Full-Time

Vulnerability and Incident Response Analyst

Hottinger Brüel & Kjaer

Hottinger Brüel & Kjaer

1,001-5,000 employees

Vibration testing and data analysis platform

No salary listed

Chennai, Tamil Nadu, India

Remote

Bachelor's, Master's

Category
IT & Security (1)
Required Skills
Incident Response
Vulnerability Analysis
Penetration Testing
DevOps

Get referred to Hottinger Brüel & Kjaer

See people who can refer or advise you

Requirements
  • A bachelor's or master's degree in cyber security, Computer Science, Information Security, Software Engineering, or a related technical discipline.
  • Experience in vulnerability management, security operations, incident response, Product Security Incident Response Team (PSIRT) work, application security, or a related cybersecurity discipline.
  • Understanding of vulnerability assessment methodologies, Common Vulnerability Scoring System (CVSS) scoring, exploitability analysis, and remediation workflows.
  • Familiarity with vulnerability management platforms, ticketing systems, and security scanning tools.
  • Knowledge of common vulnerability databases and threat intelligence sources, including Common Vulnerabilities and Exposures (CVE), National Vulnerability Database (NVD), and Known Exploited Vulnerabilities (KEV).
  • Understanding of software development lifecycles and secure development practices.
  • Familiarity with cybersecurity regulations and standards such as the EU Cyber Resilience Act, ISO/IEC 30111, ISO/IEC 29147, IEC 62443, NIST SP 800 series, or ISO 27001.
  • Ability to prioritize and manage multiple activities simultaneously.
Responsibilities
  • Perform initial triage, validation, and analysis of product vulnerabilities identified through vulnerability disclosures, internal testing, security assessments, penetration testing, or automated scanning tools.
  • Assess vulnerability severity using CVSS, exploitability, product applicability, and business impact criteria.
  • Review vulnerability reports with product teams to determine applicability, exploitability, and remediation requirements, and help prioritize vulnerabilities based on risk.
  • Maintain accurate vulnerability records, evidence, and audit trails to support governance and compliance requirements.
  • Coordinate security incident and exploited vulnerability reporting activities in accordance with applicable regulatory obligations.
  • Prepare and maintain information required for regulatory notifications in collaboration with Product Security, Legal, and Product Teams.
  • Track incident reporting timelines and ensure escalation activities are completed within defined regulatory timeframes.
  • Support incident readiness exercises and reporting process validation activities.
  • Monitor vulnerability disclosure channels, PSIRT mailboxes, public vulnerability disclosures, security advisories, and relevant threat intelligence feeds.
  • Identify vulnerabilities and emerging threats that may impact products and coordinate investigations with relevant stakeholders.
  • Track Known Exploited Vulnerabilities, industry alerts, and security advisories relevant to products and technologies.
  • Maintain awareness of evolving cybersecurity threats, attacker techniques, and regulatory developments.
  • Coordinate remediation activities with Product Teams, DevSecOps, and Product Security stakeholders.
  • Track vulnerability remediation progress against defined remediation targets and service-level objectives.
  • Support review of proposed security updates, patches, and mitigation plans.
  • Produce vulnerability status reports, metrics, and management updates for governance forums and program tracking.
  • Serve as the operational liaison between Product Security, DevSecOps, Customer Support, Legal, and Product Teams.
  • Facilitate communication and issue resolution across stakeholders involved in vulnerability management and incident response activities.
  • Support implementation and continual improvement of vulnerability management and coordinated vulnerability disclosure processes.
  • Contribute to regulatory readiness initiatives associated with the EU Cyber Resilience Act and related cybersecurity requirements.
Desired Qualifications
  • Experience preparing security reports, metrics, and compliance evidence.
  • Experience working within a Product Security Incident Response Team (PSIRT).
  • Exposure to regulatory reporting obligations and coordinated vulnerability disclosure programs.
  • Experience with vulnerability management automation, DevSecOps pipelines, static application security testing (SAST) and dynamic application security testing (DAST) integration, software bill of materials (SBOM) tooling, or software composition analysis platforms.
  • Familiarity with cloud, desktop, software-as-a-service (SaaS), embedded, or industrial control system products.
  • Prior experience with bug bounty portals.
  • Know-how in penetration testing.
Hottinger Brüel & Kjaer

Hottinger Brüel & Kjaer

View

Preparing company summary.

Company Size

1,001-5,000

Company Stage

N/A

Total Funding

N/A

Headquarters

Darmstadt, Germany

Founded

1942

Get referred to Hottinger Brüel & Kjaer

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Fusion-LN shipped in March 2026, giving HBK a fresh hardware upgrade cycle.
  • Sentech brings 86 employees and 350 blue-chip customers into HBK’s embedded-sensing funnel.
  • Owners@Spectris, launched June 2026, can improve retention and acquisition integration momentum.

What critics are saying

  • Sentech closes only after US regulatory clearance, delaying synergies into late 2026.
  • Fusion-LN backward compatibility protects customers, but it also slows replacement-driven revenue expansion.
  • KKR ownership raises integration pressure; a bad Sentech fit damages HBK’s acquisition-led strategy.

What makes Hottinger Brüel & Kjaer unique

  • HBK’s March 2026 Fusion-LN keeps LAN-XI installations working, easing upgrades.
  • HBK spans sound, vibration, and embedded sensing, serving aerospace, defence, energy, and industrial markets.
  • The August 2026 Sentech acquisition adds LVDT, RVDT, and speed-sensing depth.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Training Programs

Mentorship Program

Performance Bonus

Company News

HBK World
Aug 1st, 2026
HBK announces acquisition of Sentech

HBK has signed an agreement to acquire Sentech, a leading provider of precision position and speed sensing technologies, strengthening our capabilities in embedded sensing across aerospace, energy, defence, and industrial markets.

Process and Control Today Ltd
Mar 18th, 2026
The next generation in sound and vibration data acquisition.

The next generation in sound and vibration data acquisition. 18/03/2026 HBK - Hottinger, Bruel & Kjaer Designed to meet the evolving needs of engineers and researchers, Hottinger Brüel & Kjær's (HBK) latest innovation in sound and vibration measurement - Fusion-LN - has expanded its product line with a 12-channel module, which is available now for delivery. Fusion-LN introduces a streamlined approach to data acquisition, supporting applications across aerospace and defence, telecom, audio, industrial, and automotive sectors. Its modular design and intuitive interface enable users to adapt quickly to changing test requirements without compromising accuracy or reliability. A key function is that owners of HBK's LAN-XI data acquisition tool can preserve current capabilities and past investments, as Fusion-LN has backwards compatibility with LAN-XI. Operators are now also able to place Fusion-LN modules - combined with LAN-XI modules - in the same frame, which provides a seamless upgrade and allows them to expand their system, instead of replacing it. As industries face increasing demands for precision and efficiency, Fusion-LN provides engineers with a platform to simplify complex measurement tasks, while ensuring scalability for their future challenges.