Job Closed

This listing is no longer active.

Lead Vulnerability Management Security Engineer

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 1,001-5,000Since 1973H1B No SponsorCompany SiteLinkedIn

Location

Arizona + 4 moreAll locations: Arizona | California | Texas | Utah | Washington

Posted

171 days ago

Salary

$120K - $130K / year

Seniority

Senior

Bachelor Degree4 yrs expEnglishPython

Job Description

Lead Vulnerability Management Security Engineer

Deckers Brands

• Lead the review and analysis of vulnerability data to identify trends, patterns, and key risks across Deckers’ global environment • Facilitate vulnerability management meetings and drive risk-based discussions to prioritize and accelerate remediation efforts • Advise and support remediation teams in developing actionable plans to address vulnerabilities and strengthen our security posture • Perform risk-based assessments for both on-premise and cloud-based services, ensuring robust protection for critical assets • Integrate advanced security technologies and automation tools to enhance threat detection and response capabilities • Build and present business cases for adopting new security solutions to mitigate emerging risks • Develop, consolidate, and maintain security metrics to measure the effectiveness of our cybersecurity program • Apply industry-leading frameworks (NIST, ISO27001/2, CIS Top 20 Controls) to establish and maintain best-in-class security measures • Foster strong relationships with technical teams, serving as a trusted advisor and championing a culture of security awareness • Contribute to the strategic direction of the Technical Security team by designing and implementing tools that enhance customer trust and detect suspicious activity

Job Requirements

  • BA/BS degree or equivalent experience in a relevant field
  • Security professional certification (CISSP, CVA, GEVA, or similar) preferred
  • 4+ years of hands-on experience in vulnerability management, including scanning, assessment, and remediation
  • Proven success in starting and growing a vulnerability management program
  • Proficiency with leading vulnerability management tools (Tenable, CrowdStrike) and scripting/automation languages (PowerShell, Python)
  • Deep understanding of security frameworks and compliance standards (NIST, ISO27001/2, CIS Top 20 Controls, PCI-DSS, HIPAA)
  • Strong analytical skills to identify patterns, trends, and actionable insights from complex vulnerability data
  • Excellent communication skills for reporting and stakeholder engagement
  • Collaborative mindset with the ability to serve as a trusted advisor across cross-functional teams
  • Self-driven, strategic thinker with a passion for advancing cybersecurity programs.

Benefits

  • Competitive Pay and Bonuses
  • Financial Planning and wellbeing
  • Time away from work
  • Extras, discounts and perks
  • Growth and Development
  • Health and Wellness

Related Categories

Related Job Pages

More Security Engineer Jobs

Cobalt AI logo

Senior Security Engineer

Cobalt AI

DETECT MORE. RESPOND FASTER. SAVE MONEY.

Security Engineer172 days ago
Full TimeRemoteTeam 51-200Since 2016H1B No Sponsor

• Run Cobalt's endpoint and cloud asset security stack across managed laptops, desktops, and cloud infrastructure — including EDR, vulnerability management, and continuous compliance monitoring tooling • Administer Cobalt's compliance automation platform as the system of record for controls and evidence — manage personnel records, reconcile against HRIS and identity provider data, and handle edge cases outside the primary HRIS • Own end-to-end onboarding and offboarding security across employees, contractors, and external partners — verify new hires complete security gating before access is provisioned, apply the right requirements for each personnel tier, and close out access promptly when people leave • Triage alerts from EDR, SIEM, and the vulnerability scanner; recommend patches, file risk acceptances, and gather evidence to close out remediations • Co-own Cobalt's SOC 2 program — coordinate with auditors, gather evidence from internal teams, and run control testing (SSO, IAM, change management, access reviews) ahead of fieldwork • Maintain Cobalt's security policies (vulnerability management, logging and monitoring, incident response, access control), keep them current as the business evolves, and draft new policies when we identify gaps • Own the customer security questionnaire pipeline — partner with Sales, GTM, and product leads to turn around SIG, CAIQ, and bespoke vendor assessments quickly and accurately • Run vendor security reviews for new software and services Cobalt adopts, with clear turnaround expectations and a process the rest of the company can rely on • Triage suspected phishing reports and serve as incident manager when something happens — scope, contain, document, and run the postmortem • Own annual security awareness training rollout and tracking across the company • Partner with Engineering to secure the Cobalt Monitoring Intelligence platform at the edge and bring security perspective into design and code review • Support pen test engagements end-to-end: scoping, remediation tracking, and re-test follow-up

California
$160K - $190K / year
DuckDuckGo logo

Senior Web Security Engineer, Browser Platform

DuckDuckGo

Independent internet privacy company. Download our browser with privacy built-in, unlike Chrome, on mobile & desktop.

Security Engineer172 days ago
OtherRemoteTeam 51-200Since 2008H1B No Sponsor

• Conduct browser security audits (special pages, DuckAI integrations, password manager, etc.) • Execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code) • Manage application security scanning infrastructure setup (aka SAST/DAST integrations in GitHub) • Deliver on Internal red-team operations (simulated attack scenarios) • Support security triage

United States
$178.5K / year
Full TimeRemoteTeam 5,001-10,000H1B No Sponsor

• Diseñar e implementar prácticas de Seguridad en la Nube y DevSecOps • Asegurar la seguridad de los datos en entornos de nube • Desarrollar flujos de trabajo automatizados de detección y respuesta

Spain
Mozilla logo

Staff Security Engineer, Product Security

Mozilla

Feel good about your work again.

Security Engineer172 days ago
OtherRemoteTeam 501-1,000Since 1998H1B Sponsor

• Safeguard millions of users by embedding security into Firefox, Mozilla VPN, and other mission-critical products. • Ensure software products are secure by embedding security into the full Software Development Life Cycle (SDLC). • Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation. • Perform security code reviews • Lead penetration testing on web, mobile, and embedded applications, then guide remediation efforts. • Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early. • Partner with engineers to integrate security throughout the software development lifecycle—not as an afterthought, but as a core design principle. Provide security guidance, develop secure solutions, and facilitate secure releases. • Help define and enforce security policies and provide security guidance to development teams. • Help shape Mozilla's security culture through collaboration, guidance, and education.

United States
$138K - $217K / year
Job Closed