Vulnerability Management Engineer
The job description
Tech stack. Tenable, Qualys, or Rapid7, risk-based prioritization (Kenna, Brinqa), ServiceNow or Jira, CVSS and EPSS scoring, Python, asset inventory platforms, exploit intelligence feeds
About the role
You will run the vulnerability management program for a technology company with a sprawling estate of servers, endpoints, containers, and cloud workloads. The team converts millions of raw scan findings into a prioritized, SLA-driven remediation machine with unambiguous ownership for every asset. You will tune prioritization, drive remediation with busy infrastructure owners, and report risk trends leadership can act on. This role matters because unpatched vulnerabilities remain the most common initial access vector in breaches industry-wide, and your program is what keeps the company's exposure window measured in days instead of months. You will also partner with threat intelligence to prioritize vulnerabilities with known exploitation in the wild. Your program will treat every SLA miss as a process failure to investigate, not just a metric to report.
What you will achieve
- Build risk-based prioritization so the top 5 percent of genuinely exploitable findings receive fixes before everything else, every cycle.
- Drive critical vulnerability SLA compliance above 90 percent across infrastructure, endpoints, containers, and cloud resources.
- Cut mean time to remediate internet-facing critical vulnerabilities to under 72 hours from first detection.
- Automate ticket creation, assignment, aging, and escalation so no finding ever sits without a named owner.
- Publish the monthly exposure report executives use to track security posture trends and hold organizations accountable.
What you will bring
Must-haves
- 2 to 5 years in vulnerability management, security operations, or systems administration roles.
- Hands-on experience with enterprise scanning platforms such as Tenable, Qualys, or Rapid7.
- Understanding of CVSS, EPSS, and risk-based prioritization extending well beyond raw severity scores.
- Experience driving remediation with infrastructure and application owners juggling competing priorities.
- Ability to build dashboards and reports showing risk trends over time, not just point-in-time counts.
- Scripting skills in Python for data analysis, deduplication, SLA computation, and workflow automation.
- Persistence and diplomacy: you follow up relentlessly without becoming the team everyone avoids.
Nice-to-haves
- Experience with attack surface management or continuous pentesting platforms.
- Familiarity with SLA design, exception handling workflows, and formal risk acceptance processes.
- Knowledge of container and cloud-native vulnerability management workflows.
- Exposure to threat-informed prioritization using exploit intelligence.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta