We are seeking a highly experienced and technically proficient Senior Vulnerability Management Engineer to lead and mature our enterprise vulnerability management program. This critical role involves architecting, implementing, and optimizing vulnerability scanning and remediation processes, with a strong emphasis on automation, securing our cloud infrastructure, and managing traditional on-premises systems. The ideal candidate will be a subject matter expert in cloud and traditional security, possess advanced scripting capabilities, and be adept at driving significant security improvements across large, complex environments. In This Role, You Will... Lead the Vulnerability Management Program: Strategically design, implement, and continuously mature the vulnerability scanning and management program across the enterprise, including on-premises infrastructure (servers, network devices), applications, containers, and complex cloud environments. Automation and Engineering: Architect, develop, and maintain robust automation pipelines to integrate vulnerability scanners with cloud APIs, asset inventory, and orchestration tools, significantly reducing manual efforts and improving data accuracy. Cloud and Infrastructure Security Expertise: Serve as a subject matter expert for identifying, assessing, and remediating vulnerabilities specific to both cloud and on-premises services and configurations. Risk Analysis and Prioritization: Continuously refine the risk-based prioritization methodology, ensuring the highest severity and most exploitable vulnerabilities are addressed first, collaborating closely with development and infrastructure teams. Tool Management: Evaluate, deploy, configure, and maintain advanced vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7), ensuring optimal coverage, accuracy, and integration across the hybrid environment. Mentorship and Documentation: Mentor junior team members, develop detailed technical documentation, and define best practices for vulnerability identification, reporting, and remediation. Reporting and Metrics: Define, track, and present advanced security metrics (KPIs/KRIs) and management-level reports on the overall vulnerability posture, remediation trends, and program effectiveness. Process Improvement: Drive measurable improvements in the mean time to detect (MTTD) and mean time to remediate (MTTR) vulnerabilities.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed
Number of Employees
501-1,000 employees