
Engineer III, Vulnerability Management
Posted Aug 18

Posted Aug 18
This is a fully remote position, open to applicants in Texas.
• Conduct comprehensive vulnerability assessments across infrastructure, cloud, endpoints, networks, applications, SaaS, and externally accessible assets.
• Lead and facilitate Continuous Threat Exposure Management (CTEM) processes, encompassing scoping, discovery, prioritization, validation, mobilization, and ongoing risk mitigation.
• Manage and enhance capabilities in vulnerability management, attack surface management, external posture management, cloud posture, and SaaS posture.
• Analyze and normalize vulnerability and posture data to develop risk-focused remediation priorities.
• Evaluate vulnerabilities considering business context, asset criticality, exploitability, threat intelligence, exposure, compensating controls, and regulatory or compliance implications.
• Foster remediation and risk treatment collaboration with infrastructure, cloud, network, application, endpoint, DevOps, and business technology teams.
• Oversee responses to emerging vulnerabilities and critical exposures, including impact assessments, stakeholder coordination, mitigation tracking, and executive-level reporting.
• Design and maintain dashboards, metrics, and reports that track vulnerability trends, remediation progress, SLA performance, exposure reduction, attack surface modifications, and program maturity.
• Support integrated vulnerability management workflows, including ticketing, ownership assignment, exception handling, rescan validation, remediation automation, and governance.
• Assess and recommend enhancements to scanning coverage, asset inventory quality, vulnerability data integrity, risk scoring, and stakeholder reporting.
• Convert technical findings into actionable remediation advice and succinct risk summaries for leadership.
• Contribute to the development of security standards, procedures, playbooks, documentation, and continuous improvement initiatives.
• Mentor junior engineers and analysts on vulnerability triage and remediation governance.
• Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Engineering, or a related field, or equivalent practical experience.
• 7–10 years of combined experience in information technology, cybersecurity, systems administration, cloud operations, network security, application security, security engineering, or related fields.
• Minimum of 4 years of hands-on experience in vulnerability management, exposure management, attack surface management, configuration assurance, or a closely related cybersecurity function.
• At least one active cybersecurity certification, such as CISSP, CISM, Security+, CySA+, GSEC, CCSK, CCSP, OSCP, GIAC certification, or another recognized security certification.
• Strong grasp of vulnerability lifecycle management, including discovery, validation, prioritization, remediation, exception handling, rescan validation, and reporting.
• Experience with vulnerability assessment or management platforms like Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Wiz, Armis, or similar tools.
• Familiarity with attack surface, posture, or exposure management capabilities such as CAASM, EASM, RBVM, CSPM, SSPM, external posture management, or security ratings platforms.
• Ability to analyze CVEs, CVSS, EPSS, threat intelligence, exploitability indicators, asset context, and compensating controls to prioritize risk effectively.
• Experience with enterprise asset data, CMDB data, ownership models, assignment groups, and business criticality attributes.
• Proficiency in using Excel, Power BI, SQL, data lakes, reporting platforms, or other data analysis and visualization tools.
• Working knowledge of NIST CSF, NIST 800-53, ISO 27001, CIS Critical Security Controls, PCI DSS, HIPAA, GDPR, OWASP Top 10, SANS Top 25, and MITRE ATT&CK.
• Excellent written and verbal communication abilities.
• Proven capability to coordinate cross-functional remediation activities within a complex enterprise environment.
• Preferred: experience in building or maturing CTEM, exposure management, or unified risk-based vulnerability management programs.
• Preferred: experience with vulnerability workflow automation, ServiceNow SecOps, Jira, SOAR, or similar platforms.
• Preferred: experience in consolidating and normalizing vulnerability data from multiple source tools.
• Preferred: experience in cloud security and cloud posture management across AWS, Azure, Google Cloud, or hybrid environments.
• Preferred: experience in external attack surface management, SaaS security posture management, configuration assurance, or third-party exposure management.
• Preferred: experience in regulatory, audit, customer assurance, or compliance reporting.
• Preferred: scripting or automation experience using Python, PowerShell, APIs, or query languages.
• Ability to influence without direct authority and lead cross-functional initiatives.
• Medical, dental, and vision care.
• Backup dependent care.
• Adoption assistance.
• Infertility coverage.
• Family building support.
• Behavioral health solutions.
• Paid parental leave.
• Paid caregiver leave.
• Training programs.
• Professional development resources.
• Mentorship programs.
• Employee resource groups.
• Volunteer activities.
General Dynamics Information Technology
General Dynamics Information Technology
Anduril Industries
Peraton
Get handpicked remote jobs straight to your inbox weekly.