Senior Vulnerability Management Engineer
Role Overview
We are seeking a
Senior Vulnerability Management Engineer to serve as a technical leader within a cybersecurity organization. This role will help drive enterprise vulnerability management, asset visibility, exposure analysis, and remediation effectiveness across on-premises, cloud, and hybrid environments.
The position combines hands-on vulnerability management platform expertise with a strong understanding of network architecture, asset discovery, vulnerability analysis, and the end-to-end remediation lifecycle.
The ideal candidate will ensure broad and reliable vulnerability coverage, identify visibility gaps, translate technical findings into actionable recommendations, and partner with technology teams to prioritize remediation based on actual risk.
Responsibilities
Own and optimize enterprise vulnerability scanning across on-premises, cloud, endpoint, and network environments, including scanners, agents, scan policies, schedules, credentials, platform health, upgrades, and integrations.
Analyze scan coverage and troubleshoot gaps related to asset discovery, authentication, agent deployment, scanner placement, routing, firewall rules, network segmentation, and onboarding.
Maintain accurate vulnerability and asset visibility by identifying unmanaged, duplicate, stale, or improperly classified assets and resolving asset-correlation and data-quality issues.
Develop and maintain asset tagging and classification strategies that support ownership, prioritization, reporting, and remediation workflows.
Analyze critical and high-risk vulnerabilities using exploitability, reachability, threat intelligence, asset criticality, internet exposure, compensating controls, and business context.
Identify vulnerabilities and assets requiring prioritized remediation and provide clear technical recommendations to infrastructure, network, cloud, database, application, and endpoint teams.
Support vulnerability triage, false-positive validation, assignment and ownership resolution, rescans, remediation verification, and recurring-issue analysis.
Maintain and improve integrations and workflows between vulnerability management, cloud security, IT service management, and other enterprise security platforms.
Contribute technical expertise to assignment rules, risk scoring, dashboards, metrics, reporting, and vulnerability workflow enhancements.
Develop or support automation using APIs, PowerShell, Python, or similar technologies.
Document technical procedures, operational processes, and platform configurations.
Partner across technology and security teams to remove remediation blockers and continuously improve vulnerability coverage, data quality, prioritization, and remediation outcomes.
Help evolve the vulnerability management program toward a broader exposure management model as the cybersecurity environment and threat landscape continue to change.
Identify opportunities to streamline processes, improve operational efficiency, and reduce manual effort across the vulnerability management program.
Required Experience & Qualifications
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent practical experience.
5+ years of experience in vulnerability management, security engineering, infrastructure engineering, network engineering, or a related cybersecurity discipline.
Hands-on experience administering and optimizing enterprise vulnerability management platforms, scanners, agents, policies, credentials, and integrations.
Experience designing, operating, and troubleshooting credentialed and unauthenticated vulnerability scans across Windows, Linux, network, and cloud environments.
Strong understanding of TCP/IP, DNS, routing, firewalls, load balancers, network segmentation, authentication, and common enterprise infrastructure.
Experience analyzing vulnerability findings, validating false positives, prioritizing risk, and supporting remediation through closure.
Experience integrating multiple security and enterprise technology platforms.
Ability to translate complex vulnerability and network information into clear, actionable guidance for both technical and non-technical stakeholders.
Strong analytical, troubleshooting, collaboration, documentation, and communication skills.
Ability to work effectively in a fast-paced cybersecurity environment and manage multiple priorities.
Preferred Experience
Experience with enterprise vulnerability management platforms such as Tenable or similar technologies.
Experience with Nessus scanners and Nessus Agents.
Experience with cloud security and exposure management platforms such as Wiz or similar technologies.
Experience with ServiceNow Vulnerability Response, Security Operations, or related IT service management/security workflows.
Experience with exposure management, attack-surface analysis, exploitability assessment, threat intelligence, and risk-based vulnerability prioritization.
Experience supporting AWS, Azure, hybrid cloud, virtualized, containerized, or ephemeral infrastructure.
Experience integrating vulnerability platforms with ServiceNow, SIEM, privileged-access management, asset-management, cloud, or automation technologies.
Experience developing automation with PowerShell, Python, REST APIs, Bash, Ansible, or similar technologies.
Relevant cybersecurity, vulnerability management, or cloud security certifications.
Team & Environment
Join a small, collaborative cybersecurity team focused on modernizing and expanding its vulnerability and exposure management capabilities.
The team is evolving toward a broader exposure management model and is looking for someone who can help streamline and mature the program.
This is a senior, hands-on role requiring the ability to work across security, infrastructure, network, cloud, and technology teams.
Experience working across multiple security platforms and integrating disparate technologies is important.
Standard working hours aligned with Pacific Time.
Interview process consists of two rounds.
Location: RemotePay Range: $75/hr-$80/hr