Architect I
Gurugram Gurgaon HR, IN
Requisition Number: 105821
Architect 1 (Cyber Exposure)
Location: This is a hybrid opportunity in Delhi NCR, Bangalore, Hyderabad, Gurugram area.
Shifts: 7:00 PM IST- 4:00 AM IST
- 14,000+ engaged teammates globally with operations in 25 countries across the globe.
- Received 35+ industry and partner awards in the past year
- $9.2 billion in revenue
- #20 on Fortune’s World's Best Workplaces™ list
- #14 on Forbes World's Best Employers in IT – 2023
- #23 on Forbes Best Employers for Women in IT- 2023
- $1.4M+ total charitable contributions in 2023 by Insight globally
Now is the time to bring your expertise to Insight. We are not just a tech company; we are a people-first company. We believe that by unlocking the power of people and technology, we can accelerate transformation and achieve extraordinary results. As a Fortune 500 Solutions Integrator with deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organisations through complex digital decisions.
About the role
The Lead Attack Surface Analyst is a player-coach who blends hands-on delivery with day-to-day leadership of the Attack Surface Support Analyst team. In addition to performing a subset of analyst responsibilities — operating vulnerability management tooling, validating exposures, and overseeing agentic remediation workflows — the Lead is accountable for the quality, consistency, and continuous improvement of Insight’s CTEM & CPEN service. As the program evolves, the Lead refines roles, processes, automation, and client deliverables based on operational learnings, ensuring the service scales and matures while sustaining high client satisfaction and SLA performance.
Key Responsibilities:
- Team Leadership & Daily Management
- Provide daily direction and work prioritization for the Attack Surface Support Analyst team, balancing workload across active engagements.
- Mentor and develop analysts through coaching, quality reviews, and performance feedback in partnership with management.
- Serve as the primary escalation point for complex findings, contested risk acceptances, and client concerns.
- Monitor delivery quality and SLA adherence across the client portfolio and report status to practice leadership.
- Hands-On Attack Surface Analysis (Player Component)
- Perform analyst-level work as needed — operate Qualys and related tooling, validate high-risk exposures, and drive prioritization on the most critical or sensitive engagements.
- Govern automated and agentic workflows for validation, prioritization, and remediation dispatch, maintaining human-in-the-loop oversight and appropriate confidence thresholds.
- Partner with Managed Infrastructure Services on remediation strategy, compensating controls, and verification of closure.
- Continuous Improvement & Program Refinement
- Refine and enhance the CTEM & CPEN roles runbooks, and operating procedures based on learnings as the programs evolve.
- Tune detection content and automation including prioritization logic, orchestration playbooks, and agentic decision frameworks.
- Define and track service KPIs identify efficiency and maturity opportunities, and lead their implementation.
- Standardize onboarding, reporting templates, and proof-of-execution artifacts across the client portfolio.
- Client Engagement & Advisory
- Lead complex or strategic client onboardings and support onboarding of all new CTEM & CPEN clients.
- Represent the service in exposure reviews, QBRs, and escalations communicating risk posture and remediation strategy to technical and executive stakeholders.
- Collaborate with sales engineering and practice leadership on scoping, service evolution, and client expansion.
What we’re looking for
- 9-12+ years in vulnerability management, security operations, penetration testing, or related cybersecurity disciplines, including 1–2+ years of team lead, mentorship, or people-management responsibility.
- Advanced, hands-on expertise with Qualys (VMDR/TruRisk) or an equivalent enterprise VM platform, including administration and tuning.
- Demonstrated experience designing or refining vulnerability/exposure management processes, SLAs, and runbooks.
- Strong command of CTEM frameworks, risk-based prioritization (CVSS/EPSS/asset criticality), and the end-to-end remediation lifecycle.
- Experience overseeing security automation/orchestration; familiarity with agentic or AI-assisted security operations is a strong plus.
- Proven client-facing delivery experience in an MSSP/MXDR or consulting environment.
- Bachelor’s degree in a related field or equivalent experience.
- Advanced certifications such as CISSP, OSCP, GPEN, GWAPT, GIAC GEVA, or Qualys VMDR Specialist.
- Experience with continuous/automated penetration testing platforms (NodeZero, Pentera, Cymulate) and adversary emulation.
- Scripting and automation proficiency (Python, PowerShell, KQL) and ServiceNow workflow design.
- Familiarity with NIST CSF, CIS Controls v8, and regulated-industry compliance (HIPAA/HITECH, PCI DSS, CMMC).
- Prior experience standing up or maturing a managed security service offering.
What you can expect
We’re legendary for taking care of you, your family and to help you engage with your local community. We want you to enjoy a full, meaningful life and own your career at Insight. Some of our benefits include:
- Freedom to work from another location—even an international destination—for up to 30 consecutive calendar days per year.
- Medical Insurance
- Health Benefits
- Professional Development: Learning Platform and Certificate Reimbursement
- Shift Allowance
But what really sets us apart are our core values of Hunger, Heart, and Harmony, which guide everything we do, from building relationships with teammates, partners, and clients to making a positive impact in our communities.
Join us today, your ambITious journey starts here.
When you apply, please tell us the pronouns you use and any reasonable adjustments you may need during the interview process.
At Insight, we celebrate diversity of skills and experience so even if you don’t feel like your skills are a perfect match - we still want to hear from you!
Today's talent leads tomorrow's success. Learn more about Insight:
https://www.linkedin.com/company/insight/
Insight does not accept unsolicited resumes from recruiters or employment agencies. Unsolicited resumes will be treated as direct applications from the candidate, and recruiters or agencies who submit candidates for this position without a prior, written vendor agreement will not be eligible for any form of compensation, even if the candidate is hired.
Insight is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, sexual orientation or any other characteristic protected by law.
Insight India Location:Level 16, Tower B, Building No 14, Dlf Cyber City In It/Ites Sez, Sector 24 &25 A Gurugram Gurgaon Hr 122002 India
Job Segment:
Cyber Security, Sales Engineer, Social Media, Consulting, Architecture, Security, Sales, Marketing, Technology, Engineering