| Skills/Experience: | Minimum Qualifications Additional Experience- 8+ years of combined hands-on vulnerability management and/or cyber risk management work experience with a broad exposure to infrastructure/network and multi-platform environments.
Knowledge, Skills, Abilities Key Responsibilities Vulnerability Investigation & Validation- Investigate and validate vulnerabilities identified through enterprise vulnerability scanning and aggregation platforms, including Rapid7 InsightVM/Nexpose, Qualys, and Nucleus.
- Perform technical analysis beyond scanner output to determine whether vulnerabilities are valid, applicable, exploitable, or otherwise relevant within the context of the affected environment.
- Research CVEs, vendor advisories, security bulletins, affected versions, patches, mitigations, exploitability, and other technical information necessary to accurately assess vulnerability risk.
- Analyze affected infrastructure, middleware, operating systems, network technologies, platforms, and DevOps technologies to understand vulnerability applicability and appropriate remediation.
- Identify potential false positives, configuration issues, version discrepancies, or other conditions requiring additional investigation.
- Work directly with technical teams to gather evidence, validate findings, troubleshoot discrepancies, and determine appropriate remediation or mitigation approaches.
Vulnerability Management Operations- Execute established vulnerability management processes and runbooks consistently and independently.
- Provide backup support for day-to-day and on-call vulnerability management activities, including investigation and coordination of newly identified or time-sensitive vulnerabilities.
- Triage vulnerability findings and determine appropriate actions based on severity, exposure, exploitability, affected technology, and established enterprise requirements.
- Create and distribute vulnerability advisories that clearly communicate affected technologies, risk, required actions, remediation guidance, and timelines.
- Create, route, track, and follow up on remediation tickets with responsible technology teams.
- Monitor outstanding vulnerability work and proactively engage stakeholders to drive remediation to completion.
- Support both newly identified vulnerabilities and existing vulnerability backlog as needed.
- Maintain accurate records and documentation throughout the vulnerability lifecycle.
Risk Acceptance- Facilitate established vulnerability risk acceptance processes for findings that cannot be remediated within required timelines.
- Work with technical teams to understand remediation constraints, compensating controls, exposure, and residual risk.
- Review existing risk acceptances approaching expiration and coordinate remediation, renewal, or escalation as appropriate.
- Ensure risk acceptance documentation is technically accurate, clearly written, and completed in accordance with established processes and approval requirements.
- Communicate effectively with engineers, managers, and technology leadership regarding vulnerability risk and remediation decisions.
Stakeholder Partnership & Communication- Build productive working relationships with infrastructure, middleware, DevOps, application, security, and other technology teams.
- Serve as a knowledgeable and pragmatic vulnerability management partner rather than simply distributing scanner findings.
- Explain vulnerabilities, technical risk, remediation requirements, and security expectations clearly to stakeholders with varying levels of security expertise.
- Adapt communication appropriately for hands-on engineers, technical managers, and technology leadership.
- Navigate disagreements or questions regarding vulnerability validity, severity, remediation, or risk professionally and collaboratively while maintaining security requirements.
- Produce clear, concise, technically accurate written communications, including advisories, remediation tickets, risk acceptance documentation, and stakeholder updates.
Skills/Experience Required- Significant hands-on experience in vulnerability management, vulnerability analysis, infrastructure security, or a closely related security engineering discipline.
- Senior-level understanding of vulnerabilities, including CVEs, CVSS, vulnerability applicability, exploitability, remediation, mitigation, and false-positive validation.
- Demonstrated ability to independently investigate and validate vulnerability findings rather than relying solely on vulnerability scanner results or severity ratings.
- Strong technical understanding of enterprise infrastructure, including operating systems, networking, middleware, servers, common enterprise platforms, and related technologies.
- Experience with enterprise vulnerability scanning and/or vulnerability management platforms such as Rapid7 InsightVM/Nexpose, Qualys VM, Nucleus, or comparable technologies.
- Ability to research and interpret vendor security advisories, CVE information, scanner evidence, software versions, patches, configurations, and other technical data when assessing vulnerability findings.
- Experience coordinating vulnerability remediation with infrastructure, platform, middleware, DevOps, or other technical engineering teams.
- Ability to learn and consistently execute established operational processes and runbooks with minimal oversight.
- Strong organizational skills and ability to independently manage multiple concurrent vulnerability investigations, remediation efforts, and stakeholder interactions.
- Excellent written and verbal communication skills.
- Strong interpersonal and relationship-management skills, with demonstrated ability to work effectively with both highly technical engineers and technology leadership.
Preferred- Direct experience with Rapid7 InsightVM/Nexpose, Nucleus, and/or Qualys Vulnerability Management.
- Experience supporting enterprise-scale vulnerability management programs and large, heterogeneous technology environments.
- Experience managing vulnerability advisories, remediation ticketing workflows, vulnerability exceptions, and/or formal risk acceptance processes.
- Experience investigating vulnerabilities affecting middleware, infrastructure platforms, network technologies, operating systems, containers, or DevOps tooling.
- Familiarity with vulnerability intelligence sources, exploitability analysis, CISA KEV, EPSS, vendor advisories, and other risk-prioritization inputs.
- Experience working within defined vulnerability remediation SLAs and escalation processes.
- Familiarity with workflow/ticketing platforms such as Jira or Ivanti.
|