- Location
- IN KA BANGALORE Home Office Building 11, India
- Type
- Full-time
- Seniority
- Senior
- Education
- Bachelor
- Source
- Workday
Description
Position Summary...
We are looking for a Staff Technical Vulnerability Analyst (TVA) who brings deep expertise in enterprise vulnerability management, strong analytical skills, and the ability to drive cross-functional remediation programs at scale. The ideal candidate has hands-on experience with industry-leading vulnerability scanning and management platforms, a solid understanding of CVSS scoring (v3.x/v4.0), risk prioritization frameworks, and the ability to communicate technical risk clearly to both engineering teams and executive stakeholders.This role requires someone who can operate independently, mentor junior analysts, influence remediation outcomes without direct authority, and contribute to the continuous maturation of Walmart's vulnerability management program. You will work within a globally distributed team and partner with Walmart's India-based engineering, cloud, and DevOps communities to embed security into the software and infrastructure delivery lifecycle.
What you'll do...
About the team
The Threat & Vulnerability Management (TVM) team at Walmart is a critical pillar of the Global Information Security organization. Operating out of the India Development Center, this team is part of Walmart's enterprise-wide mission to proactively identify, prioritize, and drive the remediation of security vulnerabilities across one of the world's largest and most complex technology ecosystems — spanning on-premise infrastructure, cloud environments (Azure, GCP), WCNP (Walmart Cloud Native Platform), and retail technology.
Our TVM team works on Walmart's unified vulnerability intelligence platform — WalSec Radar (WSR) — which aggregates data from scanning tools such as Tenable, Snyk, Tanium, Wiz, and penetration testing platforms including ReSTART and STASH. The team partners directly with engineering, DevOps, cloud, and compliance stakeholders to reduce mean time to remediate (MTTR), enforce SLA adherence, and provide risk-based security insights to leadership.
As part of the Security Intelligence & Management (SIM) function, the TVA sub-team is specifically responsible for managing risk scoring, vulnerability ownership, and the accuracy of security issue data across the enterprise. This is a high-visibility, high-impact team that operates at the intersection of data, security engineering, and organizational risk management.
What You’ll Do
Vulnerability Identification & Risk Scoring
- Own and continuously refine Walmart CVSS scoring vectors and risk ratings for vulnerabilities ingested into WalSec Radar (WSR), incorporating asset criticality, business context, exploitability data (EPSS), and threat intelligence (CISA KEV catalog).
- Validate and triage vulnerability findings from multiple data sources: Tenable (endpoint & infrastructure scans), Snyk (container and SAST/SCA), Tanium (PCI endpoint scanning), Wiz (cloud misconfiguration), and ReSTART (penetration test findings from APT, ACR, NPT, NST, and Bugcrowd).
- Identify, investigate, and remediate false positives in scan data; improve signal-to-noise ratio across all data sources.
- Develop and maintain Diesel Rules (regex-based ownership matching logic) within WSR to ensure accurate and automated vulnerability ownership assignment at scale.
- Conduct asset-level PCI scope management and ensure compliance-driven vulnerability data is accurately captured for PCI 4.0 requirements.
Remediation Program Management
- Act as a primary liaison between the TVM team and engineering / infrastructure owners across Walmart IDC, driving accountability for vulnerability remediation within defined SLAs (Critical: 15 days, High: 30 days, Medium: 90 days).
- Track remediation progress end-to-end — from identification through patching, configuration hardening, or compensating controls — and validate closure via re-scan or manual validation.
- Facilitate exception management workflows, including risk acceptance, compensating controls documentation, and escalation to leadership when SLA breach risk is elevated.
- Partner with Security Partners (TISA, TCA, CAV) to embed vulnerability remediation checkpoints into Walmart's software delivery and deployment pipelines (Concord, KITT, WCNP).
Reporting & Analytics
- Build and maintain executive-facing dashboards and operational reports on vulnerability posture, including KPIs such as MTTR, scan coverage percentage, vulnerability aging, and risk reduction trends.
- Deliver regular vulnerability status briefings to senior engineering leadership and the CISO organization.
- Produce ad hoc analysis on emerging threat campaigns, zero-day exploits, and their potential impact on Walmart's asset inventory.
- Contribute to quarterly risk reports aligned with Walmart's enterprise risk management framework.
Tool & Platform Ownership
- Serve as a subject matter expert (SME) for WSR platform configurations — including ownership assignment logic, risk scoring customizations, and data source integration health.
- Collaborate with the WSR platform team (IDA) to troubleshoot data ingestion issues, inaccurate ownership assignments, and reporting anomalies.
- Evaluate and recommend new vulnerability data sources, scanning methodologies, or tooling enhancements to expand coverage and improve fidelity.
- Governance, Compliance & Standards
- Ensure alignment of vulnerability management activities with industry frameworks: NIST SP 800-40, NIST CSF, ISO 27001, CIS Controls, and PCI DSS 4.0.
- Support audit and compliance engagements (internal audit, PCI QSA assessments) by providing evidence of scanning coverage, remediation SLA adherence, and risk scoring methodology.
- Develop and maintain vulnerability management Standard Operating Procedures (SOPs), runbooks, and process documentation.
