ViaSat Inc logo

Senior Security Specialist, Vulnerability Management

ViaSat Inc

  • Carlsbad, CA
  • 2 days ago
  • $150,000–$225,000 Per Year

Highlights

Defending Technical Risk Decisions: Demonstrated ability to confidently explain vulnerability prioritizations, technical workarounds, and formal risk acceptance/exception decisions to both internal compliance teams and external auditors. Determine the Optimal Mitigation Path: Prioritize what needs to be fixed and how to do it efficiently-whether that means coordinating a full software/OS update, deploying a temporary configuration workaround, or implementing compensating security controls.

Numbers & Facts

LocationCarlsbad, CA
IndustryTelecommunications Services
Salary$150,000–$225,000 Per Year
Company Size2,500 to 4,999 employees
Year Founded1986
Websitehttp://www.viasat.com/company/about/about-viasat

Description

About us

One team. Global challenges. Infinite opportunities. At Viasat, we're on a mission to deliver connections with the capacity to change the world. For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries around the globe communicate. We're looking for people who think big, act fearlessly, and create an inclusive environment that drives positive impact to join our team.

What you'll do

  • Vulnerability Prioritization: Efficiently evaluate and respond to the daily influx of newly disclosed CVEs, cutting through the noise to separate theoretical risks from immediate, real-world threats to our business
  • Determine the Optimal Mitigation Path: Prioritize what needs to be fixed and how to do it efficiently-whether that means coordinating a full software/OS update, deploying a temporary configuration workaround, or implementing compensating security controls.
  • Navigate System Ownership: Track down and identify the exact system owners and engineering teams responsible for vulnerable assets, ensuring every high-priority vulnerability is routed to the right person for swift remediation.
  • Scale the Program via Automation: Design concepts and build them with fellow security engineers to automate the process allowing us to handle a high volume of threats without increasing manual overhead.
  • Assist with Audits and Regulatory Alignment: Function as the technical representative during internal and external audit reviews.
  • Collaborate directly with auditors to illustrate program maturity and detail vulnerability scanning methodologies.
  • Create automated dashboards to track operational efficiency metrics, including Mean Time to Detect (MTTD) relevant CVEs and Mean Time to Remediate (MTTR).
  • Lead Zero-Day Assessments: Serve as the VM initial responder during urgent, zero-day vulnerability revelations. Quickly scope our exposure, assess the blast radius across infrastructure and codebases, and coordinate response efforts.
  • Develop automated data visualizations and reporting tools. These tools retrieve audit evidence on demand, such as proof of patching SLA adherence, historical scanning cadences, and approved risk exceptions. This reduces time spent on manual preparation.

The day-to-day

  • Tactical Threat Triage: Analyze internal data against advisories to identify critical risks relevant to our infrastructure and work to mitigate them.
  • Lead Zero-Day Assessments: Function as the VM first-responder during critical, zero-day disclosures. Rapidly determine our exposure, evaluate the blast radius throughout infrastructure and codebases, and coordinate response efforts.
  • Scale Reporting Metrics: Design automated dashboards that track operational efficiency metrics, such as Mean Time to Detect (MTTD) relevant CVEs and Mean Time to Remediate (MTTR).
  • Support Audits & Regulatory Compliance: Serve as the technical point of contact during internal and external audits. Interface directly with auditors to demonstrate program maturity and explain vulnerability scanning methodologies.

What you'll need

  • Experience: 5+ years of experience in Vulnerability Management, with at least 3 years dedicated specifically to tactical vulnerability management.

  • Risk-Prioritization: In-depth knowledge of modern vulnerability evaluation frameworks, including EPSS, CVSS, SSVC, and KEV.

  • Audit Defense: Demonstrable experience preparing for and participating in external third-party security audits (e.g., ISO 27001, PCI, or CMMC).

  • Defending Technical Risk Decisions: Demonstrated ability to confidently explain vulnerability prioritizations, technical workarounds, and formal risk acceptance/exception decisions to both internal compliance teams and external auditors.

  • Tooling Proficiency: Deep hands-on experience with enterprise scanners and cloud-native security platforms.

  • Technical Depth: Good understanding of operating system internals, container environments, and cloud security fundamentals.

  • Communication & Influence: Demonstrable ability to translate complex vulnerability details into clear, actionable technical instructions for engineering partners without direct authority.

  • Tactical Threat Triage: Analyze internal data against new CVEs and vulnerability disclosures to identify critical risks relevant to our infrastructure and work to mitigate them.

  • Lead Zero-Day Assessments: Act as the VM first-responder during critical, zero-day disclosures. Quickly scope our exposure, assess the blast radius across infrastructure and codebases, and coordinate response efforts.

  • Scale Reporting Metrics: Design automated dashboards that track operational efficiency metrics, such as Mean Time to Detect (MTTD) relevant CVEs and Mean Time to Remediate (MTTR).

  • Support Audits & Regulatory Compliance: Serve as the technical point of contact during internal and external audits. Interface directly with auditors to demonstrate program maturity and explain vulnerability scanning methodologies.

  • Build automated reports and dashboards that pull audit evidence on demand. Examples include proof of patching SLA alignment, historical scanning cadences, and approved risk exceptions. This reduces manual preparation time.

What will help you on the job

  • Artificial Intelligence: Familiarity/Experience with AI technologies, with a strong preference for knowledge in AI risk and governance frameworks (experience applying these concepts to vulnerability management is a major plus).

  • Penetration Testing: Experience with penetration testing methodologies and tools to help validate vulnerability exploitability and assist with remediation prioritization.

  • Workflow Automation: Prior experience building security pipelines inside automation and orchestration platforms.

  • CI/CD: Familiarity with CI/CD tools and automated configuration/deployment environments.

  • Active Security Community Engagement: A passion for following emerging threats, exploit trends, and security research.

  • Industry Certifications: SANS GPEN or GEVA.

  • Web Applications: experience in assessments or penetration testing of web applications and Internet-facing tech stacks.

Salary range

$121,000.00 - $191,000.00 / annually. For specific work locations within San Jose, the San Francisco Bay area and New York City metropolitan area, the base pay range for this role is $150,000.00- $225,000.00/ annually

At Viasat, we consider many factors when it comes to compensation, including the scope of the position as well as your background and experience. Base pay may vary depending on job-related knowledge, skills, and experience. Additional cash or stock incentives may be provided as part of the compensation package, in addition to a range of medical, financial, and/or other benefits, dependent on the position offered. Learn more about Viasat's comprehensive benefit offerings that are focused on your holistic health and wellness at https://careers.viasat.com/benefits.

EEO Statement

Viasat is proud to be an equal opportunity employer, seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, ancestry, physical or mental disability, medical condition, marital status, genetics, age, or veteran status or any other applicable legally protected status or characteristic. If you would like to request an accommodation on the basis of disability for completing this on-line application, please click here.

About Company

Digital Communication Products for Commercial and Government Markets

ViaSat produces innovative satellite and other digital communication products that enable fast, secure, and efficient communications to any location. We bring today’s new communication applications to people out of reach of terrestrial networks, in both the commercial and government sectors, with a variety of networking products and services.

Here you’ll find a company that is always asking,” What’s next?”, with the vertically integrated set of technologies to push the limits of what is possible for your system and service performance.

Products:

  • Satellite networks for fixed-site and mobile communications
  • Satellite antenna systems
  • Wireless datalinks and terminals for combat situational awareness
  • Cybersecurity and Information Assurance for military networking and encrypted data storage
  • Mobile IP networking for soldiers
  • Communication microprocessor chipsets
  • Application and communication acceleration
  • Satellite network and RF system design
  • Communication simulation and training systems

Services:

  • Global mobile satellite services for government and commercial aircraft, vehicles, and seagoing vessels
  • Satellite Internet access and other broadband services for consumers, business, and government customers in the U.S.
Recognized for Innovation, Growth, and Stability

With these past awards, ViaSat is well known as a successful, innovative, high-growth company:

  • World Technology Network - 2013 Winner, Communications Technology Award for high-capacity satellite system
  • Arthur C. Clarke Foundation - Innovator Award, CEO Mark Dankberg
  • Edison Awards 2013 - Bronze award for communications innovation
  • Popular Science 2012 "Best of What's New" for Exede Internet and high-capacity satellite system
  • Satellite Research and Markets - 2012 Visionary Executive of the Year
  • Society of Satellite Professionals International (SSPI) - 2012 Industry Innovator
  • TechAmerica - 2011 American Technology Award in the Telecommunications
  • Space News "Top 50 Space Companies"
  • San Diego Magazine "Made In San Diego: 11 Cool Companies"
  • Mark Dankberg American Institute of Aeronautics and Astronautics (AIAA) "2008 Aerospace International Communications Award"
  • Hannover Fairs ISCe2004 Satellite Industry Award for Innovation and Technology
  • Mark Dankberg Via Satellite “2003 Satellite Executive of the Year”
  • Defense Systems "Super 75"
  • DefenseNews "Top 100 Defense Contractors"
  • DefenseNews "Fast Track 50"
  • Washington Technology "Top 100 Federal Prime Contractors"
  • Three-time INC. 500 prior to going public in 1996


Surpassing 2,900 Employees and $1 Billion in Sales

The company employs over 2,900 professional and support personnel. The largest department is engineering, with many holding graduate degrees in electrical engineering or computer science. Annual revenues hit a record $1.1 billion during the most recently completed fiscal year (ended March 29, 2013).

History

ViaSat is part of the well-known Linkabit Corporation “family-tree” that spawned hundreds of San Diego area telecom startups, including Qualcomm, General Instruments, and Titan. Founded in 1986 by three former M/A-Com Linkabit employees, ViaSat is publicly traded on the Nasdaq Stock Market under the symbol VSAT. Go to the History, Timeline or Industry Innovation & Firsts pages for more details.

To find out more about ViaSat, use the links on this page to explore our Web site.
Note: ViaSat Inc. is a separate company from and is not affiliated with Viasat Broadcasting, owned by Modern Times Group, Sweden.



Similar Jobs

See more jobs