Gruve
Cyber Threat Exposure Management Lead
Pune, Maharashtra, India
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Lead / management
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 22 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About Gruve
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.
Position summary:
We are looking for an experienced CTEM (Continuous Threat Exposure Management) Expert to lead the design, implementation, and continuous operation of exposure management programs for our clients. This role sits at the intersection of vulnerability management, attack surface management, threat intelligence, and risk-based remediation helping clients move from periodic point-in-time assessments to a continuous, adversary-informed exposure reduction program aligned with 5-stage CTEM framework (Scoping, Discovery, Prioritization, Validation, and Mobilization).
You will work directly with client CISOs, security operations teams, and IT owners to build programs that identify, prioritize, validate, and reduce cyber exposure across on-prem, cloud, and hybrid environments and demonstrate measurable reduction in exploitable risk over time.
Key Roles & Responsibilities:
Lead end-to-end delivery of CTEM engagements across the five stages: Scoping, Discovery, Prioritization, Validation, and Mobilization
Design and operationalize continuous exposure management programs tailored to client risk appetite, industry, and regulatory context
Integrate and correlate data across vulnerability management, attack surface management (ASM), cloud security posture management (CSPM), threat intelligence, and breach & attack simulation (BAS) tools to build a unified exposure view
Translate technical findings (CVEs, misconfigurations, exposed assets, identity risks) into business-risk-prioritized remediation plans using exploitability, asset criticality, and threat context (e.g., KEV, EPSS, active exploitation campaigns)
Drive adversarial validation of exposures through coordination with red/purple teams, pentesters, or automated validation platforms to confirm real-world exploitability
Own exposure reduction metrics and reporting and present progress to client stakeholders and leadership
Coordinate remediation and patch/mitigation execution with client asset owners, IT, and SOC teams; manage emergency response for zero-days and actively exploited vulnerabilities
Build and refine CTEM playbooks, runbooks, and governance frameworks; establish exception and risk-acceptance processes
Support pre-sales activities — scoping calls, proposals, PoCs, and CTEM maturity assessments for prospective clients
Mentor junior consultants/analysts and contribute to practice capability building, including tool evaluation and methodology development
Stay current on the threat landscape, emerging attack techniques, and CTEM tooling ecosystem.
Mandatory Qualifications:
BE/BTech (CS/IT/E&TC) or equivalent.
5–10 years of overall cybersecurity experience, with 3+ years in exposure management, vulnerability management, attack surface management, or red team/adversary simulation
Strong hands-on experience with CTEM/exposure management platforms such as Tenable (Exposure Management/One), Qualys VMDR/ETM, CrowdStrike Falcon Exposure Management, or similar
Practical experience with attack surface management (ASM) tools and breach & attack simulation (BAS) platforms
Solid understanding of vulnerability prioritization frameworks: CVSS, EPSS, CISA KEV, exploit maturity, and asset-criticality-based risk scoring
Experience integrating exposure data with SIEM/SOAR, ticketing (ServiceNow, Jira), and patch management tools.
Familiarity with cloud security posture (AWS, Azure, GCP) and CSPM tools, and how cloud exposures fit into a unified CTEM program
Strong grasp of the MITRE ATT&CK framework and how attack-path/graph analysis supports validation and prioritization
Experience defining and reporting exposure/remediation KPIs (MTTD, MTTR, MTRER, risk reduction trend lines) to executive and client audiences
Working knowledge of relevant compliance/regulatory frameworks
Excellent client-facing communication skills — able to translate technical exposure data into business risk narratives for CISOs and boards
Preferred Qualifications:
Relevant certifications: CISSP, CISM, Tenable/Qualys certifications
Experience building or scaling a CTEM-as-a-Service offering within an MSSP/consulting practice
Experience with pre-sales, proposal writing, and CTEM maturity/readiness assessments
Prior experience mentoring teams or leading a practice/pod within a cybersecurity consulting or MSSP environment
Why Gruve
At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.
Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.
Similar jobs
- Senior Product Manager - Aurora Exposure Management ASMArcticwolf · Bengaluru, INDFirst seen 3d ago
- Senior Product Manager - Exposure ManagementArcticwolf · Bengaluru, INDFirst seen 18d ago
- Info Security Exposure Management Specialist I BGhr · 2 LocationsFirst seen yesterday
- Senior Cybersecurity Engineer – Exposure ManagementSyneoshealth · IND-Hyderabad-HybridFirst seen 3d ago
- Purple Team Engineer – Risk & Exposure ManagementCardinalhealth · IND07First seen 3d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job