
Senior Vulnerability Management Engineer
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in United States.
• Manage the complete vulnerability management process: asset discovery, scanning, enrichment, prioritization, assignment, verification, and closure.
• Develop, document, and refine a data-driven prioritization framework that incorporates CVSS, EPSS, KEV, exploit availability, asset criticality, exposure/reachability, compensating controls, and business context.
• Automate the entire workflow using SOAR playbooks, webhooks, REST/GraphQL APIs, message queues, and custom scripts as necessary.
• Create and enhance KPIs, metrics, and trends for vulnerability management operations, highlighting root-cause issues that contribute to systemic vulnerability risks to leadership.
• Consolidate scanners, CMDB/asset inventory, EDR, cloud services (AWS/Azure/GCP), and other tools into a unified management pipeline.
• Continuously minimize noise by deduplication, suppression of known benign issues, correlating related findings, and automatically closing tickets upon remediation evidence.
• Assess and implement AI/LLM tools for triage, false-positive suppression, remediation guidance, and vulnerability research, with necessary safeguards in place.
• Lead the technical response during emergency patch cycles across various technical platforms.
• A Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
• 5-7 years of experience in information security, particularly within the financial sector.
• Practical experience in deploying, configuring, and managing vulnerability scanning solutions at an enterprise level, including policy design, noise reduction tuning, and performance impact management (e.g., Tenable, Microsoft Defender, Wiz, Tanium).
• Hands-on experience in engineering, integrating, and optimizing automation for security platforms (e.g., Swimlane, Elastic).
• Strong understanding of public cloud platforms (e.g., AWS, Azure, GCP) from both infrastructure and development perspectives, including their security features.
• Familiarity with DevSecOps methodologies and CI/CD pipelines.
• Knowledge of industry security frameworks, standards, and best practices (e.g., NIST, ISO, CIS).
• Proficient in one or more programming languages (e.g., Python, Golang, JavaScript), especially for automating security platform operations, health monitoring, and integration tasks.
• Excellent communication and collaboration skills, with the capability to work closely with engineering, operations, and infrastructure teams.
• Familiarity with compliance standards and regulations.
• Strong creativity and critical thinking skills, able to work independently and collaboratively in a dynamic environment.
• Ability to act as a mentor or subject matter expert to colleagues in vulnerability management and systems engineering.
• Employees (and their families) can enroll in the Company’s extensive health, dental, and vision insurance plans.
• Employees are also entitled to Basic and Supplemental Life Insurance, along with Short and Long-Term Disability coverage.
• All employees (regardless of their hours worked) have immediate access to the Company’s Employee Assistance Program and wellness initiatives—no enrollment is necessary.
• Employees may also take part in the Company’s 401K plan, which includes matching contributions from the Company.
Spartech LLC
Montreal Oficial
HappyOps
Medallion
Get handpicked remote jobs straight to your inbox weekly.