
Security Specialist, Vulnerability Management
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in California.
• Develop and manage a risk-centric vulnerability management capability across various cloud platforms, applications, Kubernetes and container settings, network infrastructure, software supply chains, and cloud-managed customer-premises equipment.
• Create authoritative visibility for vulnerabilities across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware, and customer-premises equipment asset categories.
• Catalog the attack surface and establish coverage for both internet-facing and internal assets, including cloud services, hosts, network devices, containers, Kubernetes clusters, applications, APIs, source code, dependencies, images, infrastructure as code, and customer-premises equipment/firmware.
• Design, configure, and maintain both authenticated and unauthenticated scans, agent-based evaluations, cloud-native configuration checks, container and dependency scans, external attack-surface discovery, and targeted validation tests.
• Set safe scan windows, credentials, rate limits, exclusions, and testing procedures to prevent disruptions in production, customer environments, or customer-premises equipment fleets.
• Assess, select, and manage vulnerability management and scanning tools like Tenable Nessus, Qualys, Rapid7, Wiz, Orca, Prisma Cloud, Snyk, Veracode, Checkmarx, Trivy, Grype, and Nuclei.
• Evaluate coverage, scan health, credential success, stale assets, and blind spots; enhance asset-to-owner mapping and data quality.
• Review findings to classify them as true positives, false positives, duplicates, accepted risks, mitigated conditions, or actionable vulnerabilities.
• Analyze CVE applicability based on affected components and versions, package provenance, customer-premises equipment or firmware SBOMs, runtime reachability, configuration, network exposure, privileges, exploit prerequisites, and existing controls.
• Reproduce or safely validate significant findings using advisories, proof-of-concept analysis, logs, configuration evidence, package inspections, and non-production testing.
• Track vulnerability intelligence and vendor advisories for cloud, Kubernetes, Linux, networking, broadband/customer-premises equipment, as well as both open-source and commercial technologies.
• Prioritize remediation efforts based on CVSS, CISA KEV, EPSS, exploit availability, exposure, reachability, asset criticality, tenant/customer impact, and compensating controls.
• Establish remediation and mitigation targets according to risk tiers and escalate vulnerabilities that are actively exploited or accessible via the internet.
• Document remediation records that include affected assets, evidence, owners, due dates, recommended actions, validation criteria, and customer or operational considerations.
• Collaborate with Engineering and DevOps on patches, upgrades, configuration changes, image rebuilds, dependency updates, firmware releases, and compensating controls; confirm closure through rescans or equivalent evidence.
• Manage risk exceptions with documented justifications, accountable approvals, compensating controls, expiration dates, and scheduled reassessments.
• Evaluate end-to-end security across cloud control planes, APIs, device-management protocols, access networks, gateways, routers, ONTs, and connected-home devices.
• Work alongside Engineering to identify affected device models, hardware revisions, firmware branches, software components, and deployed cohorts; assist in safe remediation and rollout validation.
• Develop automation and integrations for asset enrichment, deduplication, risk scoring, ticket creation, ownership routing, SLA tracking, notifications, rescans, exception expiry, and evidence collection.
• Maintain dashboards for coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, asset ownership, and risk trends.
• Create playbooks, standards, and procedures for routine vulnerability management, critical CVEs, zero-day responses, scanner administration, and tool outages.
• Report to technical owners and leaders, distinguishing raw finding volumes from material risks and identifying decisions or overdue actions.
• Assist in audits and customer security inquiries with traceable evidence while safeguarding sensitive vulnerability and customer information.
• Collaborate with Engineering, DevOps, NOC, Support, Product, and Compliance to minimize measurable exposure without impacting customer service.
• Over 5 years of practical experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security, or a closely related field.
• Experience with enterprise scanning and vulnerability management workflows, including scanner configuration, authenticated scanning, coverage analysis, finding validation, false-positive management, remediation tracking, and rescanning.
• Strong skills in CVE analysis, including assessing applicability and exploitability based on versions, configurations, exposure, reachability, privileges, controls, and business context.
• Familiarity with enterprise vulnerability platforms along with complementary cloud, container, dependency, application, and open-source scanning tools.
• Knowledge of CVE/CWE, NVD, CVSS, CISA KEV, EPSS, vendor advisories, software bills of materials, and risk-based prioritization.
• Practical understanding of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers, and Kubernetes.
• Capability to read code, package manifests, container images, configurations, logs, and network evidence.
• Proficient in scripting or programming in Python, Go, PowerShell, Bash, or a similar language.
• Experience with integrating security platforms using APIs, ticketing systems, and dashboards.
• Excellent written and verbal communication skills for articulating technical risks, uncertainties, trade-offs, and decisions.
• Bachelor’s degree in cybersecurity, computer science, engineering, or equivalent practical experience.
• Ability to primarily work during standard business hours with escalation availability for critical, actively exploited, or zero-day vulnerabilities.
• Capacity to manage sensitive vulnerability, exploit, and customer information with strict need-to-know access and evidence controls.
• Ability to coordinate intrusive scans, validation tests, and production-impacting activities through approved change and maintenance processes.
• Willingness and ability to participate in an on-call rotation.
• Must be eligible to work without visa sponsorship; AXON Networks cannot provide visa sponsorship.
• Fully remote work opportunity within North America.
• On-call escalation availability for critical, actively exploited, or zero-day vulnerabilities.
• Equal opportunity and inclusive work environment.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.