Job Summary
As a member of the Cyber Security team, the Cyber Security Senior Engineer for Vulnerability Management will be responsible for developing, implementing, and operating vulnerability management solutions to identify, classify, and report existing and emerging vulnerabilities detected in enterprise infrastructure. The Senior Engineer will operate within the existing exposure management team as an expert in vulnerability management, ensuring sound practices while designing, growing, and maintaining the vulnerability management program, contributing to vulnerability identification and remediation methodologies, supporting penetration testing practices, report generation, and more. The Senior Engineer will be responsible for seeking out and reporting on vulnerability discoveries and classifications of new vulnerabilities as well as partnering with Threat Intelligence to incorporate current threat activity into risk prioritization. The Senior Engineer will work directly with other security and information technology team members to develop plans for reporting and remediation of vulnerabilities across all operating systems and applications in the enterprise.
Essential Duties and Responsibilities
Education
H.S. Diploma or GED required Bachelor’s or Master’s Degree in Cyber Security, Computer Science, Information Systems (or other related field), or equivalent work experience preferredRequired Experience
Duration: 3+ years of IT or information security, and 2+ years of vulnerability management Activities: Practical experience with designing and implementing technologies related to vulnerability management including vulnerability scanning, penetration testing, and configuration management Served as expert thought leader for vulnerability management technologies and influenced the strategy for remediation Worked in process-driven structured environments and participated in process optimization activities. Competencies: In-depth knowledge of CVEs, CVSS, threat modeling, and vulnerability scanning technologies. Familiarity with industry frameworks and standards such as NIST, CIS, and CVSS. Strong understanding of operating systems, network protocols, and web applications. Hands-on experience with vulnerability scanning and assessment tools (e.g., Nessus, Qualys, OpenVAS). Excellent analytical and problem-solving skills, with the ability to prioritize and address vulnerabilities based on risk. Strong communication and collaboration skills to work effectively with cross-functional teams. Relevant certifications such as CISSP, CISA, or GIAC certifications are a plus. Commitment to continuous learning and staying updated on the latest trends and threats in the field of vulnerability management. Strong understand of lifecycle management principles and their application to the remediation of cybersecurity vulnerabilities Effective communication of technical concepts to a non-technical audience Excellent written and verbal communication skillsPreferred Experience
3+ years of vulnerability managementComputer Skills Required
● Productivity suite software required
● Python, Powershell, Microsoft SQL, industry standard vulnerability scanning software, and various other cybersecurity tools preferred
Licenses and Certifications
SANS Certifications, GIAC Certifications, EC Council CEH preferredPhysical Demands
In order to successfully perform this job, with or without a reasonable accommodation, the following are outlined below: