Engineer III, Vulnerability Management

CencoraPhiladelphia, PA

About The Position

The Engineer III - Vulnerability Management is a senior technical contributor responsible for identifying, analyzing, prioritizing, reporting, and driving remediation of vulnerabilities and posture findings across enterprise environments. This role supports and helps mature a unified, risk-based Vulnerability and Posture Management capability spanning infrastructure, endpoints, cloud workloads, network devices, applications, SaaS platforms, external attack surface, and other critical assets. The Engineer III will help lead Continuous Threat Exposure Management (CTEM) activities, operate and optimize attack surface management and vulnerability management tools, and partner with technology, security, and business stakeholders to measurably reduce cyber risk.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Engineering, or a related field, or equivalent practical experience.
  • 7-10 years of combined experience in information technology, cybersecurity, systems administration, cloud operations, network security, application security, security engineering, or related disciplines.
  • At least 4 years of hands-on experience in vulnerability management, exposure management, attack surface management, configuration assurance, or a closely related cybersecurity function.
  • At least one active cybersecurity certification, such as CISSP, CISM, Security+, CySA+, GSEC, CCSK, CCSP, OSCP, GIAC certification, or another recognized security certification.
  • Strong understanding of vulnerability lifecycle management, including discovery, validation, prioritization, remediation, exception handling, rescan validation, and reporting.
  • Experience using vulnerability assessment or vulnerability management platforms such as Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Wiz, Armis, or comparable tools.
  • Experience with attack surface, posture, or exposure management capabilities such as CAASM, EASM, RBVM, CSPM, SSPM, external posture management, or security ratings platforms.
  • Ability to interpret vulnerability findings, CVEs, CVSS, EPSS, threat intelligence, exploitability indicators, asset context, and compensating controls to prioritize risk.
  • Experience working with enterprise asset data, CMDB data, ownership models, assignment groups, and business criticality attributes.
  • Strong analytical skills with experience using Excel, Power BI, SQL, data lakes, reporting platforms, or other data analysis and visualization tools.
  • Working knowledge of common security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Critical Security Controls, PCI DSS, HIPAA, GDPR, OWASP Top 10, SANS Top 25, and MITRE ATT&CK.
  • Excellent written and verbal communication skills, with the ability to explain technical risk to both technical and non-technical audiences.
  • Demonstrated ability to coordinate cross-functional remediation activities in a complex enterprise environment.

Nice To Haves

  • Experience helping build or mature a CTEM, exposure management, or unified risk-based vulnerability management program.
  • Experience with vulnerability workflow automation, ServiceNow SecOps, Jira, SOAR, or similar remediation workflow platforms.
  • Experience consolidating and normalizing vulnerability data across multiple source tools and integrating results into dashboards, remediation queues, or governance workflows.
  • Experience with cloud security and cloud posture management across AWS, Azure, Google Cloud, or hybrid environments.
  • Experience with external attack surface management, SaaS security posture management, configuration assurance, or third-party exposure management.
  • Experience supporting regulatory, audit, customer assurance, or compliance reporting related to vulnerability and exposure management.
  • Familiarity with scripting or automation using Python, PowerShell, APIs, or query languages to improve reporting, remediation tracking, and data quality.
  • Ability to influence without direct authority and lead cross-functional initiatives across technical teams, business stakeholders, and security leadership.

Responsibilities

  • Perform advanced vulnerability analysis across infrastructure, cloud, endpoint, network, application, SaaS, and externally facing assets.
  • Lead and support Continuous Threat Exposure Management (CTEM) processes, including scoping, discovery, prioritization, validation, mobilization, and ongoing risk reduction activities.
  • Operate and improve vulnerability management, attack surface management, external posture management, cloud posture and SaaS posture capabilities.
  • Analyze vulnerability and posture data from multiple sources, normalize findings, and develop actionable risk-based remediation priorities.
  • Assess vulnerabilities using business context, asset criticality, exploitability, threat intelligence, exposure, compensating controls, and regulatory or compliance impact.
  • Drive remediation and risk treatment efforts with infrastructure, cloud, network, application, endpoint, DevOps, and business technology teams.
  • Lead emerging vulnerability and critical exposure response activities, including impact analysis, stakeholder coordination, mitigation tracking, and executive-level status reporting.
  • Create and maintain dashboards, metrics, and reporting for vulnerability trends, remediation progress, SLA performance, exposure reduction, attack surface changes, and program maturity.
  • Support implementation and optimization of unified vulnerability management workflows, including ticketing, ownership assignment, exception handling, rescan validation, remediation automation, and governance routines.
  • Evaluate and recommend improvements to scanning coverage, asset inventory quality, vulnerability data integrity, risk scoring, and stakeholder reporting.
  • Translate complex technical findings into clear remediation guidance for technical teams and concise risk summaries for leadership.
  • Contribute to security standards, procedures, playbooks, process documentation, and continuous improvement initiatives for the Vulnerability and Posture Management program.
  • Mentor junior engineers and analysts by providing technical guidance, quality review, and support for vulnerability triage and remediation governance.

Benefits

  • medical
  • dental
  • vision care
  • backup dependent care
  • adoption assistance
  • infertility coverage
  • family building support
  • behavioral health solutions
  • paid parental leave
  • paid caregiver leave
  • training programs
  • professional development resources
  • mentorship programs
  • employee resource groups
  • volunteer activities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service