / EASM)
    • Run continuous discovery and attribution of all Internet-facing assets, shadow IT, and third-party exposure.
    • Enrich findings with threat intelligence, KEV data, and active exploitation trends.
    • Maintain an accurate inventory as the authoritative basis for prioritisation.
    • Continuously improve coverage, reduce noise, and sharpen the prioritisation model.
  • Vulnerability Management
    • Own the vulnerability management programme end to end: triage, remediation, SLA governance, and closure.
    • Maintain risk-based scoring incorporating CVSS, EPSS, business criticality, and threat context.
    • Hold remediation teams to SLAs; resolve systemic blockers across functions.
  • Cloud Security Posture Management (CSPM)
    • Own CSPM strategy across AWS, Azure, and OCI; keep visibility current with estate growth.
    • Partner with cloud platform and architecture teams to embed security posture requirements into platform design and IaC standards.
    • Eliminate recurring misconfigurations through root cause analysis; don't accept repeat findings.
  • Pentest & Purple Team Oversight
    • Commission and manage penetration testing and purple team engagements; QA external deliverables.
    • Translate findings into prioritised remediation and track to closure.
    • Use validation outputs to improve controls and update the exposure model.
  • Secure SDLC
    • Integrate security requirements, threat modelling, and code review into the SDLC.
    • Drive secure-by-design principles with engineering and architecture teams.
    • Measure secure development maturity and set improvement targets.
  • Leadership, Reporting & Stakeholder Engagement
    • Deliver executive dashboards translating technical risk into business impact; represent the function in ISO 27001, Cyber Essentials Plus, SOC 1, and MSP audit cycles.
    • Build credibility with senior stakeholders, client security teams, and third-party assessors.
    • Lead, coach, and develop the team; set clear goals, resolve conflicts, and create growth opportunities.
    • Foster a culture of learning and delivery excellence; act as escalation point for complex technical decisions.
    • Coordinate remediation owners, platform teams, and external parties; keep all stakeholders aligned on plans and blockers.

Qualifications

  • 6+ years’ experience in cyber security, 2+ years in a senior exposure management, VM, or threat intelligence role; degree in Computer Science or Information Security, or equivalent.
  • Relevant certifications: CISSP, CISM, OSCP, or equivalent. CTEM-related training or Gartner CTEM methodology experience advantageous.
  • Experience evaluating and selecting security tooling across EASM/CAASM, CSPM, and VM platforms; hands-on with Defender XDR/CSPM, Zscaler, Tenable, Tanium, or equivalent.
  • Deep working knowledge of NIST CSF, ISO 27001, MITRE ATT&CK, and CTEM principles.
  • ISPM and attack path mapping experience; ability to communicate technical exposure as business risk to senior stakeholders.
  • Experience designing or maturing a CTEM programme; familiarity with AI-augmented vulnerability triage, attack path analysis, or BAS.
  • Exposure to audit frameworks (Cyber Essentials Plus, SOC 1, FSQS) or MSP/MSSP environment.

Benefits

  • Share in our success with our Quarterly Performance-Related Profit Share Scheme, where employees collectively benefit from a share of our company's profits.
  • Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme.
  • Flexible/remote working; Version 1 is tremendously understanding of life events and people’s individual circumstances and offers flexibility to help achieve a healthy work-life balance.
  • Financial Wellbeing initiatives including Pension, Private Healthcare Cover, Life Assurance, Financial advice, and an Employee Discount scheme.
  • Employee Wellbeing schemes including Gym Discounts, Bike to Work, Fitness classes, Mindfulness Workshops, Employee Assistance Programme and much more.
  • Generous holiday allowance, enhanced maternity/paternity leave, marriage/civil partnership leave, and special leave policies.
  • Educational assistance, incentivised certifications, and accreditations, including AWS, Microsoft, Oracle, and Red Hat.
  • Reward schemes including Version 1’s Annual Excellence Awards & ‘Call-Out’ platform.
  • Environment, Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity, inclusion and belonging schemes.
  • And many more exciting benefits… drop us a note to find out more.
Before You Apply
️
remote Be aware of the location restriction for this remote position: India
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Cyber Threat Exposure Management Lead @Version 1
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 3wks ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: India
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 127,050+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later