Engineer III, Vulnerability Management

Posted Aug 18

This is a fully remote position, open to applicants in Texas.

📋 Description

• Conduct comprehensive vulnerability assessments across infrastructure, cloud, endpoints, networks, applications, SaaS, and externally accessible assets.

• Lead and facilitate Continuous Threat Exposure Management (CTEM) processes, encompassing scoping, discovery, prioritization, validation, mobilization, and ongoing risk mitigation.

• Manage and enhance capabilities in vulnerability management, attack surface management, external posture management, cloud posture, and SaaS posture.

• Analyze and normalize vulnerability and posture data to develop risk-focused remediation priorities.

• Evaluate vulnerabilities considering business context, asset criticality, exploitability, threat intelligence, exposure, compensating controls, and regulatory or compliance implications.

• Foster remediation and risk treatment collaboration with infrastructure, cloud, network, application, endpoint, DevOps, and business technology teams.

• Oversee responses to emerging vulnerabilities and critical exposures, including impact assessments, stakeholder coordination, mitigation tracking, and executive-level reporting.

• Design and maintain dashboards, metrics, and reports that track vulnerability trends, remediation progress, SLA performance, exposure reduction, attack surface modifications, and program maturity.

• Support integrated vulnerability management workflows, including ticketing, ownership assignment, exception handling, rescan validation, remediation automation, and governance.

• Assess and recommend enhancements to scanning coverage, asset inventory quality, vulnerability data integrity, risk scoring, and stakeholder reporting.

• Convert technical findings into actionable remediation advice and succinct risk summaries for leadership.

• Contribute to the development of security standards, procedures, playbooks, documentation, and continuous improvement initiatives.

• Mentor junior engineers and analysts on vulnerability triage and remediation governance.


⛳️ Requirements

• Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Engineering, or a related field, or equivalent practical experience.

• 7–10 years of combined experience in information technology, cybersecurity, systems administration, cloud operations, network security, application security, security engineering, or related fields.

• Minimum of 4 years of hands-on experience in vulnerability management, exposure management, attack surface management, configuration assurance, or a closely related cybersecurity function.

• At least one active cybersecurity certification, such as CISSP, CISM, Security+, CySA+, GSEC, CCSK, CCSP, OSCP, GIAC certification, or another recognized security certification.

• Strong grasp of vulnerability lifecycle management, including discovery, validation, prioritization, remediation, exception handling, rescan validation, and reporting.

• Experience with vulnerability assessment or management platforms like Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Wiz, Armis, or similar tools.

• Familiarity with attack surface, posture, or exposure management capabilities such as CAASM, EASM, RBVM, CSPM, SSPM, external posture management, or security ratings platforms.

• Ability to analyze CVEs, CVSS, EPSS, threat intelligence, exploitability indicators, asset context, and compensating controls to prioritize risk effectively.

• Experience with enterprise asset data, CMDB data, ownership models, assignment groups, and business criticality attributes.

• Proficiency in using Excel, Power BI, SQL, data lakes, reporting platforms, or other data analysis and visualization tools.

• Working knowledge of NIST CSF, NIST 800-53, ISO 27001, CIS Critical Security Controls, PCI DSS, HIPAA, GDPR, OWASP Top 10, SANS Top 25, and MITRE ATT&CK.

• Excellent written and verbal communication abilities.

• Proven capability to coordinate cross-functional remediation activities within a complex enterprise environment.

• Preferred: experience in building or maturing CTEM, exposure management, or unified risk-based vulnerability management programs.

• Preferred: experience with vulnerability workflow automation, ServiceNow SecOps, Jira, SOAR, or similar platforms.

• Preferred: experience in consolidating and normalizing vulnerability data from multiple source tools.

• Preferred: experience in cloud security and cloud posture management across AWS, Azure, Google Cloud, or hybrid environments.

• Preferred: experience in external attack surface management, SaaS security posture management, configuration assurance, or third-party exposure management.

• Preferred: experience in regulatory, audit, customer assurance, or compliance reporting.

• Preferred: scripting or automation experience using Python, PowerShell, APIs, or query languages.

• Ability to influence without direct authority and lead cross-functional initiatives.


🏝️ Benefits

• Medical, dental, and vision care.

• Backup dependent care.

• Adoption assistance.

• Infertility coverage.

• Family building support.

• Behavioral health solutions.

• Paid parental leave.

• Paid caregiver leave.

• Training programs.

• Professional development resources.

• Mentorship programs.

• Employee resource groups.

• Volunteer activities.

People also viewed

General Dynamics Information Technology1 day ago

ICAM Identity Provider Engineer – Enterprise Authentication Services

US flagUnited States OnlyFull-timeEngineer$170k – $230k/year
ApplyView job
General Dynamics Information Technology1 day ago

ICAM Identity Provider (IdP) Engineer – Enterprise Authentication Services

US flagUnited States OnlyFull-timeEngineer$170k – $230k/year
ApplyView job
Anduril Industries1 day ago

PLM Engineer – DBA/Infrastructure

US flagCalifornia OnlyFull-timeEngineer$111k – $147k/year
ApplyView job
Peraton1 day ago

Engine Performance and Operability Engineer

US flagUnited States OnlyFull-timeEngineer$135k – $216k/year
ApplyView job
Nokia1 day ago

Resident Engineer

US flagMaryland OnlyFull-timeEngineer$120k – $140k/year
ApplyView job
SimSpace1 day ago

Senior Cyber Range Engineer

CR flagCosta Rica OnlyFull-timeEngineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers