Job Closed
This listing is no longer active.
Lead Security Engineer – Vulnerability Management
Location
Arizona + 4 moreAll locations: Arizona | California | Texas | Utah | Washington
Posted
93 days ago
Salary
$145K - $155K / year
Seniority
Senior
Job Description
Lead Security Engineer – Vulnerability Management
Deckers Brands
• Architect and lead the end-to-end vulnerability management lifecycle, ensuring alignment with global security frameworks such as NIST, ISO 27001/2, and CIS Top 20 • Lead high-level risk discussions with business and technical stakeholders to transform raw vulnerability data into prioritized, actionable remediation roadmaps • Serve as a trusted security advisor to infrastructure and application teams, fostering a culture of shared accountability for security debt and remediation • Design and maintain a comprehensive security metrics program using BI tools (e.g., Tableau) to communicate program effectiveness and residual risk to executive leadership • Drive the strategic selection, integration, and optimization of advanced security technologies to ensure a future-ready defense against emerging threats • Spearhead the use of Python, PowerShell, and API integrations (with tools like CrowdStrike) to automate repetitive workflows and improve the Mean Time to Remediate (MTTR) • Own the development and continuous improvement of cybersecurity policies and standards, ensuring they reflect current global threat intelligence and regulatory requirements • Perform complex, risk-based assessments of both on-premises and cloud-native services to ensure consistent security controls across a hybrid environment • Build and present compelling technical and business cases for security investments, securing buy-in for initiatives that mitigate critical enterprise vulnerabilities
Job Requirements
- BA/BS degree, or equivalent experience
- Security professional certification, such as Global Information Assurance Certifications, Certified Information Systems Security Professional (CISSP), Certified Vulnerability Assessor (CVA), GIAC Enterprise Vulnerability Assessor (GEVA), or other similar credentials, is desired
- Demonstrated success in architecting, implementing, and scaling enterprise-grade vulnerability management programs from the ground up
- 7+ years of extensive experience in security vulnerability management, including sophisticated scanning methodologies, risk-based assessment, and complex remediation orchestration
- Advanced hands-on experience with industry-leading vulnerability management platforms and their integration into the broader security stack
- Deep understanding of mapping vulnerability remediation to regulatory frameworks and standards such as PCI-DSS, HIPAA, SOC2, and GDPR
- Proven ability to author and enforce enterprise security policies, standards, and SLAs that drive measurable risk reduction
- Expert-level skill in developing and presenting high-fidelity security metrics and KPIs to influence executive-level decision-making
- Advanced knowledge of current and emerging threat vectors, exploit techniques, and the ability to pivot strategies based on the evolving global landscape
- Strong background in aligning vulnerability data with Incident Response (IR) and Threat Hunting workflows to accelerate containment and recovery
- Experience serving as a technical lead on large-scale infrastructure and cloud security initiatives, ensuring "secure-by-default" configurations
- Proficiency with vulnerability management tools (e.g., Tenable, CrowdStrike) and scripting/automation languages (e.g., PowerShell, Python)
- In-depth understanding of security frameworks and standards (NIST, ISO27001/2, CIS Top 20 Controls)
- Strong knowledge of compliance standards and regulatory requirements (e.g., PCI-DSS)
- Ability to analyze complex vulnerability data to identify patterns, trends, and actionable insights
- Risk-based assessment capabilities to prioritize and address critical vulnerabilities effectively
- Strong verbal and written communication skills for reporting and stakeholder engagement
- Proven ability to collaborate with cross-functional teams, serving as a trusted advisor
- Ability to identify gaps in security measures and propose effective solutions
- Strategic mindset for building business cases and influencing security tool adoption
- Self-driven with the ability to manage and update cybersecurity policies and standards independently
- Strategic thinking to contribute to the advancement of the cybersecurity program.
