Full-Time

Vulnerability Management Senior Cyber Security Analyst

Sopra Steria

Sopra Steria

10,001+ employees

No salary listed

Chennai, Tamil Nadu, India + 1 more

More locations: Noida, Uttar Pradesh, India

In Person

Category
IT & Security (1)
Required Skills
Dynatrace
ServiceNow
Microsoft Intune
SCCM
Vulnerability Analysis
Ansible
Requirements
  • Hands on experience with detection and monitoring tools (Microsoft Defender for Endpoint EDR/XDR, WIZ, NESSUS PRO, Dynatrace)
  • Experience information system management and mapping tools (CMDB, VISIT)
  • Good knowledge of software distribution tools (SCCM, Intune, Satellite, Ansible, etc.), and reporting and analysis tools (PowerBI)
  • Experience with ServiceNow (SNOW), specifically the SECOPS module; ServiceNow SECOPS certification is preferred
  • Strong understanding of On-prem infrastructure, SaaS / IaaS / Cloud workloads, Application vulnerability context
  • Ability to enrich findings using CMDB / asset mapping tools
  • Working knowledge of - SCCM, Intune, Ansible, Satellite
  • Mandatory Soft Skills: Stakeholder & Coordination Skills - Ability to work with all stakeholders, and escalation handling and follow-up discipline
  • Documentation & Effective Communication - Clear communication (EN/FR preferred) with structured documentation mindset
  • Process & Continuous Improvement Mindset - Ability to maintain VM process documentation, Identify gaps and improvement areas and support internal training and knowledge base enrichment
  • Bachelor's degree or Master's in Computer Science, Engineering, or related field.
  • Strongly Recommended Certifications: CompTIA Security+ / ISC² SSCP / ISO 27001 Foundation
  • Strongly Recommended Certifications: Tenable Nessus Certification / GIAC Vulnerability Assessment / CREST Practitioner Security Analyst (CPSA)
  • Strongly Recommended Certifications: Microsoft SC-200 / SC-300
  • Strongly Recommended Certifications: AWS Security Specialty / Azure Security Engineer Associate
  • Strongly Recommended Certifications: ServiceNow SECOPS certification
Responsibilities
  • Vulnerability Management (Common VM Core) - Oversee the receipt, analysis, and tracking of vulnerabilities from various sources (CERT, scanning tools, division reports)
  • manage backlog processing, and create or update vulnerability tickets using multiple detection and asset management tools.
  • Asset Identification and Qualification - Assess and identify impacted assets across various environments, Qualify vulnerabilities by evaluating exposure, versions, severity, attack vectors, and client context, Enhance asset information using CMDB, and promptly issue alerts for critical vulnerabilities.
  • Definition and Steering of Remediation Plans - Develop, implement, and coordinate remediation plans by analyzing security advisories and scan reports, Defining tailored action strategies (including patches, workarounds, and updates), Prioritizing tasks, tracking requests in ServiceNow, Sending criticality-based reminders, and supporting remediation teams.
  • Monitoring and Validation of Patch Application - Monitor and validate patch application by ensuring timely verification, Gathering remediation evidence (especially for critical vulnerabilities), Documenting exceptions, and confirming remediation effectiveness prior to ticket closure.
  • Management of Critical P0 / P1 Vulnerabilities - Rapidly identify and assess impacted components and teams for critical vulnerabilities (P0/P1), Ensure targeted follow-up with dedicated reporting and regular meetings, draft essential documentation (minutes and summaries), Manage urgent vulnerability alerts, and escalate unresolved issues as needed.
  • Management of Non-CERT Vulnerabilities (VM3) - Monitor and assess non-CERT vulnerabilities, Evaluate their criticality using external sources, Recommend and implement remediation strategies, and escalate issues as required.
  • CTI & Incidentology Management - Oversee remediation tracking for CERT Threat Intelligence findings, including asset identification, Investigation, remediation coordination, and ticket processing, Support weekly CYB coordination, Enhance CTI quality, and maintain a comprehensive knowledge base.
  • COD Controls – Management and Follow-up - Oversee the execution, monitoring, and remediation tracking of key security controls—including asset management, Privileged account onboarding/offboarding, Identity administration, endpoint detection and response, Patch management with ongoing deployment of additional measures to mitigate cyber risk.
  • Reporting and Steering - Develop and maintain consolidated dashboards, Prepare monthly reports, conduct incident analysis, recommend service improvements, Adapt reporting to meet client expectations for vulnerability management.
  • Governance and Continuous Improvement - Oversee VM process documentation, monitor performance, Develop internal training materials, interface with the product team for requirements and tool evolution, Support data exchanges, and drive continuous service improvement.
Desired Qualifications
  • Bachelor's degree or Master's in Computer Science, Engineering, or related field.
  • Strongly Recommended Certifications: CompTIA Security+ / ISC² SSCP / ISO 27001 Foundation
  • Strongly Recommended Certifications: Tenable Nessus Certification / GIAC Vulnerability Assessment / CREST Practitioner Security Analyst (CPSA)
  • Strongly Recommended Certifications: Microsoft SC‑200 / SC‑300
  • Strongly Recommended Certifications: AWS Security Specialty / Azure Security Engineer Associate
  • Strongly Recommended Certifications: ServiceNow SECOPS certification

Company Size

10,001+

Company Stage

IPO

Headquarters

Paris, France

Founded

1968

Simplify Jobs

Simplify's Take

What believers are saying

  • Space and cybersecurity segments reach critical mass enabling European market leadership positioning.
  • AI momentum across defence, aeronautics, public sector drives strategic sector outperformance.
  • Consulting business targets doubling by 2028, reaching 12% of total revenue.

What critics are saying

  • Integration of Starion and Nexova disrupts operations; 20-30% talent exodus likely within year.
  • Aggressive acquisition spree dilutes earnings per share, net debt exceeds €500 million.
  • Atos post-restructuring undercuts Sopra pricing on public sector contracts, captures market share.

What makes Sopra Steria unique

  • Completed Starion and Nexova acquisitions establish €200M+ space and cybersecurity revenue base.
  • AI-related business surged 44% French clients, 50% consultant growth in 2025.
  • NHS joint venture secured £1.5B Tech Devices framework tender for device supply.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Sopra Steria who can refer or advise you

Benefits

Remote Work Options

Flexible Work Hours

Health Insurance

Paid Vacation

Paid Holidays

PTO/vacation

Unlimited Paid Time Off

Flexibility in schedule

Company News

Yahoo Finance
Mar 13th, 2026
Sopra Steria releases 2025 Universal Registration Document with $6.3B revenue

Sopra Steria has released its 2025 Universal Registration Document, registered with the Autorité des Marchés Financiers on 13 March 2026. The document includes the Annual Financial Report, management reports, statutory auditor reports and draft resolutions for the Annual General Meeting scheduled for 20 May 2026. The European technology company, which employs 51,000 people across nearly 30 countries, generated revenue of €5.6 billion in 2025. Sopra Steria specialises in consulting, digital services and solutions, helping clients drive digital transformation across various business sectors. The registration document is available on the company's investor relations website under Financial Publications & Reports.

Business Wire
Feb 26th, 2026
Sopra Steria returns to growth in Q4, net profit up 18% to $336M

Sopra Steria Group reported 2025 revenue of €5.65 billion, down 2.2% year-on-year, though the company returned to organic growth of 1.8% in the fourth quarter. Net profit attributable to the Group rose 18.3% to €296.8 million, with operating margin on business activity at 9.5%. The European IT services firm saw strong performance in strategic sectors including defence, aeronautics, public sector and financial services. AI-related business surged, with the number of French clients launching AI projects rising 44% and AI consultants increasing 50%. Free cash flow reached €340.9 million, representing 6% of revenue. Net financial debt fell 35.4% to €246.7 million. The company will propose a dividend of €5.30 per share, up from €4.65 previously. For 2026, Sopra Steria targets organic revenue growth of 1% to 2% and an operating margin of at least 9.5%.

L'Echo
Feb 4th, 2026
Belgian firms Starion and Nexova target €300M revenue after acquisition by French giant Sopra Steria

Starion and Nexova, Belgian companies based in Transinne, are targeting €300 million in revenue following their acquisition by French technology giant Sopra Steria. The deal aims to establish them as leading European players in space technology and cybersecurity. The acquisition positions the Belgian firms to leverage Sopra Steria's resources and scale to expand their operations across Europe. Both companies specialise in critical technology sectors, with Starion focused on space systems and Nexova on cybersecurity solutions. The integration is expected to accelerate growth in both core business areas whilst maintaining the companies' operational presence in Belgium.

Business Wire
Dec 2nd, 2025
Sopra Steria: Completion of Neocase Acquisition

Regulatory News: Sopra Steria (Euronext Paris: SOP), a major tech player in Europe, has announced that it has completed its acquisition of Neocase to bolster...

The Register
Sep 2nd, 2024
NHS dangles £1.5B carrot to be outfitted with everything from PCs to printers

NHS Shared Business Services Limited (NHS SBS), a joint venture between the NHS and French outsourcer Sopra Steria, and North of England Commercial Procurement Collaborative (NOE CPC), an NHS buying organization, have launched the tender for a framework deal dubbed "Tech Devices - Link 4."