
Vulnerability Management Engineer
Posted Jul 21

Posted Jul 21
This is a fully remote position, open to applicants in Philippines.
• Oversee Vulnerability Scanning Infrastructure: Set up, schedule, and manage authenticated credentials, scan policies, and asset groups across client networks and cloud-based environments using enterprise platforms such as Tenable/Nessus, Qualys, Rapid7 InsightVM, and Vanta.
• Perform Threat Analysis and Risk Prioritization: Assess raw scan results and filter out false positives; utilize advanced risk-based prioritization data, including CVSS base scores, EPSS real-time exploit indices, global threat intelligence feeds, and critical client asset contexts.
• Facilitate Collaborative Remediation and Governance: Convert technical vulnerabilities into straightforward, actionable architectural guidance and patch-management workflows; collaborate closely with client software engineers and IT teams to enhance remediation efforts and achieve a sub-30-day time frame for remediation.
• Manage Exceptions and Ensure Audit Compliance: Document, verify, and monitor formal client requests for temporary vulnerability exceptions or long-term risk acceptances; align operational patching data with evidence required for regulatory audits (SOC 2, ISO 27001, HIPAA, CMMC, and NIST).
• Lead the Advisory Client Experience: Serve as the strategic primary point of contact and trusted security advisor for an assigned portfolio of rapidly growing startups; provide regular updates on project milestones, address high-priority technical escalations with professionalism, and create regular status reports and executive summaries that translate technical risk into tangible business value.
• Proven enterprise vulnerability engineer - Expert in operational execution for configuring, deploying, and maintaining leading vulnerability discovery platforms, particularly using Tenable/Nessus, Qualys, Rapid7 InsightVM, or Vanta.
• Skilled risk prioritizer - Proficient in advanced risk scoring frameworks, including CVSS base scores and EPSS real-time exploit probability indices, to identify, rank, and target significant threats.
• Detail-oriented threat analyst - Analyzed extensive raw scanning datasets, systematically validated results to remove false positives, and transformed complex technical threat data into understandable business risk metrics.
• Experienced infrastructure posture auditor - Diagnosed, classified, and cataloged various vulnerability types, cloud/container exposure risks, active exploit mechanisms, and configuration weaknesses across distributed system architectures.
• GRC architecture strategist - Matched automated infrastructure scanning processes with regulatory compliance frameworks, ensuring continuous monitoring records align with stringent audit evidence controls for SOC 2, ISO 27001, HIPAA, and CMMC.
• High-velocity technical consultant - Developed clear technical blueprints, structured project milestones, and progress matrices while effectively managing deliverables across a diverse portfolio of client accounts.
• Exceptional stakeholder diplomat - Built immediate trust and conducted technical risk assessments directly with US-based tech founders, engineering executives, and corporate leaders utilizing clear, business-oriented communication.
• Career Development: Clear path with mentorship and training opportunities.
• Technical Training: Comprehensive onboarding on security and compliance frameworks.
• Competitive Compensation: A competitive base salary with regular performance reviews tied to merit-based evaluations and bonus opportunities.
• Growth Opportunity: Early-stage company offering significant opportunities for career advancement.
• Remote-First Culture: Flexibility to work from any location while collaborating with a global team.
Anduril Industries
Sargent & Lundy
Sargent & Lundy
Get handpicked remote jobs straight to your inbox weekly.