Benefits
- Competitive Pay and Bonuses
- Financial Planning and wellbeing
- Time away from work
- Extras, discounts and perks
- Growth and Development
- Health and Wellness
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Network Security Engineer
General DynamicsA business unit of General Dynamics, General Dynamics Information Technology (GDIT) supports some of the United States' most complex government, defense, and in
• Complete understanding and wide application of technical principles, theories and concepts in Zscaler • Considerable knowledge in the following areas: TCP/IP (IPv4 and IPv6), Fortinet Firewall, security principles, and troubleshooting • Define, implement, and maintain corporate security policies • Experience with deployment and documentation of enterprise project management and change management processes • Ability to identify solutions to potential network issues • Collaborate on problem management and root cause analysis discussions with fellow network engineers, security engineers and analysts • Draft technical requirements, configuration management, and planning documentation • Other duties as assigned
• Lead security design and threat modeling for new and existing systems (cloud, application, data, network) • Implement and manage core controls: IAM/SSO, least privilege, network segmentation, encryption and key management, secrets management, endpoint and email security • Build and operate detection and response capabilities: SIEM/EDR/SOAR, log pipelines, alert tuning, use-case development, threat hunting • Own vulnerability remediation: scanning, triage, risk-based prioritization, remediation with product/IT teams, tracking to closure • Strengthen application and cloud security: SAST/DAST/SCA, secure SDLC, CI/CD guardrails, IaC scanning, container/Kubernetes runtime protections, CSPM/CIEM • Coordinate and support security testing: internal reviews, penetration tests, red/purple team, tabletop exercises; drive remediation and lessons learned • Lead/participate in incident response: triage, containment, eradication, recovery, forensics, root-cause analysis, post-incident reports and runbooks • Define and maintain security standards, baselines, hardening guides, and architecture diagrams • Monitor and report security metrics, KPIs/KRIs, and risk posture to stakeholders • Support audits and compliance efforts (e.g., SOC 2, ISO 27001, PCI DSS, HIPAA) and align controls to frameworks (NIST CSF, CIS Controls) • Conduct third‑party/vendor security reviews and support contract/security requirements • Drive security awareness initiatives and phishing simulations; mentor engineers on secure practices • Contribute to business continuity and disaster recovery planning and testing • Automate repetitive tasks and integrations to improve scale and reliability
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description The Cyber Resiliency and Recovery Expert plays a hands-on assurance role in ensuring the organisation can withstand and rapidly recover from major cyber incidents - especially ransomware events. Working in the 2nd line of defence, this role conducts structured, evidence-based assessments of recovery capabilities and applies an independent lens to evaluate and measure recovery readiness, objectively assess gaps and provide recommendations for leadership action. Acting as a trusted partner across Technology, Security, Operations, and Risk, the specialist provides expert insight into the soundness of recovery designs, operational readiness, and the effectiveness of recovery strategies. This role suits someone with a strong foundation in technology infrastructure or cyber security who is looking to move into - or deepen their experience in independent assurance and recovery validation. Key responsibilities - Design and maintain an enterprise-wide Recovery Readiness & Assurance Framework, including measurable validation criteria and success indicators. - Assess recovery runbooks against defined success criteria — identifying gaps, untested assumptions, and sequencing risks - Establish consistent validation and testing processes, driving continuous improvement in cyber recovery readiness. - Conduct detailed analysis of technical recovery architectures, verifying assumptions and dependencies, limitations and operational feasibility. - Independently validate recovery capabilities, including completeness of backups, , restoration feasibility, interconnection testing and data reconciliation approaches. - Identify hidden dependencies, potential failure points, and resilience gaps across systems, processes, and teams. - Plan and execute structured recovery simulations and scenario-based validation exercises (e.g., ransomware, data corruption). - Validate restoration sequencing, decision points, and end-to-end execution workflows to ensure operational readiness. - Document validation evidence, outcomes, and readiness assessments, ensuring clarity and traceability for stakeholders. - Translate findings into actionable remediation recommendations, driving improvements across technology and operations. - Serve as a trusted advisor to Technology, Security, and Risk partners, providing expert guidance on cyber resiliency and recovery best practices. Essential Skills - Minimum 5 years’ hands on experience in cyber resiliency, disaster recovery engineering, infrastructure recovery, backup/restore validation or technology risk management. - Solid working knowledge of enterprise infrastructure recovery - AD, DNS, PKI, PAM, backup and restore processes - Practical experience completing business-critical recovery validation exercises (e.g., VM/database restores, cloud recovery tests, ransomware-style simulations) with evidence of outcomes. - Experience in engaging with senior technical SMEs and asking probing questions Desirable Skills - Exposure to second-line assurance, internal audit, or technology risk frameworks - Familiarity with offline BCP or crisis communications arrangements - Led or co-led enterprise-level recovery simulations or ransomware scenario tests Supervisory Responsibilities This job does not have supervisory duties. #LI-Remote #LI-JB2 Skills Application Infrastructure, Backup Recovery, Cyber Resiliency, Cybersecurity, Disaster Recovery (DR), IT Infrastrcuture Project Management, Recovery Management, Solution Engineering, Strategic Collaborations, Systems Recovery, Technical Knowledge Compensation Compensation offered for this role is 120,000.00 - 193,725.00 annually and is based on experience and qualifications. The candidate(s) offered this position will be required to submit to a background investigation. Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact. Allstate generally does not sponsor individuals for employment-based visas for this position. Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component. For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance. For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance. To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs. To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint. It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description This position is only open to candidates currently pursuing their associates degree from a community college or trade school. Those currently pursuing their bachelors degree or higher will not be considered for this role. Early Career Apprentice Program Want to work in your field and train on the job? Join our 12–24-month apprentice program! You will earn and learn on the job, receive career guidance and mentorship, all while attending school. Allstate will also provide tuition assistance and hands-on training in customer service and claims processing. Founded by The Allstate Corporation in 2016, Arity is a data and analytics company focused on improving transportation. We collect and analyze enormous amounts of data, using predictive analytics to build solutions with a single goal in mind: to make transportation smarter, safer and more useful for everyone. At the heart of that mission are the people that work here — the dreamers, doers and difference-makers that call this place home. As part of that team, your work will showcase both your intelligence and your creativity as you tackle real problems and put your talents towards transforming transportation. That’s because at Arity, we believe work and life shouldn’t be at odds with one another. After all, we know that your unique qualities give you a unique perspective. We don’t just want you to see yourself here. We want you to be yourself here. Operational Excellence Team As a member of the Operational Excellence team, you’ll help make sure the entire Arity team is enabled and empowered to get things done! It’s our job to ensure Arity is an industry leader both in terms of the products we offer, and by the way in which we deliver and deploy them to our customers. We are one-part business - for example, contracting with customers and suppliers, and one-part risk managers - tackling tough issues like data security and privacy. Our top candidate embraces ambiguity and change. They can see the big picture, understand all the implications that need to be addressed, and lead the team to overcome any hurdles to achieve Arity’s goals. Sound like you? Let’s talk! The Role The Privacy Technology Apprentice supports the Regulatory Compliance and Privacy (RC-P) team’s technology needs by automating manual compliance tasks and developing dashboards and monitoring tools that proactively identify privacy and compliance issues. The apprentice will have the opportunity to administrate and complete development tasks within the OneTrust privacy suite assisting with consumer request and privacy assessment administration and automation improvements. The apprentice will also have the opportunity to use tools such as Tableau, Quick Suite, MS Copilot, and Cursor to build compliance monitors and dashboards. This role reports to the Regulatory Compliance and Privacy Senior Manager. Responsibilities - Serves as both administrator and developer for the OneTrust privacy suite assisting with consumer privacy requests, cookie consent, and privacy assessments - Coordinates with applicable engineering teams to build integrations and workflow automation between OneTrust and internal systems - Assists with technology changes to meet new regulatory requirements, process improvements of issue remediation - Using tools such as Tableau, Quick Suite, MS Copilot, and Cursor, documents and builds privacy and compliance monitors - Utilizing compliance monitors, communicates with applicable teams when issues arise Qualifications - Pursuing a Computer Science, Data Analytics, or similar degree/program preferred - Strong technical aptitude – ability to learn and take ownership of new systems - Ability and willingness to learn how to use AI tools to build technology solutions - Ability and willingness to learn how to use dashboard tools such as Tableau, Power BI, or Quicksight - Basic analytical skills - Flexibility to adapt to business needs and changing regulatory environment. - Strong ethics and integrity - Strong interpersonal skills, written and oral communication skills - Ability to manage time and tasks and deliver results with a sense of urgency - Self-starter – ability to take ownership of work and move tasks to completion Compensation offered for this role is between $18 and $25 an hour and is based on experience and qualifications. Skills Amazon Quicksight, Computer Science, Data Analysis, Microsoft Copilot, Microsoft Power Business Intelligence (BI), Tableau (Software) Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact. Allstate generally does not sponsor individuals for employment-based visas for this position. Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component. For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance. For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance. To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs. To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint. It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.



