CyberSecurity as a Solution: Enabling Secure Business.
Vulnerability Management Engineer
Location
United States
Posted
2 days ago
Salary
0
Seniority
Senior
Job Description
Vulnerability Management Engineer
Dragonfli Group
• Lead and manage end-to-end vulnerability disclosure programs (VDP), including coordination with ethical hackers, system owners, and agency stakeholders. • Own attack surface management programs (e.g., CISA FAST), including scheduling, scope management, findings coordination, and POA&M documentation. • Manage and update Standard Operating Procedures (SOPs), SharePoint repositories, and program tracking documentation. • Lead recurring stakeholder syncs (weekly vulnerability management meetings, DMZ syncs, Security Report presentations). • Operate and maintain enterprise vulnerability scanning platforms including Tenable.sc, Tenable.io, and web application scanning tools (OpenText ScanCentral or equivalent). • Scope, schedule, execute, and report on vulnerability scans across large, complex federal environments. • Analyze scan results to identify critical and high-severity findings; triage false positives; prioritize remediation activities. • Manage hardware/software certification pipelines; process ServiceNow tickets within defined SLAs. • Support transition from legacy tools to modernized scanning platforms with minimal operational disruption. • Track and drive remediation of critical, high, and all severity-tiered vulnerabilities to closure within program SLAs. • Maintain accurate POA&M records for all open findings across program scope. • Produce and present vulnerability dashboards, compliance reports, and executive-level status briefings. • Validate remediation effectiveness through post-remediation scanning and analysis. • Monitor HTTPS/HSTS compliance and other BOD requirements (BOD 18-01, BOD 20-01, and others as applicable). • Build and maintain working relationships with CISA contacts, agency system owners, SOC personnel, and contractor teams. • Communicate vulnerability risks and remediation recommendations clearly to both technical and non-technical audiences. • Serve as subject matter expert and primary point of contact for assigned programs. • Provide backfill coverage across vulnerability management workstreams as needed.
Job Requirements
- 3+ years of hands-on vulnerability management experience.
- Demonstrated program ownership: VDP, attack surface management, or equivalent independently managed programs.
- Proficiency with Tenable.sc and/or Tenable.io (scan configuration, report generation, false positive management).
- Experience with CISA programs (VDP, FAST, BOD compliance) or equivalent federal cybersecurity initiatives.
- Working knowledge of ServiceNow or equivalent ITSM platforms for ticket management.
- Ability to produce clean, accurate SOPs, POA&Ms, and stakeholder-facing documentation.
- Active security clearance or eligibility to obtain one preferred.
- 3+ years of hands-on vulnerability management experience within a federal agency environment preferred.
- Experience operating WebInspect, OpenText ScanCentral, or equivalent DAST/web application scanning tools.
- Familiarity with Bugcrowd or other managed bug bounty platforms.
- Experience with HSTS/HTTPS compliance monitoring aligned to BOD 18-01.
- Active certifications: Security+, CEH, CISSP, CISM, or Certified Vulnerability Assessor (CVA).
- Experience leading or co-leading standing meetings with federal stakeholders.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent practical experience.
Benefits
- Health, Dental, and Vision Insurance
- PTO
- 401(k)
- Remote work flexibility
- Exposure to high-impact federal cybersecurity programs
- Direct access to firm leadership and career development opportunities
Related Guides
Related Categories
Related Job Pages
More Engineer Jobs
Senior Identity & Access Management Engineer - Moveworks
ServiceNowAs the AI platform for business transformation, we're putting AI to work across organizations — freeing people for work that matters. Making old tech work with new tech. Reaching across departments, from the front office to the back office and every office in between. Our ambition? To become the AI defining enterprise software company of the 21st century (or "AI DESCO21C," as we like to call it). With more than 8,400+ customers, we serve approximately 90% of the Fortune 500®, and we're proud to be a Fortune 100 Best Companies to Work For® and World's Most Admired Companies™. Explore your future career with us, visit www.careers.servicenow.com From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
Company Description Who we are Moveworks is the Agentic AI Assistant platform that empowers the entire workforce. Our platform enables employees to converse with all of their business systems through natural language to quickly find answers and automate tasks. Powered by the world's most advanced LLMs, our proprietary models, and a sophisticated Agentic AI platform, we're transforming how work gets done by allowing AI to take initiative, streamline complex workflows, and continuously learn and adapt. Moveworks is trusted by over 5.5 million employees at more than 350 of the world’s largest companies, including 10% of the Fortune 500, to automate everyday tasks and streamline business operations. Recognized on the Forbes Cloud 100 and AI 50 lists, Moveworks was also named one of Fast Company’s 2025 Most Innovative Companies and Inc’s Best in Business, in the Best in Innovation category. Moveworks was also recognized at Microsoft’s 2025 Partner of the Year and in 2024, received the AI Breakthrough Award. In December 2025, Moveworks was acquired by ServiceNow, marking a pivotal milestone in our journey to create a single front door to work for all business systems. By combining ServiceNow’s leading workflow automation with Moveworks’ Reasoning Engine and natural language capabilities, we deliver the AI platform for every person and