
Lead Information Security Engineer – Vulnerability Management
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Act as the main escalation contact and subject matter expert for the most intricate and high-risk remediation challenges across infrastructure, cloud, containers, applications, and code.
• Offer advanced technical guidance on remediation strategies, exploitability assessments, interpretation of scanning results, and multi-layered False Positive evaluations.
• Keep abreast of the latest vulnerabilities, exploitation methods, and exploits.
• Independently manage the intake, investigation, escalation, and mitigation reviews for high-impact issues, including critical vulnerabilities, emerging threats, and executive escalations.
• Lead and own comprehensive remediation planning that encompasses dependency mapping, coordinated timelines, and long-term solutions.
• Conduct analytical assessments of large datasets to pinpoint significant trends and develop targeted remediation campaigns for the highest risk areas.
• Proactively follow up on stalled remediation plans and escalate as necessary when progress is lacking.
• Provide expert-level communication to both technical and non-technical stakeholders to ensure understanding of risk, urgency, and remediation requirements.
• Oversee False Positive determinations, Exception requests, and Risk Acceptance submissions to ensure precision, thoroughness, and compliance with governance standards.
• Collaborate with teams across Information Security and application departments within the Bank to ensure complex issues are effectively and efficiently resolved.
• Track and report on vulnerability metrics, KPIs, and KRIs, with proactive escalations to maintain risk within acceptable levels.
• Develop impactful presentations to communicate key metrics and data to senior leadership.
• Conceptualize, design, and refresh dashboards and workflows using scripting, Power Automate, PowerBI, ServiceNOW, Brinqa, and/or other relevant tools/processes.
• Employ macros, scripting, formulas, and optimizations for workflows in Excel.
• Operate within an Agile framework to deliver incremental value.
• Identify opportunities for improvement and volunteer to enhance EVM processes, demonstrating measurable impact on reducing inefficiencies.
• Establish and maintain standards, playbooks, and repeatable processes to enhance the efficiency and maturity of the vulnerability management program.
• Mentor junior and mid-level engineers through hands-on support, structured coaching, and active involvement in complex cases.
• Contribute to the progression of the Program and participate in additional duties and projects as necessary.
• Minimum of 6 years of relevant and recent hands-on experience in Vulnerability Management.
• Strong attention to detail with an advanced understanding of security architecture, networking, operating systems, identity, and cloud services.
• Proven experience in risk articulation and remediation strategies across various technology stacks.
• Demonstrated ability to triage and prioritize complex findings from scanning tools, translating technical results into actionable remediation guidance.
• Excellent written and verbal communication skills, capable of effectively engaging with senior leaders and deeply technical teams.
• Strong analytical and problem-solving skills, with the ability to interpret large datasets and identify significant trends.
• Experience in collaborating across multiple teams and influencing outcomes without direct authority.
• Bachelor’s degree in computer science/information systems or an equivalent combination of education and experience.
• Relevant certifications such as Security+, CISSP, CISM, GIAC, or cloud certifications (AWS preferred).
• Comprehensive benefits package
• Competitive compensation offerings
• Performance-based incentive compensation plan
Perseus Group, Constellation Software
Kraken Digital Asset Exchange
SmarterDx
NinjaOne
Get handpicked remote jobs straight to your inbox weekly.