We are a financial services enterprise creating useful and intuitive solutions and products for everyone.
Senior Vulnerability Management Engineer
Location
United States
Posted
13 days ago
Salary
$190K - $230K / year
Seniority
Senior
Job Description
Senior Vulnerability Management Engineer
Group 1001
• Own the end-to-end vulnerability management pipeline: asset discovery > scanning > enrichment > prioritization > assignment > verification > closure. • Build, codify, and iterate a data-driven prioritization framework (blending CVSS, EPSS, KEV, exploit availability, asset criticality, exposure/reachability, compensating controls, and business context). • Automate the full workflow via SOAR playbooks, webhooks, REST/GraphQL APIs, message queues, and custom scripts where needed. • Develop and improve KPIs, metrics, and trending for vulnerability management functions, and bring leadership attention to root-cause issues driving systemic vulnerability risk. • Integrate scanners, CMDB/asset inventory, EDR, cloud providers (AWS/Azure/GCP), and others into a single pipeline for management. • Continuously reduce noise: dedupe, suppress known-benign, correlate related findings, and auto-close on evidence of remediation. • Evaluate and integrate AI/LLM tooling for triage, false-positive suppression, remediation guidance, and vulnerability research — with appropriate guardrails. • Lead technical response for emergency patch cycles on various technical platforms.
Job Requirements
- Bachelor's degree in Computer Science, Information Security, or related academic field or equivalent experience.
- 5-7 years of professional experience in information security, with focus on the financial sector.
- Hands-on experience deploying, configuring, and managing vulnerability scanning solutions at enterprise scale, including policy design, tuning for noise reduction, and managing performance impact (e.g. Tenable, Microsoft Defender, Wiz, Tanium)
- Hands-on experience engineering, integrating, and optimizing for automation of security platforms (e.g. Swimlane, Elastic).
- Strong knowledge of public cloud platforms (e.g., AWS, Azure, GCP) from an infrastructure and development aspect and their related security features.
- Familiarity with DevSecOps practices and CI/CD pipelines.
- Understanding of industry security frameworks, standards, and best practices (e.g., NIST, ISO, CIS).
- Proficiency in one or more software programming languages (e.g. Python, Golang, JavaScript), particularly for automation of security platform operations, health monitoring, and integration tasks.
- Strong communication and collaboration skills, with the ability to work closely with engineering, operations and infrastructure teams.
- Familiarity with compliance standards and regulations.
- Creativity and critical thinking with the ability to work both independently and collaboratively in a fast-paced environment.
- Be able to serve as a mentor or subject matter expert to other members within the organization, particularly in the areas of vulnerability management and systems engineering.
Benefits
- Employees (and their families) are eligible to participate in the Company’s comprehensive health, dental, and vision insurance plan options.
- Employees are also eligible for Basic and Supplemental Life Insurance, Short and Long-Term Disability.
- All employees (regardless of hours worked) have immediate access to the Company’s Employee Assistance Program and wellness programs—no enrollment is required.
- Employees may also participate in the Company’s 401K plan, with matching contributions by the Company.
Related Guides
Related Job Pages
More Full-stack Engineer Jobs
Senior Software Engineer – Mobile
FlashA plataforma que simplifica sua gestão: da admissão ao controle de benefícios e despesas.
• Work on the development and evolution of the mobile application, focusing on React Native and Expo. • Build, maintain and enhance mobile features with quality, performance, stability and a strong user experience. • Work on integrations with the app's native parts on Android and iOS, supporting debugging, maintenance and evolution of platform-specific modules when necessary. • Investigate production issues using telemetry and observability tools such as Sentry and Grafana, analyzing errors, logs, metrics and app behavior. • Collaborate with Product, Design, QA and other Engineering teams to turn business needs into simple, robust and sustainable mobile solutions. • Contribute to technical decisions, code reviews, continuous improvement of the mobile codebase and mentoring developers on the team.
• Foster a collaborative, inclusive engineering culture that values diverse perspectives and continuous learning • Provide coaching and mentorship to managers and senior engineers, strengthening leadership depth and team effectiveness • Support organizational priorities through thoughtful talent planning, development, and retention strategies • Partner with leadership to reinforce a culture of accountability, transparency, and engagement • Translate enterprise and product strategy into clear engineering priorities, roadmaps, and deliverables • Partner closely with Product and Architecture to deliver scalable, customer-centric solutions • Drive adoption of modern engineering practices and technologies to improve speed, quality, and reliability • Establish and maintain engineering standards, processes, and metrics to drive consistent, high-quality delivery • Optimize team performance through data-driven insights, continuous improvement, and effective resource allocation • Promote cross-functional collaboration to ensure seamless execution across Technology, Product, and business partners • Support operational rigor across global teams, ensuring effective delivery across time zones
• Administer and optimize the full Tenable platform, including: - Tenable.sc - Tenable Vulnerability Management (formerly Tenable.io) - Nessus - Nessus Agents • Perform authenticated and unauthenticated vulnerability scans across Windows, Linux, network, and cloud environments. • Analyze vulnerability data, validate findings, eliminate false positives, and prioritize remediation efforts based on risk. • Coordinate remediation activities with infrastructure, networking, and application teams through closure. • Manage scan schedules, repositories, credentials, scan zones, and agent deployments. • Troubleshoot scanning issues, credential failures, performance bottlenecks, and platform health. • Develop executive dashboards, compliance reports, and security metrics. • Support RMF continuous monitoring, POA&M management, and audit activities. • Integrate Tenable with ServiceNow, SIEM, asset management, and automation platforms. • Develop automation using PowerShell, Python, Bash, and Tenable APIs. • Recommend system hardening improvements and security best practices. • Provide technical mentorship to junior engineers and vulnerability analysts. • Support security investigations and incident response activities requiring vulnerability analysis.
• Design and implementation of applications, data integrations, and technology solutions • Development oversight and standards adherence • Provide technical guidance and mentoring to Developers, Sr. Developers, and Technical Leads • Create Design & Technical Specs from Business requirement specifications • Lead and participate in code reviews • Collaborate with various teams to ensure delivery of projects




