Engineer - Vulnerability Management

Ulta Beauty, Inc.Bolingbrook, IL
Hybrid

About The Position

The Engineer - Vulnerability Management is responsible for working with the VM Manager to design, implement, and maintain a robust vulnerability management program across hybrid environments, including on-premises, cloud, containers, and SaaS platforms. This role focuses on technical execution—deploying and tuning scanning tools (Tenable Security Center/Falcon Exposure Management), then using continuous, data driven communication to remediation teams via ServiceNow VR so that they are empowered to address the riskiest vulnerabilities within their environments. The engineer will leverage risk-based prioritization, threat intelligence, and business context to reduce exposure and improve resilience. This position requires deep technical expertise in vulnerability scanning technologies, scripting and automation, and security practices across the traditional and cloud-native spectrum. The engineer will collaborate closely with infrastructure, cloud, application, and security teams to drive remediation according to organizational SLAs, and continuously improve program maturity through metrics, automation, and emerging technologies.

Requirements

  • Bachelor's degree in Computer Science, CIS, or equivalent experience (5+ years in cybersecurity)
  • 3-5 years professional experience in a relevant field
  • Excellent analysis/troubleshooting skills, able to solve problems efficiently
  • Excellent communication skills; feels comfortable working with non-technical business partners
  • Skilled and comfortable with tackling complex challenges, either in leading the troubleshooting effort or advising/leading others
  • Work with production support and project consultants in an onshore / offshore model
  • Able to prioritize and execute tasks in a high-pressure environment
  • Solid knowledge of industry best practices and technical systems
  • Knowledgeable as to IT security concepts, compliance, principles, and tools
  • Ability to work in team in diverse/ multiple stakeholder environments
  • Ability to follow-up, follow through and deliver timely results
  • Proven track record of delivering high quality solutions on time and on schedule

Nice To Haves

  • Preferred Certifications – CISSP or equivalent
  • Retail industry experience preferred

Responsibilities

  • Design, schedule, and optimize authenticated/credentialed scans for on‑prem, cloud, and remote endpoints; ensure minimal disruption and scan hygiene
  • Validate scanner configuration and coverage (e.g., Qualys/Tenable/Rapid7/Falcon Exposure Management) and continuously tune for false-positive reduction
  • Prioritize findings using context: exploit likelihood (EPSS), Known Exploited Vulnerabilities (CISA KEV), network exposure, business impact, compensating controls, and asset criticality
  • Correlate with threat intel and active detections (EDR/XDR/SIEM), elevating actively exploited vulnerabilities to emergency treatment
  • Define severity thresholds and SLAs per asset class; manage exceptions with time-bound risk acceptance and compensating controls.
  • Drive remediation by regularly partnering with Infra/Platform, Cloud, and App teams to empower them to make informed decisions when weighing the priority of patches and configuration changes versus compensating controls and operational realities
  • Integrate with ticketing systems (ServiceNow VR) to ensure that proper assignment logic is in place, and that automated validation scans determine the status of fix actions.
  • Assist the Security Operations team as they execute zero‑day/rapid-response playbooks (e.g. scans/queries, exploitability assessments, validations, enrich post‑mortems)
  • Contribute to and help maintain an accurate, continuously updated asset inventory across a primary scope of endpoints, servers, and network devices, as well as containers, mobile, OT/IoT, and cloud resources (IaaS, PaaS, SaaS)
  • Integrate data from CMDB, cloud provider APIs, EDR/XDR, MDM, and attack surface management to reduce blind spots
  • Assist CMDB owner with categorization of assets for business criticality, data sensitivity, internet-exposure, and ownership to enable risk-based prioritization
  • Perform targeted rescans and exploit-simulation where safe to confirm remediation
  • Tune detection rules to reduce noise; establish a feedback loop with platform owners for recurring findings
  • Run root cause analyses for chronic issues (missing patch baselines, unsupported OS, inadequate maintenance windows)
  • Publish actionable dashboards and reports: weighted risk trends, criticality & exposure trends, SLA adherence, risky asset highlighting, KEV coverage, etc
  • Align with risk and audit frameworks (NIST CSF/800‑53, CIS Controls, ISO 27001, SOC 2) and support audit evidence requests
  • Maintain policy/standards for scanning coverage, remediation SLAs, and risk acceptances.
  • Work with teams utilizing existing scanning in their CI/CD pipelines and enforce policy gates for images, IaC, and dependencies
  • Partner with cloud engineering to communicate misconfigurations (CSPM/CNAPP) and high-risk services (public S3, exposed admin ports, overly permissive IAM)
  • Champion SBOM generation and consumption; track vulnerable components (e.g., Log4j) across apps, images, and functions
  • Act as the primary point of contact with Infra/Platform, Cloud, AppSec, Networking, and Business Owners for remediation prioritization
  • Communicate risk in business terms; escalate blockers; provide clear, concise guidance
  • Build automation for asset enrichment, ticket creation, SLA tracking, and report generation (APIs, scripts, workflows)
  • Evaluate and pilot emerging capabilities (exposure management, ASM, CNAPP) and drive vendor/tool rationalization
  • Work across groups to identify opportunities for improvement within the environment, both technical and operational, along with plans to capture those benefits.
  • Responsible for ensuring adherence to existing processes both operationally, and in support of PCI and/or SOX audit requirements.
  • Collaborate with other members of the Engineering organization to create and maintain standards and operating procedures, and provide information as appropriate to manager, project manager, and various departments within the Company.

Benefits

  • paid time off
  • health
  • dental
  • vision
  • life and disability benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service