Remotery

Vulnerability Management Engineer

Posted Jul 21

This is a fully remote position, open to applicants in India.

📋 Description

• Oversee Vulnerability Scanning Infrastructure: Set up, schedule, and maintain authenticated credentials, scanning policies, and asset groups across client networks and cloud-based environments utilizing enterprise platforms (Tenable/Nessus, Qualys, Rapid7 InsightVM, and Vanta).

• Conduct Threat Analysis and Risk Prioritization: Analyze raw scan results and filter out false positives; apply sophisticated risk-based prioritization data using CVSS base scores, EPSS real-time exploit indices, global threat intelligence feeds, and critical contexts of client assets.

• Facilitate Collaborative Remediation and Governance: Convert technical vulnerabilities into concise, actionable architectural guidance and patch-management workflows; work closely alongside client software engineers and IT teams to streamline remediation efforts and enhance their sub-30-day remediation timeline.

• Oversee Exceptions and Audit Compliance: Document, confirm, and monitor formal client requests for temporary vulnerability exceptions or long-term risk acceptances; align operational patching data with the control evidence necessary for regulatory audits (SOC 2, ISO 27001, HIPAA, CMMC, and NIST).

• Manage the Advisory Client Experience: Serve as the primary strategic point of contact and trusted security advisor for a designated portfolio of rapidly growing startups; provide regular project updates, address high-priority technical escalations with professionalism, and create regular status reports and executive summaries that translate technical risk into clear business value.


⛳️ Requirements

• Demonstrated experience as an enterprise vulnerability engineer - Expertly execute operations related to configuring, deploying, and maintaining top-tier vulnerability discovery platforms, specifically using Tenable/Nessus, Qualys, Rapid7 InsightVM, or Vanta.

• Expertise in risk prioritization - Proficient in advanced risk scoring frameworks including CVSS base scores and EPSS real-time exploit probability indices to identify, rank, and address high-impact threats.

• Skilled threat analyst - Analyzed extensive raw scanning datasets, systematically verified results to remove false positives, and transformed complex technical threat data into understandable business risk metrics.

• Advanced infrastructure posture auditor - Assessed, categorized, and documented various classes of vulnerabilities, cloud/container exposure vectors, active exploit mechanisms, and configuration flaws within distributed system architectures.

• GRC architecture strategist - Ensured automated infrastructure scanning protocols align with regulatory compliance frameworks, specifically correlating continuous monitoring records with stringent audit evidence controls for SOC 2, ISO 27001, HIPAA, and CMMC.

• High-velocity technical consultant - Developed precise technical blueprints, organized project milestones, and progress matrices while managing deliverables across an active client account portfolio.

• Elite stakeholder diplomat - Established immediate trust and conducted technical risk calibrations directly with US-based tech founders, engineering executives, and corporate leaders through clear, business-oriented communication.

• Management of patch management pipelines - Proven experience in handling full-lifecycle patch deployments, technical change management workflows, and remediation sequences while collaborating with distributed IT, DevOps, and software engineering teams in a managed service provider (MSP/MSSP) or consulting setting.

• Credentialed cybersecurity specialist - Possess active, validated professional industry certifications such as CompTIA Security+, CEH, Tenable Certified Security Associate, or GIAC GEVA.

• Cloud-native security engineering - Hands-on experience in mapping, configuring, and securing cloud-native vulnerability surfaces across public multi-cloud hosting platforms, specifically in AWS, GCP, and Azure environments.

• Proficient in threat intelligence syndication - Advanced understanding of the CVE lifecycle, National Vulnerability Database (NVD) registries, and real-time threat feed integrations to intercept and preempt real-world exploits.


🏝️ Benefits

• Career Development: Clear path with mentorship and training opportunities.

• Technical Training: Comprehensive onboarding on security and compliance frameworks.

• Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.

• Growth Opportunity: Early-stage company with significant room for career advancement.

• Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.

People also viewed

Utopia8 hours ago

Engenheiro de Orçamentos

BR flagBrazil OnlyFull-timeEngineer
ApplyView job
Anduril Industries8 hours ago

Senior Airworthiness Engineer – Advanced Effects

US flagUnited States OnlyFull-timeEngineer$146k – $194k/year
ApplyView job
Sargent & Lundy8 hours ago

Lead Nuclear Component Engineer

US flagUnited States OnlyFull-timeEngineer$118k – $180.3k/year
ApplyView job
Sargent & Lundy8 hours ago

License Renewal Engineer Consultant 2 – Electrical, Nuclear

US flagUnited States OnlyFull-timeEngineer$145.3k – $222k/year
ApplyView job
SMS Environmental Ltd8 hours ago

Plumbing Remedial Engineer

GB flagUnited Kingdom OnlyFull-timeEngineer£32k – £38k/year
ApplyView job
DoorDash8 hours ago

Senior Detection Engineer

US flagUnited States OnlyFull-timeEngineer$159.8k – $235k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers