Lead Engineer - Exposure Management in Bengaluru, KA, IN - DISH TV | Job Apply

Lead Engineer - Exposure Management

Bengaluru, KA, IN

Job type:

Fulltime-Regular

Resume required:

Yes

Street Address:

SALARPURIA SATTVA EMINENCE

Posted date:

2026-09-24

Full job description:

Company Summary

DISH Network Technologies India Pvt. Ltd is a technology subsidiary of EchoStar. Our organization is at the forefront of technology, serving as a disruptive force and driving innovation and value on behalf of our customers.

Our product portfolio includes Boost Mobile (consumer wireless), DISH TV (direct broadcast satellite), Sling TV (over-the-top service provider), Hughes (global satellite connectivity solutions) and Hughesnet (satellite internet).

Our facilities in India are some of EchoStar's largest development centers outside the U.S. As a hub for technological convergence, our engineering talent is a catalyst for innovation in multimedia network and communications development.

EchoStar does not charge any fees to job applicants or candidates at any point during the recruitment and hiring process. We strongly advise all individuals to be vigilant and disregard any unsolicited requests for payment or personal financial information related to an EchoStar employment opportunity.

Our Technology teams challenge the status quo and reimagine capabilities across industries. Whether through research and development, technology innovation or solution engineering, our people play vital roles in connecting consumers with the products and platforms of tomorrow.

Job Duties and Responsibilities

As part of the expanding InfoSec Center of Excellence at BTC, DISH is scaling its daily Vulnerability Assessment and Penetration Testing (VA/PT) operations. The Lead / Staff Operational Security Engineer will serve as the operational backbone and technical authority for the vulnerability lifecycle. This role focuses on maintaining operational excellence across hybrid environments, leading response operations for critical threats, and acting as the primary operational bridge to software and platform teams—defining specific automation requirements and validating automated solutions to scale scanning, triage, and reporting operations.

KEY RESPONSIBILITIES

Operational Execution & Vulnerability Lifecycle Management

  • Oversee and execute day-to-day VA/PT operational workflows across hybrid infrastructure (AWS, GCP, Azure, and legacy data centers) to guarantee scanning coverage, accurate triage, and SLA enforcement.
  • Lead operational response efforts for emergency vulnerabilities, zero-day outbreaks, and active exploitation threats, coordinating war rooms and rapid mitigations across IT and Business units.
  • Analyze complex vulnerabilities to eliminate false positives, evaluate real-world exploitability, and establish strict prioritization using threat intelligence (CVE, CISA KEV, IOCs) and CVSS/SSVC metrics.
  • Drive end-to-end remediation tracking with system, network, and application owners, maintaining tight oversight on vulnerability aging, SLAs, and exception/deferral workflows.
  • Establish and monitor daily operational Key Performance Indicators (KPIs) and metrics, delivering actionable reports to operational leadership and audit teams.

Automation Requirements & Validation

  • Translate daily operational bottlenecks and manual testing workflows into actionable automation requirements for the InfoSec Engineering and DevOps teams.
  • Establish test plans and rigorously validate all incoming automation initiatives, scripts, API integrations, and CI/CD security gates developed by engineering teams before production rollout.
  • Define requirements for automated tool configuration, automated asset discovery, ticket creation workflows, and shift-left scanning triggers to maximize operational throughput.

People Leadership & Operational Governance

  • Lead, direct, and mentor a high-performing team of operational VA/PT analysts, establishing clear operational playbooks and standard operating procedures (SOPs).
  • Manage day-to-day operational schedules, workload distribution, shift coverage, and ticket escalation queues.
  • Oversee operational relationships with third-party scanning vendors, external penetration testing teams.

Skills, Experience and Requirements

KNOWLEDGE, SKILLS & ABILITIES

  • Operational & Technical Expertise: Deep operational mastery of vulnerability scanning engines, threat intelligence feeds, manual verification techniques, and network/application infrastructure protocols.
  • Automation Drive: Expert ability to analyze operational workflows, author technical requirement documents (PRDs/epics) for tool integration, and perform acceptance testing on delivered automated tools.
  • Tooling Operations: Hands-on operational administration of enterprise tools such as Qualys, Nessus, Synk, XSIAM, Invicti/Netsparker, Twistlock/Prisma Cloud, Metasploit, Burp Suite Pro, and ticketing platforms (Jira, ServiceNow).
  • Frameworks & Compliance: Strong operational application of NIST SP 800-53, OWASP Top 10, CIS Benchmarks, and regulatory requirements (PCI-DSS, ISO).
  • Scripting Literacy: Proficiency in Python, PowerShell, or Bash to independently verify operational scripts, review automation code, and validate API behavior.

REQUIRED EDUCATION, CERTIFICATIONS & EXPERIENCE

  • Experience: 10+ years of hands-on experience in security operations, vulnerability management, or penetration testing, including 3+ years in an operational lead or supervisory capacity.
  • Education: Bachelor’s or Master’s degree in Computer Science, Information Security, Network Engineering, or a related discipline.

Benefits

  • Insurance and Wellbeing
  • Financial & Retiral Benefit Program
  • Mental Wellbeing
  • Employee Stock Purchase Program (ESPP)
  • Professional Development Reimbursement
  • Time Off
  • Team Outings

We pride ourselves on developing and promoting talent as an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. EchoStar will accommodate the sincerely held religious beliefs of employees if such accommodations are not undue hardships and are otherwise within the bounds of applicable law. All qualified applicants with arrest or conviction records will be considered for employment in accordance with local, state, and federal law. You may redact any information that identifies age, date of birth, or dates of school/graduation from your application documents before submission and throughout our application process.

EchoStar will provide reasonable accommodation to otherwise qualified job applicants and employees with known physical or mental disabilities, unless doing so poses an undue hardship on the Company, poses a direct threat of substantial harm to others, or is otherwise not required by law. EchoStar has a more detailed Accommodation Policy that applies to employees. EchoStar endeavors to make echostar.com and jobs.echostar.com accessible to users. Please contact [email protected] if you would like to discuss the accessibility of our website or need assistance completing the application process. This contact information is for accommodation requests only; do not use this contact information to inquire about the status of applications.

Click the links to access the following statements: EEO Policy StatementPay Transparency, EEOC Know Your Rights (English/Spanish)

Job reference:

2026-100671

Add your contact information