
Vulnerability Management β CTEM Specialist
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in United States.
β’ Spearhead the implementation of a CTEM platform, transitioning from an outdated vulnerability management system.
β’ Create and configure connectors, scoring/exploitability models, and consolidation logic across various scanners and source systems.
β’ Ensure the accuracy of data ingestion across vulnerability scanners and source systems.
β’ Develop SLA and exploitability/risk-scoring frameworks.
β’ Establish workflows for exception handling and risk acceptance.
β’ Conduct asset and vulnerability de-duplication and manage inventory reconciliation.
β’ Set up processes for escalating critical/high-priority vulnerabilities.
β’ Construct and validate API-based integrations between the CTEM platform and downstream systems like ServiceNow.
β’ Write Python scripts and automate processes for data tagging, gap analysis, and reporting.
β’ Create role-based dashboards and reporting tools for analysts, remediation owners, and CISO-level stakeholders.
β’ Develop frameworks for KPIs and metrics related to security operations.
β’ Produce documentation for platform configuration, runbooks, and policy/SLA guidelines.
β’ Assist in business process mapping and the design of current-state and future-state workflows.
β’ Generate documentation for the Target Operating Model (TOM).
β’ Support an embedded security team within a large commercial enterprise in the Financial Services sector.
β’ Proven experience with Risk-Based Vulnerability Management (RBVM) and CTEM tools and platforms (e.g., Kenna, Zafran, Rapid7, Tenable, Qualys).
β’ Familiarity with vulnerability management platforms, including connectors, scoring/exploitability models, consolidation logic, and ticketing integration.
β’ Experience in validating data ingestion accuracy across scanners and source systems.
β’ Expertise in designing SLA and exploitability/risk-scoring frameworks.
β’ Background in designing processes for exception handling and risk acceptance.
β’ Experience with asset and vulnerability de-duplication and inventory reconciliation.
β’ Proven ability to establish critical/high-priority vulnerability escalation processes.
β’ Minimum of 5 years of relevant experience in vulnerability management or cybersecurity consulting.
β’ U.S. Citizenship or Permanent Residency is required.
β’ Availability to work within the continental United States.
β’ Experience in API-based system integration and validation testing.
β’ Scripting and automation experience, particularly with Python, for data tagging, gap analysis, and reporting automation.
β’ Familiarity with IT Service Management (ITSM) platforms like ServiceNow, including workflow design and ticket lifecycle automation.
β’ Experience in creating role-based dashboards and reporting for both technical and executive audiences.
β’ Proven track record in developing KPI and metrics frameworks for security operations.
β’ Technical writing experience, encompassing platform configuration documentation, runbooks, and policy/SLA documentation.
β’ Competence in business process mapping and current-state/future-state workflow design.
β’ Experience in developing Target Operating Model (TOM) documentation.
β’ Strong cross-functional stakeholder communication skills.
β’ Ability to work independently within an embedded client team.
β’ Medical β A variety of POS health plan options, including an HSA-compatible plan.
β’ Dental β PPO coverage for preventive, basic, and major services.
β’ Vision β Annual eye exam, frames, lenses, and contact lens allowance.
β’ 401(k) β Employer match of up to 5% of eligible compensation.
β’ Long-Term Disability β 100% employer-paid coverage at 50% of pre-disability earnings.
β’ Life Insurance & AD&D β 100% employer-paid coverage valued at $10,000 each.
β’ PTO β 15β25 days of paid time off annually based on tenure.
β’ Paid Federal Holidays β Observance of all 11 federal holidays.
Allara
Pfizer
CareTalk Health
Parexel
Get handpicked remote jobs straight to your inbox weekly.