We are currently seeking a
Cloud Vulnerability Management Engineer (Onsite Hybrid) to join our team in Atlanta, Georgia (US-GA), United States (US).
Technology Focus: Hybrid Cloud / Azure / AWS / Apache Spark
Role Focus: Cloud Vulnerability Management / DevSecOps / Cloud Security
Job Responsibilities Include:- Manage the end-to-end vulnerability management lifecycle for enterprise applications and infrastructure hosted across hybrid cloud, Microsoft Azure, and AWS environments.
- Analyze vulnerability scan results and identify security vulnerabilities affecting cloud infrastructure, operating systems, containers, application dependencies, open-source libraries, and cloud-hosted data platforms.
- Perform vulnerability assessment and prioritization based on CVE/CVSS severity, exploitability, application criticality, external exposure, and overall business risk.
- Work closely with Application Development, Cloud Engineering, DevOps, SRE, Infrastructure, and Cybersecurity teams to define and execute vulnerability remediation plans.
- Support identification and remediation of vulnerabilities across AWS and Azure cloud services, Linux/Windows servers, Kubernetes, containers, Docker images, Java applications, and open-source components.
- Support vulnerability management for Apache Spark-based applications and data-processing platforms, including Spark runtime versions, Java/JVM dependencies, libraries, packages, and associated cloud infrastructure.
- Work with engineering teams to troubleshoot the technical root cause of vulnerabilities and recommend appropriate remediation, including patching, dependency upgrades, configuration changes, infrastructure changes, or compensating controls.
- Validate successful remediation through rescanning, technical verification, and security evidence collection.
- Track Critical and High vulnerabilities against established remediation SLAs and proactively escalate overdue vulnerabilities, blockers, and risks.
- Identify recurring vulnerability patterns and recommend systemic solutions and preventive controls to reduce repeat findings.
- Integrate vulnerability and security scanning into CI/CD and DevSecOps pipelines, enabling earlier identification of vulnerabilities during the software development lifecycle.
- Support cloud security posture assessments and remediation of configuration weaknesses across Azure, AWS, and hybrid-cloud environments.
- Develop scripts and automation to improve vulnerability identification, remediation tracking, validation, reporting, and compliance evidence collection.
- Create dashboards and reports covering open vulnerabilities, remediation aging, SLA compliance, risk acceptance, remediation trends, and vulnerability reduction.
- Participate in vulnerability governance and operational review meetings and communicate technical risks, remediation status, dependencies, and blockers to engineering and management stakeholders.
Basic Qualifications:- Minimum 7+ years of experience in IT engineering, Cloud Engineering, DevOps/SRE, Cybersecurity, Application Security, or Vulnerability Management within enterprise environments.
- Minimum 4+ years of hands-on experience in Vulnerability Management / Application Security / Cloud Security, including vulnerability analysis, prioritization, remediation, and validation.
- Minimum 4+ years of experience working with public cloud technologies, with strong hands-on knowledge of AWS and/or Microsoft Azure.
- Minimum 2+ years of experience supporting hybrid-cloud or multi-cloud environments, preferably involving application migration or transformation between Azure and AWS.
- Minimum 3+ years of experience using enterprise vulnerability/security platforms such as Qualys, Tenable, Rapid7, Wiz, Prisma Cloud, Microsoft Defender for Cloud, AWS Inspector, or comparable tools.
- Minimum 3+ years of experience analyzing and remediating CVE/CVSS-based vulnerabilities, including operating-system vulnerabilities, application dependencies, open-source libraries, containers, and cloud infrastructure.
- Minimum 2+ years of experience supporting security or vulnerability management for Apache Spark, Databricks, EMR, Hadoop, or similar large-scale data-processing platforms.
- Minimum 2+ years of experience working with Java/JVM applications and open-source dependency vulnerability remediation, including upgrading vulnerable libraries and packages.
- Minimum 2+ years of experience working with containers and container orchestration technologies such as Docker and Kubernetes, including container/image vulnerability management.
- Minimum 2+ years of experience with CI/CD and DevSecOps technologies such as GitLab CI, GitHub Actions, Jenkins, Azure DevOps, or comparable platforms.
- Minimum 2+ years of experience integrating or working with security controls such as SAST, DAST, Software Composition Analysis (SCA), container scanning, secrets scanning, and Infrastructure-as-Code scanning.
- Minimum 2+ years of experience with scripting or automation using Python, Bash, PowerShell, or equivalent technologies.
Preferred Skills:- Strong understanding of AWS and Azure security concepts, including IAM/access controls, cloud configuration, network security, logging/monitoring, and cloud security posture management.
- Strong knowledge of vulnerability-management concepts including CVE, CVSS, risk-based prioritization, patch management, vulnerability SLAs, remediation validation, security exceptions, and risk acceptance.
- Strong analytical, troubleshooting, and communication skills with the ability to translate security findings into actionable technical remediation for engineering teams.
Travel:- This position may require occasional travel based on client and project requirements.
Degree:- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent work experience.
Nice to Have:- Experience working in Banking, Financial Services, or other highly regulated enterprise environments.
- Experience securing enterprise data platforms utilizing Apache Spark, Databricks, AWS EMR, Kafka, Hadoop, or related technologies.
- Experience with cloud security services including AWS Security Hub, Inspector, GuardDuty, CloudTrail, Config, Microsoft Defender for Cloud, Azure Policy, and Entra ID.
- Experience with Infrastructure as Code technologies such as Terraform and AWS CloudFormation.
- Knowledge of security standards and frameworks including NIST, CIS Benchmarks, OWASP, and cloud security best practices.
- Experience implementing automated vulnerability-remediation and security-validation workflows.
- Experience applying AI/LLM-based capabilities to vulnerability analysis, remediation recommendations, or security automation.
- Familiarity with SRE, observability, production support, and incident-management practices.
- Relevant certifications such as AWS Certified Security - Specialty, Microsoft Azure Security Engineer, CISSP, CCSP, Security+, or equivalent cloud/security certifications.
NTT DATA provides a reasonable range of compensation for U.S.-based positions. The starting pay range for this role is $87,720 - $131,580 per annum. Actual compensation will depend on a number of factors, including the candidate's relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance.
This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits.
#L1-NorthAmerica