every workflow. Built to go beyond basic summaries to deliver meaningful business impact. Together, our AI acts across enterprise systems to turn conversations into completed work. By joining our team, you’ll be at the forefront of the AI transformation, backed by the global scale of ServiceNow and the agility of a high-growth company. We are looking for world-class talent to help us extend agentic AI to every employee across every corner of the business. Come join us! ServiceNow It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone. Job Description The Role Do you care deeply about secure access at scale? Making sure the right people have the right access, exactly when they need it, without slowing teams down? Join Moveworks and help shape the future of our identity and access strategy. At Moveworks, we believe great security is an enabler, not a blocker. As a Senior Identity & Access Management Engineer, you’ll be a hands-on technical developer, coding, designing, building, and scaling IAM solutions across cloud infrastructure, SaaS applications, and internal systems. You’ll own the development of IAM initiatives end-to-end, from untangling ambiguous access challenges to architecting secure, automated solutions and driving them into production. In this role, you’ll develop robust access models across AWS, Azure, Kubernetes, and beyond; reduce privilege sprawl through thoughtful role design; and build strong observability through logging, metrics, and reporting in our SIEM. You’ll modernize access reviews to deliver real security impact with minimal friction, continuously de-risk IAM threats, and partner closely with teams to drive adoption of secure-by-default patterns. Your work will directly protect Moveworks’ most critical systems while enabling our engineers to move fast, safely, and confidently. What you get to do in this role: - Be the technical developer to drive IAM application development: Code, design, and implement solutions with extensive knowledge in AWS, Azure, Teleport, and Terraform. Enabling robust and reliable solutions to keep our engineering teams active. - Drive IAM projects end-to-end: Take ambiguous access problems, understand and have the ability to define requirements, architect solutions, and own the rollout/operationalization (not just the design). - Develop with secure access models in mind: Continuously develop role design improvements and access assignment patterns across AWS, Kubernetes, SaaS apps, and internal systems to reduce unnecessary privileges, minimize manual grants, and create scalable “safe baseline” access that covers routine work without daily elevation. - Develop on operationalizing logging and metrics: Ensure access changes are observable in our Security Information and Event Management (SIEM) tool; build repeatable reporting that surfaces risky access and drift. - Run and improve user access reviews (UAR): Develop, execute and design a UAR process & solution that meets compliance requirements while improving real security signal—minimizing approver burden through scoping, automation, and clear decision support. - Develop technology to continuously de-risk: Identify high-risk permissions and misuse paths, propose appropriate controls and mitigations, drive adoption with partner teams, and develop solutions to continuously de-risk. - Operate with strong security judgment and high signal: Reliably distinguish meaningful IAM risk from noise, gather context efficiently, and escalate with crisp rationale and actionable mitigations. - Document and standardize the paved road: Write lightweight procedures, runbooks, and automation so access decisions are consistent, scalable, and not dependent on tribal knowledge. Qualifications To be successful in this role you have: - US Citizenship preferred (Some responsibilities in this role involve working with U.S. government customer environments subject to regulatory access requirements. Eligibility may be contingent on the ability to satisfy applicable export control or government contract obligations.) - Experience: 5+ years of experience working in IAM, security engineering, or platform engineering with substantial IAM responsibilities in production environments. - IAM Expertise: Strong grasp of IAM best practices and common failure modes (e.g., least privilege, privilege escalation paths, separation of duties, breakglass, auditability). - Cloud Infrastructure IAM: Practical experience implementing and designing access control in AWS, Azure, GCP environments and partnering with teams who manage infrastructure at scale. Experience configuring IAM in Teleport, Terraform and Kubernetes environments is a plus. - SSO Experience: Experience with Okta administration and patterns (e.g., groups, app assignments, lifecycle/provisioning), or equivalent experience with a similar SSO product. - Threat-aware thinking: Ability to spot dangerous permissions and misuse paths (including insider-threat scenarios), assess risk, and identify suitable mitigations and controls. - Automation-first mindset: Comfortable using scripting languages and AI coding tools to build reliable automation, and able to read/validate what the code is doing. - Protocol fluency: Working understanding of OAuth, OIDC, SAML, and SCIM, including when to use which, failure modes, and common pitfalls. - Collaboration: Proven ability to build long-lasting relationships with various technical teams, such as Engineering, Information Technology, Infrastructure, and DevOps teams. - Educational Background: BS+ in computer science or a related field, or equivalent relevant experience. Additional Information Work Personas We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service. Equal Opportunity Employer ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. Accommodations We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance. Export Control Regulations For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license.
