Senior Vulnerability Management Engineer
$190,000–$190,000 year
RemoteUnited States
Job Summary
Own the end-to-end vulnerability management pipeline: asset discovery, scanning, enrichment, prioritization, assignment, verification, and closure. Build and iterate a data-driven prioritization framework blending CVSS, EPSS, KEV, and asset criticality, then automate the full workflow via SOAR playbooks, webhooks, and custom scripts. Integrate scanners, CMDB, EDR, and cloud providers into a unified system while continuously reducing noise through deduplication and false-positive suppression. Lead technical response for emergency patch cycles and develop KPIs to track systemic risk. Apply AI/LLM tooling for triage and remediation guidance under appropriate guardrails. Serve as a subject matter expert to mentor engineering and operations teams.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, or related academic field or equivalent experience
- 5-7 years of professional experience in information security, with focus on the financial sector
- Hands-on experience deploying, configuring, and managing vulnerability scanning solutions at enterprise scale, including policy design, tuning for noise reduction, and managing performance impact (e.g. Tenable, Microsoft Defender, Wiz, Tanium.)
- Hands-on experience engineering, integrating, and optimizing for automation of security platforms (e.g. Swimlane, Elastic)
- Strong knowledge of public cloud platforms (e.g., AWS, Azure, GCP) from an infrastructure and development aspect and their related security features
- Familiarity with DevSecOps practices and CI/CD pipelines
- Understanding of industry security frameworks, standards, and best practices (e.g., NIST, ISO, CIS)
- Proficiency in one or more software programming languages (e.g. Python, Golang, JavaScript), particularly for automation of security platform operations, health monitoring, and integration tasks
- Strong communication and collaboration skills, with the ability to work closely with engineering, operations and infrastructure teams
- Familiarity with compliance standards and regulations
- Creativity and critical thinking with the ability to work both independently and collaboratively in a fast-paced environment
- Be able to serve as a mentor or subject matter expert to other members within the organization, particularly in the areas of vulnerability management and systems engineering
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.