Best-in-class trust services for high-growth companies. Vanta’s biggest services partner.
Vulnerability Management Engineer
Location
India
Posted
14 days ago
Salary
0
Seniority
Senior
Job Description
Vulnerability Management Engineer
Workstreet
• Orchestrate Vulnerability Scanning Infrastructure: Configure, schedule, and maintain authenticated credentials, scan policies, and asset groups across client networks and cloud-native environments using enterprise platforms (Tenable/Nessus, Qualys, Rapid7 InsightVM, and Vanta). • Execute Threat Analysis and Risk Prioritization: Evaluate raw scan outputs and filter false positives; apply advanced risk-based prioritization data utilizing CVSS base scores, EPSS real-time exploit indices, global threat intelligence feeds, and critical client asset contexts. • Drive Collaborative Remediation and Governance: Translate technical vulnerabilities into clear, actionable architectural guidance and patch-management workflows; partner directly inside the trenches with client software engineers and IT teams to multi-thread remediation efforts and accelerate their sub-30-day time-to-remediate velocity. • Manage Exceptions and Audit Compliance: Document, verify, and track formal client requests for temporary vulnerability exceptions or long-term risk acceptances; map operational patching data directly to control evidence required for regulatory audits (SOC 2, ISO 27001, HIPAA, CMMC, and NIST). • Own the Advisory Client Experience: Act as the strategic primary point of contact and trusted security advisor for an assigned portfolio of fast-growth startups; deliver regular project milestones, handle high-priority technical escalations with calm professionalism, and generate regular status reports and executive summaries that communicate technical risk as clear business value.
Job Requirements
- Proven enterprise vulnerability engineer - Command direct operational execution configuring, deploying, and maintaining industry-leading vulnerability discovery platforms, explicitly leveraging Tenable/Nessus, Qualys, Rapid7 InsightVM, or Vanta.
- Surgical risk prioritizer - Mastered advanced risk scoring architectures including CVSS base scores and EPSS real-time exploit probability indices to isolate, rank, and target high-consequence threats.
- Precision threat analyst - Deconstructed massive raw scanning datasets, systematically validated results to eliminate false positives, and converted intricate technical threat data into clear business risk metrics.
- Advanced infrastructure posture auditor - Diagnosed, categorized, and cataloged diverse vulnerability classes, cloud/container exposure vectors, active exploit mechanisms, and configuration weaknesses across distributed system architectures.
- GRC architecture strategist - Aligned automated infrastructure scanning protocols directly against regulatory compliance frameworks, specifically matching continuous monitoring records to strict audit evidence controls for SOC 2, ISO 27001, HIPAA, and CMMC.
- High-velocity technical consultant - Engineered clear technical blueprints, structured project milestones, and progress matrices while simultaneously orchestrating deliverables across an active portfolio of client accounts.
- Elite stakeholder diplomat - Built immediate trust and drove technical risk calibrations directly with US-based tech founders, engineering executives, and corporate leaders using clear, business-friendly communication.
- Orchestration of patch management pipelines - Proven history managing full-lifecycle patch deployments, technical change management workflows, and remediation sequences alongside distributed IT, DevOps, and software engineering teams within a managed service provider (MSP/MSSP) or consulting environment.
- Credentialed cybersecurity specialist - Hold active, validated professional industry markers such as CompTIA Security+, CEH, Tenable Certified Security Associate, or GIAC GEVA.
- Cloud-native security engineering - Direct exposure mapping, configuring, and defending cloud-native vulnerability surfaces across public multi-cloud public hosting platforms, explicitly AWS, GCP, and Azure environments.
- Command of threat intelligence syndication - Advanced navigation of the CVE lifecycle, National Vulnerability Database (NVD) registries, and active threat feed integrations to intercept and anticipate real-world exploits.
Benefits
- Career Development: Clear path with mentorship and training opportunities
- Technical Training: Comprehensive onboarding on security and compliance frameworks
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
Related Guides
Related Categories
Related Job Pages
More Engineer Jobs
Full Stack Engineer
HueHue is a fast-growing, venture-backed B2B SaaS company transforming how people shop online by making representation real. Our technology embeds authentic, shoppable video reviews from a diverse community of 2,000+ micro-creators directly into brands’ DTC websites—helping shoppers see products on people who actually look like them. Founded in 2021, Hue serves 100+ leading brands and retailers, including Foot Locker, Tatcha, REVOLVE, Andie Swim, Credo Beauty, and more. We’ve raised $4M+ in venture funding from Fika Ventures, Underscore VC, Sequoia Scouts, and others, and were named one of Business Insider’s “43 Startups to Bet Your Career On in 2025.” Hue was founded by Janvi Shah (ex-Google PM), Nicole Clay (ex-L’Oréal Marketing Director), and Sylvan Guo (ex-Airbnb, Tubi/Fox), who personally experienced the frustration of shopping online without representation—and set out to fix it.
Role Description You'll be one of our first engineering hires - as a small, fast-moving engineering team, we need someone who can hit the ground running and take real ownership. This isn't a maintenance job on a mature codebase; it's building at the edge of genuinely unsolved problems. Your work will go live in front of enterprise clients and millions of shoppers within days, not quarters. - Work on a mix of new product features, client integrations, and production support. - Set up client implementations, troubleshoot issues in production, and communicate directly with enterprise brands. - Build AI-powered capabilities such as dynamic video ranking, AI product tagging, and AEO (AI Engine Optimization). Technical Reality - Core product is a JavaScript widget that loads on millions of product pages across enterprise DTC storefronts. - Focus on performance, reliability, and pixel-perfect rendering across different client environments. - Write JavaScript embeds, connect to shopping cart APIs, match CSS to brand style guides, and debug across browsers. - Fix production issues and explain them to non-technical clients. - Codebase is human-architected and actively maintained with tests and code reviews. - Engineers own their work end-to-end: build, merge, deploy, and support in production. What You’ll Do - Build and ship new features across the full stack: frontend interfaces, backend services, AI-powered product capabilities. - Own client integrations end-to-end: setup, CSS customization, shopping cart connections, and ongoing support. - Troubleshoot production issues quickly and communicate clearly with enterprise clients. - Collaborate directly with the founding team to turn customer feedback into product decisions. - Participate in code reviews and help set engineering standards as the team grows. - Bring a product eye and the ability to spot opportunities to improve the experience. Qualifications - 2 to 4 years of professional full-stack experience, with a track record of shipping production software. - Strong React and TypeScript skills; experience building customer-facing frontend systems. - Solid JavaScript and CSS fundamentals; ability to make designs pixel-perfect. - Backend experience with Node.js and comfort working with databases (PostgreSQL preferred). - Clear written and verbal communication skills. - CS degree or equivalent practical experience. - Authorized to work in the U.S. without visa sponsorship. Nice-to-Haves - Experience at an early-stage startup (pre-Series A is a big plus). - AWS experience with setup, deployment, or infrastructure. - Familiarity with e-commerce platforms like Shopify or Salesforce Commerce Cloud. - Exposure to data engineering, ML/AI systems, or video platforms. - Experience working in or alongside customer success and implementation roles. Compensation & Location - This is a fully remote role open to candidates based in the United States. - Base salary range: $150,000 to $160,000, depending on experience and qualifications. - Final compensation will be determined based on skills, experience, and interview performance. - Includes equity and a full benefits package. Our Commitment to Inclusion Hue is an equal opportunity employer. As a company founded by three women of color, inclusivity isn't a value we added later, it's why we exist. We welcome candidates of all backgrounds, identities, and lived experiences and are committed to building a workplace where everyone feels supported, valued, and empowered to do their best work.
PKI Engineer – Certificate Management Specialist
Makpar CorporationMakpar is an experienced solutions-oriented contractor focused on modernizing IT infrastructure. Minority + Woman Owned.
• Support Federal PKI and DHS PKI policy-aligned implementation. • Manage certificate lifecycle processes, including issuance, rekey, modification, revocation, and reissuance. • Support device certificate request processing through digital workflows. • Support DHS CA4 and external CA processes according to agency guidelines. • Support Non-Person Entity certificate authority for workstations and mobile/Apple devices. • Support person-centric PKI certificate authority and certificate lifecycle management systems. • Automate certificate management processes to reduce manual error and approval delays. • Support modernization of PIV-based PKI certificate AuthN/AuthZ in USCIS applications. • Research, design, and implement PKI/cloud/certificate solutions using COTS, open-source, and cloud-native tools. • Create SOPs, how-to videos, KB articles, process documentation, presentations, and release documentation. • Provide recommendations for optimizing cloud resource performance and security.
PAM Engineer – CyberArk Specialist
Makpar CorporationMakpar is an experienced solutions-oriented contractor focused on modernizing IT infrastructure. Minority + Woman Owned.
• Support USCIS privileged access management modernization • CyberArk/vaulting • Secrets management • Privileged session controls • Least privilege • Zero Trust • Just-in-time access • Privileged account discovery • Privileged access governance across cloud, hybrid, and on-prem environments
• Helps to develop resolutions to complex problems that require the frequent use of creativity and innovation. • Utilizes engineering input from across the NuScale organization in the development of reactor servicing tools, inspection equipment, and control systems. • Prepares, checks, and reviews engineering reports, system descriptions and specifications, drawings, calculations, and other design documents. • Works on complex tasks in multiple and diverse areas. • Work collaboratively with the NSSS Component design organization. • Works collaboratively with the Civil/Structural team. • Works closely with Systems Engineering and the Operations group. • Assists in the planning and organization of complex engineering work. • Performs innovative and complex engineering assignments on a team dedicated to the development of an engineered product.



