
Vulnerability Management Engineer
Posted Jul 21

Posted Jul 21
This is a fully remote position, open to applicants in India.
• Oversee Vulnerability Scanning Infrastructure: Set up, schedule, and maintain authenticated credentials, scanning policies, and asset groups across client networks and cloud-based environments utilizing enterprise platforms (Tenable/Nessus, Qualys, Rapid7 InsightVM, and Vanta).
• Conduct Threat Analysis and Risk Prioritization: Analyze raw scan results and filter out false positives; apply sophisticated risk-based prioritization data using CVSS base scores, EPSS real-time exploit indices, global threat intelligence feeds, and critical contexts of client assets.
• Facilitate Collaborative Remediation and Governance: Convert technical vulnerabilities into concise, actionable architectural guidance and patch-management workflows; work closely alongside client software engineers and IT teams to streamline remediation efforts and enhance their sub-30-day remediation timeline.
• Oversee Exceptions and Audit Compliance: Document, confirm, and monitor formal client requests for temporary vulnerability exceptions or long-term risk acceptances; align operational patching data with the control evidence necessary for regulatory audits (SOC 2, ISO 27001, HIPAA, CMMC, and NIST).
• Manage the Advisory Client Experience: Serve as the primary strategic point of contact and trusted security advisor for a designated portfolio of rapidly growing startups; provide regular project updates, address high-priority technical escalations with professionalism, and create regular status reports and executive summaries that translate technical risk into clear business value.
• Demonstrated experience as an enterprise vulnerability engineer - Expertly execute operations related to configuring, deploying, and maintaining top-tier vulnerability discovery platforms, specifically using Tenable/Nessus, Qualys, Rapid7 InsightVM, or Vanta.
• Expertise in risk prioritization - Proficient in advanced risk scoring frameworks including CVSS base scores and EPSS real-time exploit probability indices to identify, rank, and address high-impact threats.
• Skilled threat analyst - Analyzed extensive raw scanning datasets, systematically verified results to remove false positives, and transformed complex technical threat data into understandable business risk metrics.
• Advanced infrastructure posture auditor - Assessed, categorized, and documented various classes of vulnerabilities, cloud/container exposure vectors, active exploit mechanisms, and configuration flaws within distributed system architectures.
• GRC architecture strategist - Ensured automated infrastructure scanning protocols align with regulatory compliance frameworks, specifically correlating continuous monitoring records with stringent audit evidence controls for SOC 2, ISO 27001, HIPAA, and CMMC.
• High-velocity technical consultant - Developed precise technical blueprints, organized project milestones, and progress matrices while managing deliverables across an active client account portfolio.
• Elite stakeholder diplomat - Established immediate trust and conducted technical risk calibrations directly with US-based tech founders, engineering executives, and corporate leaders through clear, business-oriented communication.
• Management of patch management pipelines - Proven experience in handling full-lifecycle patch deployments, technical change management workflows, and remediation sequences while collaborating with distributed IT, DevOps, and software engineering teams in a managed service provider (MSP/MSSP) or consulting setting.
• Credentialed cybersecurity specialist - Possess active, validated professional industry certifications such as CompTIA Security+, CEH, Tenable Certified Security Associate, or GIAC GEVA.
• Cloud-native security engineering - Hands-on experience in mapping, configuring, and securing cloud-native vulnerability surfaces across public multi-cloud hosting platforms, specifically in AWS, GCP, and Azure environments.
• Proficient in threat intelligence syndication - Advanced understanding of the CVE lifecycle, National Vulnerability Database (NVD) registries, and real-time threat feed integrations to intercept and preempt real-world exploits.
• Career Development: Clear path with mentorship and training opportunities.
• Technical Training: Comprehensive onboarding on security and compliance frameworks.
• Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
• Growth Opportunity: Early-stage company with significant room for career advancement.
• Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
Anduril Industries
Sargent & Lundy
Sargent & Lundy
Get handpicked remote jobs straight to your inbox weekly.