Job Title: Senior Vulnerability Management Engineer
Location: Duluth, GA 30097 Hybrid
Duration: 12 Months
Job Details:
Minimum years of experience required: 8-10 years
Job Description:
Vulnerability Management Lifecycle
Lead and execute the full Vulnerability Management (VM) lifecycle discovery, assessment, prioritization, remediation tracking, reporting, and continuous improvement.
Perform hands-on configuration, optimization, and maintenance of vulnerability assessment tools (e.g., Tenable, Qualys, Rapid7, etc.).
Analyze vulnerability data, validate findings, track remediation SLAs, and coordinate with infrastructure and application teams.
Client Engagement
Act as the primary technical and functional liaison for clients, ensuring transparency and timely delivery of VM activities.
Present vulnerability reports, risk insights, dashboards, and remediation recommendations to both technical and non-technical stakeholders.
Support consulting engagements including VM process improvements, governance models, and risk-based prioritization.
Greenfield Implementation & Transformation
Lead or support greenfield deployments of vulnerability management programs, including tool selection, architecture design, onboarding processes, and integration workflows.
Drive transformation initiatives such as operationalizing new VM platforms, setting up governance frameworks, and building automation and orchestration layers.
Develop playbooks, standard operating procedures (SOPs), and best practices for enterprise-scale VM programs.
Tool Integration & Automation
Integrate vulnerability scanners and aggregators with ServiceNow (SNOW) and other ITSM or reporting platforms.
Work with APIs and connectors to automate ingestion, normalization, prioritization, and ticket creation workflows.
Collaborate with architecture and engineering teams to ensure seamless tool interoperability.
Security & DevSecOps Alignment
Support Application Security teams in aligning infrastructure scanning with application scanning and CI/CD processes.
Contribute knowledge of DevSecOps concepts such as secure SDLC, pipeline scanning, SCA/DAST/SAST, and risk-based remediation.
Help bridge Infra Security and AppSec for unified risk visibility.
TOP skills, and the years of experience:
" 8 10 years of hands-on experience in Infrastructure Security or Vulnerability Management roles.
" Strong expertise in one or more VM tools (Tenable, Qualys, Rapid7, Nexpose, etc.).
" Experience implementing or transforming enterprise VM programs.
" Proven track record in client-facing security consulting or managed service roles.
" Demonstrated experience integrating VM tools with ServiceNow or other ITSM platforms.
" Familiarity with vulnerability aggregators and data normalization platforms (e.g., Kenna, Brinqa, Vulcan, PlexTrac).
" Strong knowledge of enterprise infrastructure: servers, endpoints, cloud platforms, containers, and network security.
" Ability to interpret CVEs, CVSS, EPSS, KEV catalog, and risk scoring models.
" Excellent communication, documentation, and stakeholder management skills.
Preferred / Nice-to-Have Skills
" Good understanding of Application Security concepts and tooling.
" Exposure to DevSecOps, CI/CD pipelines, and container security (Docker, Kubernetes).
" Experience in SIEM/SOAR, cloud security (AWS/Azure/GCP), or IT risk management frameworks.
" Relevant security certifications such as CEH, Security+, CySA+, GSEC, CISSP, or vendor certifications