Senior Vulnerability Management Engineer (Tenable) - Active Secret clearance
$145,000–$170,000 year
RemoteUnited States
Job Summary
Administer and optimize the full Tenable platform, including Tenable.sc, Tenable Vulnerability Management, and Nessus agents across Windows, Linux, network, and cloud environments. Perform authenticated and unauthenticated vulnerability scans, analyze findings to eliminate false positives, and prioritize remediation efforts. Coordinate closure activities with infrastructure and application teams while managing scan schedules, repositories, and credential failures. Develop executive dashboards, compliance reports, and security metrics to support RMF continuous monitoring, POA&M management, and audit activities. Integrate Tenable with ServiceNow, SIEM, and automation platforms using PowerShell, Python, and Bash. Provide technical mentorship to junior engineers and support security investigations requiring vulnerability analysis.
Required Qualifications
- Active Secret Clearance
- 7+ years of cybersecurity engineering, vulnerability management, or systems engineering experience
- Experience supporting Federal Government or DoD environments
- Deep experience administering Tenable.sc
- Deep experience administering Tenable Vulnerability Management
- Deep experience administering Nessus
- Deep experience administering Nessus Agents
- Strong understanding of vulnerability management lifecycle and remediation processes
- Experience with CVSS scoring
- Experience with Known Exploited Vulnerabilities (KEV)
- Experience with Patch management
- Experience with STIG compliance scanning
- Experience with False-positive validation
- Working knowledge of Windows Server
- Working knowledge of Linux (RHEL, CentOS, Ubuntu)
- Working knowledge of VMware vSphere
- Working knowledge of AWS and/or Azure
- Working knowledge of Enterprise networking (TCP/IP, DNS, VLANs, routing, switching)
- Experience supporting NIST SP 800-53
- Experience supporting Risk Management Framework (RMF)
- Experience supporting DISA STIGs and SRGs
- Experience supporting CMMC
- Experience supporting CIS Benchmarks
- Experience supporting DoD 8570 / 8140 requirements
Desired Qualifications
- TS/SCI clearance
- 5+ years supporting Federal Government or DoD environments
- PowerShell, Python, or Bash scripting
- Tenable API development and automation
- ServiceNow or Jira integration
- SIEM and SOAR platforms
- Executive reporting and security metrics
- Experience improving vulnerability remediation processes and reducing MTTR
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.