Senior Vulnerability Engineer

King County•Chinook Building 401 5th Avenue Seattle, WA
•Hybrid

About The Position

King County Information Technology (KCIT) is seeking a Senior Vulnerability Engineer to join the Information Security, Risk & Compliance team and lead the technical execution of its enterprise vulnerability management program. The role is responsible for identifying, assessing, validating, and prioritizing vulnerabilities across infrastructure, cloud environments, applications, and network devices. It serves as the technical authority ensuring vulnerabilities are accurately identified, risk-prioritized, and remediated according to policies and SLAs. The position collaborates closely with infrastructure, application, cloud, networking, security operations, and governance teams to reduce cyber risk through continuous monitoring, threat-informed prioritization, automation, and process improvement. Additionally, the engineer provides technical leadership in evaluating emerging threats, implementing vulnerability technologies, developing remediation strategies, and advancing program maturity.

Requirements

  • Four (4) or more years of experience in information security, vulnerability management, application security, security engineering, or related discipline.
  • Strong understanding of modern security vulnerabilities, exploit techniques, and common attack vectors.
  • Deep knowledge of vulnerability scanning tools (e.g., Rapid7, Qualys, Tenable), asset inventory systems, and security orchestration platforms.
  • Familiarity with cloud security (AWS, Azure, GCP), container security, and modern DevOps workflows.
  • Strong understanding of operating systems, networking fundamentals, and secure development practices.
  • Awareness of regulatory, compliance, and industry security standards.
  • Ability to translate technical findings into clear business risk for diverse stakeholders.
  • Strong analytical skills for evaluating vulnerability risk, prioritization, and remediation strategies.
  • Excellent communication and relationship-building skills across technical and non-technical teams.
  • Skill in automating repetitive tasks and improving workflows.
  • Ability to lead cross-team efforts, manage escalations, and drive timely decision-making.

Nice To Haves

  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent practical experience)
  • Relevant security certifications such as OSCP, OSWE, CISSP, GIAC (GSEC, GCIH, GPEN), Security+ or similar are preferred

Responsibilities

  • Manage enterprise vulnerability scanning
  • Validate scanner accuracy and investigate false positives
  • Tune scan templates and credentials
  • Maintain asset inventory coverage
  • Monitor scan health and failures
  • Validate remediation effectiveness
  • Maintain vulnerability exceptions
  • Track remediation SLAs
  • Support external penetration testing
  • Evaluate potential impacts of vulnerabilities
  • Reviewing Microsoft's Patch Tuesday releases
  • Assess vendor advisories
  • Monitor threat intelligence feeds
  • Determine emergency patch requirements
  • Develop remediation recommendations
  • Integrate vulnerability platforms with ticketing systems
  • Automate remediation workflows
  • Develop PowerShell/Python scripts
  • Create APIs between scanning platforms and CMDBs
  • Automate executive reporting
  • Reduce manual effort
  • Communicate vulnerability findings to stakeholders in clear, business focused language
  • Provide guidance on remediation strategies, expected timelines, and resource needs
  • Coordinate with engineering, product, infrastructure, and operations teams to ensure timely vulnerability resolution
  • Set and manage expectations around remediation windows, technical constraints, and risk acceptance considerations
  • Build and maintain strong cross-functional relationships with technical teams, leadership, and compliance groups
  • Recommend secure development practices and process improvements based on recurring vulnerability patterns
  • Act as the escalation point for high-risk or complex vulnerabilities requiring urgent cross-team coordination
  • Evaluate emergency vulnerabilities
  • Determine exposure within the environment
  • Identify affected assets
  • Recommend mitigations
  • Coordinate emergency patching
  • Produce executive impact assessments
  • Support incident response teams
  • Identify systemic issues and streamline vulnerability management processes
  • Enhance scanning tools, asset coverage, reporting, and remediation workflows
  • Maintain and refine policies and procedures to improve program maturity
  • Strengthen prioritization models to align remediation with business risk
  • Integrate security practices earlier in the SDLC through cross-team collaboration
  • Define and track KPIs to measure program effectiveness and guide strategy
  • Lead automation initiatives to reduce manual work and speed remediation
  • Support capability growth through maturity roadmaps and team mentorship

Benefits

  • County-issued laptop
  • Home workspace with an internet connection
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service