
Vulnerability Management Engineer
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in Alabama, +14 more states.
• Lead assessments of vulnerabilities and implement vulnerability management standards.
• Evaluate, prioritize, and remediate security vulnerabilities within intricate infrastructures.
• Transform complex security data into clear and actionable insights.
• Collaborate directly with engineering teams to mitigate risks and execute essential fixes.
• Assess and implement configuration compliance standards to enhance the security of infrastructure and cloud environments.
• Prioritize vulnerabilities according to business impact and technical risk.
• Navigate through audits and compliance requirements effectively.
• Support a defensive strategy that safeguards Cisco and its clientele.
• Query tool outputs, visualize security data, and create vulnerability-tracking dashboards utilizing Splunk and SPL.
• Integrate security scanning tools within CI/CD pipelines.
• Conduct audits of Infrastructure as Code for configuration errors prior to deployment.
• Communicate technical security risks to engineering teams and executive stakeholders.
• Research and respond to emerging security threats and technologies.
• Configure and manage enterprise vulnerability-scanning platforms.
• Over 3 years of experience in the vulnerability management lifecycle, encompassing assessment, prioritization, and hands-on remediation of security vulnerabilities in complex infrastructures.
• Proficient in assessing or applying configuration compliance standards like CIS Benchmarks and DISA STIGs.
• Experience in hardening infrastructure and cloud environments to comply with regulatory standards such as PCI DSS, SOC2, HIPAA, and FedRAMP.
• Skilled in utilizing threat modeling and CVSS scoring to prioritize vulnerabilities based on business impact and technical risk.
• Experience in securing containerized environments and orchestration platforms, particularly Docker and Kubernetes.
• Technical knowledge of cloud operational models and the security requirements of SaaS architectures built on microservices.
• Preferred: Familiarity with Splunk and Search Processing Language (SPL).
• Preferred: Experience in integrating or utilizing security scanning tools in CI/CD pipelines.
• Preferred: Experience in auditing Infrastructure as Code such as Terraform and CloudFormation.
• Preferred: Ability to translate complex technical security risks into actionable insights.
• Preferred: Self-motivated with continuous self-learning and independent research on emerging threats and technologies.
• Preferred: Hands-on experience in configuring and managing enterprise scanning platforms like Tenable, Qualys, and Rapid7.
• Must be a U.S. Person for work involving U.S. Government classified environments.
• May need to be a U.S. citizen for work required by the U.S. government that is designated for U.S. citizens only on U.S. soil.
• Medical, dental, and vision insurance.
• 401(k) plan with a Cisco matching contribution.
• Paid parental leave.
• Coverage for short- and long-term disability.
• Basic life insurance.
• Eligibility for Cisco restricted stock unit grants, contingent upon continued employment and vesting periods.
• 10 paid holidays each full calendar year.
• 1 floating holiday for non-exempt employees.
• 1 paid day off to celebrate the employee’s birthday.
• Paid holiday shutdown at year-end.
• 4 paid days for personal wellness.
• 16 days of paid vacation each full calendar year for non-exempt employees.
• A flexible vacation time-off program with no defined limit for eligible exempt employees, subject to availability and business constraints.
• 80 hours of sick time off provided upon hire and each January 1st thereafter.
• Up to 80 hours of unused sick time can be carried forward annually.
• Additional paid leave for critical or emergency family matters.
• Optional 10 paid volunteer days each full calendar year.
• Annual bonuses available for non-sales roles, in accordance with Cisco policies.
• Performance-based incentive pay for employees on sales plans.
• Opportunities for professional growth and development.
Conduent
Mercor
AtkinsRéalis
Get handpicked remote jobs straight to your inbox weekly.