Remotery

Senior Vulnerability Management Engineer

Posted Jul 29

This is a fully remote position, open to applicants in United Kingdom.

📋 Description

• Analyze and evaluate penetration testing reports to comprehend technical implications, exploitability, and business risks.

• Create, document, and maintain remediation guidance, patterns, and blueprints for prevalent vulnerability types (e.g. injections, access control, authentication, session management, and misconfigurations).

• Offer consultation to application and platform teams regarding secure design and remediation strategies, encompassing code-level, configuration-level, and business-level recommendations.

• Oversee remediation efforts across various teams, ensuring clear ownership, established timelines, and risk-based prioritization.

• Validate corrections by retesting vulnerabilities (either manually or utilizing tools/scripts) and updating the status of findings until resolution.

• Manage and monitor the remediation backlog, addressing SLAs, aging findings, and critical issues when necessary.

• Produce and maintain documentation concerning remediation processes, workflows, and controls for audit and compliance purposes.

• Prepare and present regular status reports and metrics on remediation progress, trends, and risk mitigation to management and stakeholders.

• Conduct root cause analysis for recurring or systemic issues and collaborate with engineering, architecture, and governance teams to implement long-term corrective measures.

• Contribute to the ongoing enhancement of the pentest-to-remediation lifecycle, including automation, standardization, and integration with SDLC/DevSecOps pipelines.

• Compile technical documentation, tracking and documenting remediation metadata, including engagement details (who, what, when, where), testing team members and roles, tools and methodologies used, schedules and timelines, target systems and environments, constraints, exclusions, and limitations, as well as testing activities and event logs.

• Engage in team improvement initiatives and ensure all efforts and feedback are meticulously documented for future reference.

• Participate in the continual enhancement of testing methodologies, tools, and automation.

• Stay updated on emerging threats, vulnerabilities, and offensive security strategies.

• Take part in R&D initiatives as directed by leadership.

• Foster knowledge sharing and mentoring within the team.


⛳️ Requirements

• Demonstrated hands-on experience in penetration testing for Web Applications, APIs, Thick Clients, and Common Infrastructures (Active Directory, Cloud, and Cloud-native environments).

• Proficiency in tools such as Burp Suite, common command-line utilities, and the capability to write custom scripts as necessary.

• Experience in automating penetration testing tasks.

• Strong understanding of application security, network protocols, and operating systems.

• Familiarity with cloud platforms (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes).

• Comprehensive knowledge of common vulnerabilities and exposures (OWASP Top 10, SANS Top 25) and secure coding practices in at least one major programming language stack (e.g. Java/Spring Boot, .NET, JavaScript/Node, Python).

• Ability to produce clear technical reports and effectively communicate findings and solutions to both technical and non-technical stakeholders.

• Experience working in large, complex enterprise settings.

• Strong communication skills in English, both written and oral.

• Relevant certifications and active participation in the security community are advantageous.

• Experience in Threat Modeling is a plus.

• Proven record of successfully managing and driving security initiatives for diverse organizations with varying operational and technical profiles.

• Capability to identify, assess, and communicate technical and project risks to stakeholders.

• Understanding project requirements and aligning activities with defined objectives and timelines.


🏝️ Benefits

• Healthcare

• Retirement planning

• Paid volunteering days

• Wellbeing initiatives

People also viewed

LiteLLM AI Gateway2 days ago

Forward Deployed Engineer

IN flagIndia OnlyFull-timeEngineer$50k – $90k/year
ApplyView job
Snowflake2 days ago

Principal Threat Intelligence Engineer

US flagCalifornia OnlyFull-timeEngineer$249k – $357.6k/year
ApplyView job
RTX2 days ago

Flammability Certification Engineer II

US flagNorth Carolina OnlyFull-timeEngineer$68.9k – $131.1k/year
ApplyView job
C-MORE2 days ago

Product Strategist – Environmental Engineer

Anywhere in the WorldFull-timeEngineer
ApplyView job
SGS2 days ago

Part-time Field Evaluation Engineer

GA flagGabon OnlyFull-timeEngineer$40 – $50/hour
ApplyView job
TRC Worldwide Engineering, Inc.2 days ago

Structural Forensic Engineer

US flagTennessee OnlyFull-timeEngineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers