Expleo Jobs In En logo

Vulnerability and Patch Manager

Hiring from
India
Work type
Hybrid
Posted
Sep 30, 2026
Is this job info correct?

Overview

Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to deliver innovation, improve resilience, and support the secure delivery of complex products, platforms, and systems.

As part of the Expleo UK Cybersecurity Practice, you will join a managed Cyber Operations service for a major UK energy network operator that forms part of the UK's Critical National Infrastructure (CNI). The service is governed by Expleo in the UK, with a 24/7 UK Security Operations Centre delivered by a specialist partner and an Expleo consultancy team in India providing design, engineering and assurance expertise across the client's security tooling estate.

As Vulnerability and Patch Manager, you will lead the vulnerability intelligence, prioritisation and patch advisory service across the client's server, end-user, network and security device estate, coordinating remediation through the client's operational teams and suppliers.

This is a design, review and advisory role. You will work within Expleo's offshore consultancy team, outside the client's operational environment. You will not have access to the client's operational systems or data and will not make live changes. Operational changes are implemented by UK-based, security-cleared personnel; your work provides the designs, analysis, recommendations and assurance that those changes depend on. You will work from information released to the team through Expleo's controlled UK service boundary.

Responsibilities

Responsibilities

  • Lead a continuous vulnerability assessment programme, using outputs from the client's vulnerability management platform released through the UK service boundary.
  • Prioritise vulnerabilities using threat-informed criteria (CVSS, EPSS, CISA KEV, NCSC advisories and vendor PSIRTs) and produce monthly remediation recommendations.
  • Issue critical patch advisories, typically within 24 hours, based on client guidance and credible threat intelligence, to enable expedited remediation by UK-based personnel and client suppliers.
  • Produce a monthly report on vendor patch and firmware releases across the server, end-user, mobile, network and security estate.
  • Produce OS patch and device firmware compliance reports.
  • Consolidate patch and upgrade status reporting for firewalls, intrusion prevention, email gateway, secure web gateway and application control platforms.
  • Track intrusion prevention signature (digital vaccine) compliance against the 48-hour target, working with the Security Engineer | Network.
  • Maintain the vulnerability exception and risk acceptance register and present items for decision through service governance.
  • Prepare and co-facilitate the monthly vulnerability and patch review with the UK Head of Service, client teams and third-party suppliers.
  • Carry out targeted vulnerability analysis in support of incidents and investigations when directed.
  • Apply safe practice for operational technology (OT) assets, where scanning and patching are constrained.
  • Support the growth of Expleo's Cybersecurity Practice through knowledge sharing and technical contribution.

Qualifications

  • Degree in computer science, cybersecurity or a related discipline, or equivalent professional experience.
  • Vulnerability management vendor certification, e.g. Rapid7, Tenable or Qualys (at least one required).
  • CompTIA CySA+, PenTest+, GIAC GEVA, or ITIL 4 Foundation would be advantageous.

Essential skills

  • Vulnerability management platforms (e.g. Rapid7 InsightVM, Tenable, Qualys) and interpretation of their outputs.
  • Patch management processes and tooling (e.g. Intune/MECM, Ivanti, Tanium, BigFix).
  • Threat-informed prioritisation using CVSS, EPSS, CISA KEV and vendor advisories.
  • Coordinating remediation across internal teams and third-party suppliers.
  • Strong reporting and data analysis (Excel, Power BI).
  • Clear, concise written advisories for technical and non-technical audiences.

Desired skills

  • OT vulnerability management and safe scanning practice.
  • Energy, utilities or other CNI sector experience.
  • Experience supporting NIS or CAF-aligned assurance reporting.

Experience

  • 8-12 years in IT security or infrastructure, including 4+ years managing vulnerability and patch management programmes.
  • Experience running risk exception and acceptance processes through governance.

What do I need before I apply

  • Have the right to work in India.
  • Be based in, or willing to relocate to, Chennai.
  • Be willing to complete Expleo enhanced pre-employment background screening (equivalent in standard to the UK Baseline Personnel Security Standard) and any additional vetting the client requires.
  • Be able to work hours that overlap with the UK business day, with occasional out-of-hours advisory support during major incidents.
  • Have excellent written and spoken English, suitable for engagement with senior UK stakeholders.
  • Be comfortable working within a strict security boundary, with no access to the client's operational systems or data.

Benefits

  • Collaborative working environment: we stand shoulder to shoulder with our clients and our peers through good times and challenges.
  • We empower all passionate, technology-loving professionals to expand their skills and take part in inspiring projects.
  • Expleo Academy enables you to acquire and develop the right skills by delivering a suite of accredited training courses.
  • Competitive local company benefits [India HR to confirm the benefits package].
  • Always working as one team, our people are not afraid to think big and challenge the status quo.

“We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age.”

If you are an experienced vulnerability management professional who can turn vulnerability data into clear, prioritised action, we encourage you to apply today.

Similar jobs

Apply for this job