Vulnerability Management Engineer

Posted Sep 8

This is a fully remote position, open to applicants in Alabama, +14 more states.

📋 Description

• Lead assessments of vulnerabilities and implement vulnerability management standards.

• Evaluate, prioritize, and remediate security vulnerabilities within intricate infrastructures.

• Transform complex security data into clear and actionable insights.

• Collaborate directly with engineering teams to mitigate risks and execute essential fixes.

• Assess and implement configuration compliance standards to enhance the security of infrastructure and cloud environments.

• Prioritize vulnerabilities according to business impact and technical risk.

• Navigate through audits and compliance requirements effectively.

• Support a defensive strategy that safeguards Cisco and its clientele.

• Query tool outputs, visualize security data, and create vulnerability-tracking dashboards utilizing Splunk and SPL.

• Integrate security scanning tools within CI/CD pipelines.

• Conduct audits of Infrastructure as Code for configuration errors prior to deployment.

• Communicate technical security risks to engineering teams and executive stakeholders.

• Research and respond to emerging security threats and technologies.

• Configure and manage enterprise vulnerability-scanning platforms.


⛳️ Requirements

• Over 3 years of experience in the vulnerability management lifecycle, encompassing assessment, prioritization, and hands-on remediation of security vulnerabilities in complex infrastructures.

• Proficient in assessing or applying configuration compliance standards like CIS Benchmarks and DISA STIGs.

• Experience in hardening infrastructure and cloud environments to comply with regulatory standards such as PCI DSS, SOC2, HIPAA, and FedRAMP.

• Skilled in utilizing threat modeling and CVSS scoring to prioritize vulnerabilities based on business impact and technical risk.

• Experience in securing containerized environments and orchestration platforms, particularly Docker and Kubernetes.

• Technical knowledge of cloud operational models and the security requirements of SaaS architectures built on microservices.

• Preferred: Familiarity with Splunk and Search Processing Language (SPL).

• Preferred: Experience in integrating or utilizing security scanning tools in CI/CD pipelines.

• Preferred: Experience in auditing Infrastructure as Code such as Terraform and CloudFormation.

• Preferred: Ability to translate complex technical security risks into actionable insights.

• Preferred: Self-motivated with continuous self-learning and independent research on emerging threats and technologies.

• Preferred: Hands-on experience in configuring and managing enterprise scanning platforms like Tenable, Qualys, and Rapid7.

• Must be a U.S. Person for work involving U.S. Government classified environments.

• May need to be a U.S. citizen for work required by the U.S. government that is designated for U.S. citizens only on U.S. soil.


🏝️ Benefits

• Medical, dental, and vision insurance.

• 401(k) plan with a Cisco matching contribution.

• Paid parental leave.

• Coverage for short- and long-term disability.

• Basic life insurance.

• Eligibility for Cisco restricted stock unit grants, contingent upon continued employment and vesting periods.

• 10 paid holidays each full calendar year.

• 1 floating holiday for non-exempt employees.

• 1 paid day off to celebrate the employee’s birthday.

• Paid holiday shutdown at year-end.

• 4 paid days for personal wellness.

• 16 days of paid vacation each full calendar year for non-exempt employees.

• A flexible vacation time-off program with no defined limit for eligible exempt employees, subject to availability and business constraints.

• 80 hours of sick time off provided upon hire and each January 1st thereafter.

• Up to 80 hours of unused sick time can be carried forward annually.

• Additional paid leave for critical or emergency family matters.

• Optional 10 paid volunteer days each full calendar year.

• Annual bonuses available for non-sales roles, in accordance with Cisco policies.

• Performance-based incentive pay for employees on sales plans.

• Opportunities for professional growth and development.

People also viewed

Conduent9 hours ago

MS Dynamics Engineer

US flagUnited States OnlyFull-timeEngineer$80.1k – $104k/year
ApplyView job
Arctiq9 hours ago

Sentinel Engineer

US flagTennessee OnlyFull-timeEngineer
ApplyView job
Mercor10 hours ago

Industrial Hygienist / Process Safety Engineer

US flagUnited States OnlyFreelanceEngineer$65 – $75/hour
ApplyView job
AtkinsRéalis10 hours ago

Intermediate Process Engineer, Energy

US flagTennessee, +1 more stateFull-timeEngineer$72k – $138.7k/year
ApplyView job
Whitefox11 hours ago

Senior Execution Engineer

US flagMinnesota OnlyFull-timeEngineer
ApplyView job
Cisco11 hours ago

Senior Escalation Engineer, Hypershield

US flagAlabama, +45 more statesFull-timeEngineer$160.8k – $214.1k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers