We are seeking an experienced Senior Vulnerability Management Engineer to support and mature our enterprise Vulnerability Management program. This role is intended for an experienced security professional who understands the complete vulnerability management lifecycle and can independently manage vulnerabilities from initial identification through triage, ownership determination, remediation coordination, validation, and closure.
The ideal candidate has hands on experience working with enterprise vulnerability management platforms such as Qualys VMDR, Tenable, Rapid7, or similar technologies and, more importantly, understands how to interpret vulnerability data and translate technical findings into actionable remediation efforts.
This is not simply a vulnerability scanning or reporting position. The Senior Vulnerability Management Engineer will actively analyze findings, investigate affected systems, determine risk and applicability, identify responsible system or application owners, communicate remediation requirements, track remediation activities, validate fixes, identify exceptions and false positives, and support the day-to-day operation and continued maturity of the vulnerability management program.
Several years of hands-on experience in Vulnerability Management, security engineering, infrastructure security, or a closely related cybersecurity discipline.
Demonstrated experience managing vulnerabilities throughout the complete vulnerability lifecycle, including:
o Identification
o Triage
o Risk evaluation
o Ownership determination
o Stakeholder outreach
o Remediation tracking
o Escalation
o Validation
o Closure
Strong hands-on experience with an enterprise vulnerability management platform such as Qualys VMDR, Tenable, Rapid7, or equivalent technology.
Strong understanding of vulnerability management concepts including CVE, CVSS, CPE, exploitability, vulnerability severity, compensating controls, remediation, mitigation, false positives, and risk acceptance.
Ability to read and interpret vulnerability scanner results and independently investigate findings.
Experience communicating vulnerabilities and remediation requirements to system administrators, application teams, engineers, and technical leadership.
Experience managing high volumes of vulnerability data within a large or complex technology environment.
Ability to identify responsible system or application owners and drive findings toward remediation.
Experience validating vulnerability remediation through rescanning, technical testing, or evidence review.
Strong understanding of common operating systems, including Windows and Linux.
Working knowledge of enterprise infrastructure technologies including networking, servers, databases, middleware, virtualization, and cloud environments.
Understand common vulnerability remediation methods including patching, configuration changes, software upgrades, compensating controls, and service removal.
Ability to analyze technical security information from multiple sources and determine practical organizational risk.
Strong analytical, troubleshooting, documentation, and communication skills.
Ability to independently prioritize and manage multiple vulnerability remediation efforts simultaneously.
Advanced experience with Qualys VMDR, including vulnerability detection, asset inventory, tagging, reporting, dashboards, authentication, and agent-based assessments.