ASAI job platform logo
  1. Home
  2. /Jobs
  3. /Security Engineer Jobs in Pune
  4. /Cyber Threat Exposure Management Lead
Gruve

Cyber Threat Exposure Management Lead

Pune · Senior

Good timing - competition is buildingVerified listingPosted 13d ago

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

What we know about this role

Hiring pulse

MEDIUM

Gruve is reviewing applications at a steady pace. Expect a standard response time as they evaluate the current pool.

Apply window

First 72 hours

Window passed - posted 13d ago

Early applicants get seen before the pile builds.

Not a repost

The first time we've seen this listing - it hasn't been closed and reopened.

Skills required

15 listed
Large Language Models (LLMs)Attack Surface ManagementMITRE ATT&CK FrameworkCloud InfrastructureRisk AppetitePatch ManagementRisk ReductionProposal Writing+7 more
Large Language Models (LLMs)Attack Surface ManagementMITRE ATT&CK FrameworkCloud InfrastructureRisk Appetite

You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.

Job description

About Gruve

Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.

Position summary:

We are looking for an experienced CTEM (Continuous Threat Exposure Management) Expert to lead the design, implementation, and continuous operation of exposure management programs for our clients. This role sits at the intersection of vulnerability management, attack surface management, threat intelligence, and risk-based remediation helping clients move from periodic point-in-time assessments to a continuous, adversary-informed exposure reduction program aligned with 5-stage CTEM framework (Scoping, Discovery, Prioritization, Validation, and Mobilization).

You will work directly with client CISOs, security operations teams, and IT owners to build programs that identify, prioritize, validate, and reduce cyber exposure across on-prem, cloud, and hybrid environments and demonstrate measurable reduction in exploitable risk over time.

Key Roles & Responsibilities:

  • Lead end-to-end delivery of CTEM engagements across the five stages: Scoping, Discovery, Prioritization, Validation, and Mobilization
  • Design and operationalize continuous exposure management programs tailored to client risk appetite, industry, and regulatory context
  • Integrate and correlate data across vulnerability management, attack surface management (ASM), cloud security posture management (CSPM), threat intelligence, and breach & attack simulation (BAS) tools to build a unified exposure view
  • Translate technical findings (CVEs, misconfigurations, exposed assets, identity risks) into business-risk-prioritized remediation plans using exploitability, asset criticality, and threat context (e.g., KEV, EPSS, active exploitation campaigns)
  • Drive adversarial validation of exposures through coordination with red/purple teams, pentesters, or automated validation platforms to confirm real-world exploitability
  • Own exposure reduction metrics and reporting and present progress to client stakeholders and leadership
  • Coordinate remediation and patch/mitigation execution with client asset owners, IT, and SOC teams; manage emergency response for zero-days and actively exploited vulnerabilities
  • Build and refine CTEM playbooks, runbooks, and governance frameworks; establish exception and risk-acceptance processes
  • Support pre-sales activities — scoping calls, proposals, PoCs, and CTEM maturity assessments for prospective clients
  • Mentor junior consultants/analysts and contribute to practice capability building, including tool evaluation and methodology development
  • Stay current on the threat landscape, emerging attack techniques, and CTEM tooling ecosystem.

Mandatory Qualifications:

  • BE/BTech (CS/IT/E&TC) or equivalent.
  • 5–10 years of overall cybersecurity experience, with 3+ years in exposure management, vulnerability management, attack surface management, or red team/adversary simulation
  • Strong hands-on experience with CTEM/exposure management platforms such as Tenable (Exposure Management/One), Qualys VMDR/ETM, CrowdStrike Falcon Exposure Management, or similar
  • Practical experience with attack surface management (ASM) tools and breach & attack simulation (BAS) platforms
  • Solid understanding of vulnerability prioritization frameworks: CVSS, EPSS, CISA KEV, exploit maturity, and asset-criticality-based risk scoring
  • Experience integrating exposure data with SIEM/SOAR, ticketing (ServiceNow, Jira), and patch management tools.
  • Familiarity with cloud security posture (AWS, Azure, GCP) and CSPM tools, and how cloud exposures fit into a unified CTEM program
  • Strong grasp of the MITRE ATT&CK framework and how attack-path/graph analysis supports validation and prioritization
  • Experience defining and reporting exposure/remediation KPIs (MTTD, MTTR, MTRER, risk reduction trend lines) to executive and client audiences
  • Working knowledge of relevant compliance/regulatory frameworks
  • Excellent client-facing communication skills — able to translate technical exposure data into business risk narratives for CISOs and boards

Preferred Qualifications:

  • Relevant certifications: CISSP, CISM, Tenable/Qualys certifications
  • Experience building or scaling a CTEM-as-a-Service offering within an MSSP/consulting practice
  • Experience with pre-sales, proposal writing, and CTEM maturity/readiness assessments
  • Prior experience mentoring teams or leading a practice/pod within a cybersecurity consulting or MSSP environment

Why Gruve

At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

More Security Engineer roles in Pune

See all

Lead - Security Architecture

NT Careers · Pune

Senior Staff Engineer, Product Security

Druva · Pune

Senior Network Engineer

Ensono · Pune

Security Research Engineer

Cowbell Cyber Inc. · Pune

Keep browsing

All open roles at GruveAll Security Engineer jobs in Pune

Two ways in

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

ASAI job platform logo

A job platform finally, balanced in your favour.

Jobs by CityJobs by CompanyGuidesHow We VerifyAboutPrivacy PolicyTerms of Service

Built in India 🇮🇳

© 2026 ASAI. All rights reserved.