Role Description As a Ferric Design Engineer, you contribute to building the most advanced cutting edge integrated voltage regulators, leveraging Ferric’s industry-leading on-chip inductor technology. These products have applications ranging from high-power modern SoCs to ultra-low power Mobile platforms including wearable devices. - Design analog and mixed-signal circuits meeting architectural requirements and technical specifications in various CMOS nodes. - Actively contribute to the architectural definition of the design and chip integration and work with business and application team to define specifications for upcoming IC's. - Research and investigate new circuit techniques to help improve Ferric IC's. - Perform analysis, design and verification simulations to ensure building blocks meet specifications at the schematic level and after post-layout extraction. - Document assigned blocks, and hold design review meetings and participate in the reviews. - Work cross-functionally with Characterization, Test, and Application Engineers to verify, characterize and debug owned circuit blocks. Qualifications - PhD or MSEE with 2+ years of experience in full-custom CMOS design. - Design skills in areas such as bandgaps, ADC's/DAC's, PLL's, DLL's, LDO's, temperature sensors, switched-capacitor circuits, op-amps, comparators, and biasing circuits. - CAD Software: Cadence Virtuoso Schematic and Layout, Spectre, APS, Calibre DRC/LVS/PEX, CppSim. Requirements - Experience designing high switching frequency integrated voltage regulators in standard CMOS technologies. - Experience designing analog and mixed-signal circuits in standard CMOS technologies with an emphasis on low-power consumption. - Proven track record for bringing mixed-signal designs into high volume production. - Deep understanding of process and device physics concepts. - Familiarity with mixed signal verification methodologies. - Ability to layout critical analog and mixed-signal circuits. - Experience with backend verification tools including EMIR, static/dynamic MOSFET voltage checks, etc. - Experience with Monte Carlo analysis. - Languages: Verilog, Verilog-AMS, Python, Perl, Tcl, Cadence Skill, MATLAB. Desired Characteristics & Attributes - Passionate, self-starter with strong commitment to flawless execution. - Excellent written and verbal communication skills required. - Ability to work well with others in a fast-paced collaborative team environment. Logistics - Remote or in NYC office. - Annual salary range for this position 115k-170k.
Port Engineer
Stabbert Marine & IndustrialTo provide vessels, management and support services at a level of excellence beyond the expectations of our customers.
• The Port Engineer is responsible for effectively meeting the technical goals of the company. • Ensuring the vessels are technically fit to operate, preventative maintenance is attended to, critical spares are maintained and operational, and downtime is minimized. • Develop, manage, and execute preventive and corrective maintenance schedules. • Coordinate with shipyard, contractors, and vendors for repairs and dry-docking. • Troubleshoot and resolve technical issues related to mechanical, electrical, and hydraulic systems. • Ensure vessels are in optimal condition to meet operational schedules and mission requirements. • Conduct routine inspections to verify that vessels meet company and client standards. • Develop and manage annual budgets for vessel maintenance and repairs. • Monitor and control Technical operation costs, ensuring cost-effective solutions. • Maintain accurate records of spare parts and equipment inventory. • Manage class inspections, surveys, and certifications to maintain compliance. • Keep up to date with regulatory changes impacting vessel operations. • Manage relationships with shipyards, repair facilities, and parts suppliers. • Review and approve contractor scopes of work, bids, and invoices. • Coordinate logistics for on-site contractors during maintenance or repair projects. • Collaborate with vessel chief engineers to plan and conduct crew training on technical systems and safety protocols. • Liaise with the HR department to ensure technical crew members are qualified and certified according to industry standards.
• This job sits at the intersection of product, engineering, and revenue. • You won't just work closely with the engineering team, you will be on the engineering team. • The range of problem solving includes networking, performance, security and integrations with existing systems. • Most of the code you will write will be open source. • Our products are loved by their users, you'll get to meet them regularly.



