
Lead Information Security Engineer – Vulnerability Management
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in Ohio.
• Act as the main escalation contact and subject matter expert for intricate and high-risk remediation challenges across infrastructure, cloud, containers, applications, and code.
• Offer technical advice on remediation strategies, exploitability assessments, interpretation of scanning results, and evaluations of false positives.
• Manage the intake, investigation, escalation, and mitigation reviews for critical vulnerabilities, emerging threats, and executive-level escalations.
• Lead remediation planning including dependency mapping, coordinated timelines, and long-term solutions.
• Examine large datasets to detect trends and develop focused remediation initiatives.
• Follow up on inactive remediation plans and escalate issues when progress is lacking.
• Convey risk, urgency, and remediation requirements to both technical and non-technical stakeholders.
• Supervise false-positive evaluations, exception requests, and submissions for risk acceptance.
• Collaborate with Information Security and application teams throughout the bank.
• Report and monitor vulnerability metrics, KPIs, and KRIs.
• Create presentations for senior leadership.
• Design and maintain dashboards and workflows utilizing scripting, Power Automate, Power BI, ServiceNow, Brinqa, and other tools.
• Enhance Excel workflows using macros, scripting, formulas, and various techniques.
• Operate within an Agile framework.
• Enhance Enterprise Vulnerability Management processes and eliminate inefficiencies.
• Develop and sustain standards, playbooks, and repeatable processes.
• Mentor junior and mid-level engineers.
• Contribute to the evolution of the program and participate in additional projects.
• A minimum of 6 years of relevant and recent hands-on experience in Vulnerability Management.
• In-depth knowledge of security architecture, networking, operating systems, identity, and cloud services.
• Experience in articulating risk and formulating remediation strategies across common technology stacks.
• Proven ability in triaging and prioritizing complex findings from scanning tools.
• Capability to translate technical findings into actionable remediation guidance.
• Excellent written and verbal communication skills.
• Demonstrated analytical and problem-solving abilities, including the interpretation of large datasets and trend identification.
• Experience in collaborating across various teams and influencing outcomes without direct authority.
• Bachelor’s degree in computer science/information systems or an equivalent combination of education and experience.
• Relevant certifications such as Security+, CISSP, CISM, GIAC, or cloud certifications (AWS preferred).
• Background in cloud security, container security, application security, or code-scanning programs.
• Experience in applying threat intelligence and exploitability context to remediation prioritization.
• Working proficiency in Python, PowerShell, or SQL for data analysis and workflow automation.
• Familiarity with ServiceNow, Power BI, and Power Automate.
• Proven experience in system administration, networking, or SOC roles.
• Experience integrating security controls into CI/CD pipelines and DevSecOps workflows.
• Hands-on experience with NIST CSF, NIST 800-53, CIS Controls, ISO 27001, and PCI DSS.
• This position does not offer immigration sponsorship.
• Incentive compensation plan based on company, line of business, and/or individual performance.
• Comprehensive benefits programs that support physical, financial, emotional, and social well-being.
• Benefits available for employees and their families.
• Differentiated compensation offerings.
• An inclusive culture with equal employment opportunities.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.