What You’ll bring
Education
Bachelor's degree (or higher) in Computer Science, Information Technology, Cybersecurity, or a related engineering discipline
Equivalent experience (8+ years in cybersecurity with a focus on vulnerability management)
- Experience
- Total Experience: 8–12 years in Information Technology
- Cybersecurity Experience: 6+ years with a focus on vulnerability management, threat intelligence, or security operations
- Vulnerability Management Specifically: 4+ years of hands-on, enterprise-scale vulnerability management program ownership
- Cloud Environment Experience: 2+ years managing vulnerabilities in public cloud (Azure, GCP, or AWS)
- Leadership / Influence: Demonstrated experience driving cross-team remediation programs
- Technical Skills
- Vulnerability Management: 6+ years of hands-on experience with enterprise vulnerability management programs - scanning, triage, prioritization, remediation tracking, and reporting
- CVSS Scoring: Deep expertise in CVSS v3.x and v4.0- Base, Temporal, Environmental, and Threat metric groups; ability to craft and justify Walmart-specific CVSS vectors
- Scanning Tools: Proficiency with two or more: Tenable Nessus / Tenable.io / Tenable.sc, Qualys, Rapid7 InsightVM
- Cloud Security: Vulnerability management in cloup environments - Azure, GCP; familiarity with Wiz or similar CNAPP tools for cloud misconfigurations and CVE management
- Container Security: Experience with Snyk Container, Trivy, or equivalent tools for scanning container images and WCNP workloads
- Threat Intelligence Integration: Working knowledge of EPSS, CISA KEV catalog, NVD, CVE databases to contextualize and prioritize remediation
- Scripting & Automation : Proficiency in Python or PowerShell for automating vulnerability data processing, report generation, and API integrations with ITSM/CMDB systems
- SIEM & Log Analysis: Ability to correlate vulnerability data with SIEM telemetry (Splunk, Microsoft Sentinel, or equivalent) to identify active exploitation signals
- Risk Communication: Strong ability to translate technical vulnerability data into risk narratives for non-technical leadership audiences
- Patch & Asset Management: Familiarity with enterprise patch management workflows, asset inventory systems (CMDB / ServiceNow), and their role in vulnerability lifecycle management
- Security Domain Knowledge (Good to have)
- Penetration Testing Fundamentals
- DevSecOPs - Experience integrating security scanning into CI/CD pipelines (Concord, Jenkins, GitHub Actions); SAST/DAST/SCA tooling
- Hands-on experience with PCI 4.0 compliance requirements, authenticated scanning, and scope management
- Ability to query large vulnerability datasets using SQL/ BigQuery for trend analysis and custom reporting
- Soft Skills & Collaboration
Exceptional analytical and problem-solving mindset - ability to manage ambiguity and drive clarity Strong stakeholder management - influence and drive outcomes without direct authority over engineering teams Excellent written and verbal communication - comfortable presenting to senior leadership and executive audiences Collaborative and cross-functional mindset - works effectively with globally distributed teams across time zones High ownership culture - takes accountability for outcomes, not just activities Continuous learning orientation - stays current with the evolving threat and vulnerability landscape
- Certifications (Good to Have)
- CompTIA Security+
- CompTIA CySA+ (Cybersecurity Analyst)
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- GIAC Vulnerability Assessment (GEVA)
- CISM (Certified Information Security Manager)
About Walmart Global Tech
Imagine working in an environment where one line of code can make life easier for hundreds of millions of people. That’s what we do at Walmart Global Tech. We’re a team of software engineers, data scientists, cybersecurity expert's and service professionals within the world’s leading retailers who make an epic impact and are at the forefront of the next retail disruption. People are why we innovate, and people power our innovations. We are people-led and tech-empowered.
We train our team in the skillsets of the future and bring in experts like you to help us grow. We have roles for those chasing their first opportunity as well as those looking for the opportunity that will define their career. Here, you can kickstart a great career in tech, gain new skills and experience for virtually every industry, or leverage your expertise to innovate on a scale, impact millions and reimagine the future of retail.
We’re back to work
Walmart’s culture sets us apart, and we know being together helps us innovate, learn and grow great careers. This role is based in our Bangalore office for daily work, with flexibility for associates to manage their personal lives.
Benefits
Beyond our great compensation package, you can receive incentive awards for your performance. Other great perks include a host of best-in-class benefits maternity and parental leave, PTO, health benefits, and much more.
Belonging
We aim to create a culture where every associate feels valued for who they are, rooted in respect for the individual. Our goal is to foster a sense of belonging, to create opportunities for all our associates, customers and suppliers, and to be a Walmart for everyone.
At Walmart, our vision is "everyone included." By fostering a workplace culture where everyone is—and feels—included, everyone wins. Our associates and customers reflect the makeup of all 19 countries where we operate. By making Walmart a welcoming place where all people feel like they belong, we’re able to engage associates, strengthen our business, improve our ability to serve customers, and support the communities where we operate.
Equal Opportunity Employer
Walmart, Inc., is an Equal Opportunities Employer – By Choice. We believe we are best equipped to help our associates, customers and the communities we serve live better when we really know them. That means understanding, respecting and valuing unique styles, experiences, identities, ideas and opinions – while being inclusive
Minimum Qualifications...
Outlined below are the required minimum qualifications for this position. If none are listed, there are no minimum qualifications.
Option 1: Bachelor's degree in computer science, information technology, engineering, information systems, cybersecurity, or related area and 4years’ experience in cybersecurity risk or related area at a technology, retail, or data-driven company. Option 2: 6 years’ experience in cybersecurity risk or related area at a technology, retail, or data-driven company.Preferred Qualifications...
Outlined below are the optional preferred qualifications for this position. If none are listed, there are no preferred qualifications.
Certification in Security+, GISF, GSEC, CISA, CISSP, CCSP, or CISM, Master’s degree in computer science, information technology, engineering, information systems, cybersecurity or related area and 2 years’ experience leading information security or cybersecurity projects