Haystack
← Back to Jobs
Remote
Engineering

Vulnerability Management Engineer || Remote || 14 weeks || Video

Stellent IT LLCUnited States🇺🇸United StatesPosted 28 Jul 2026

Quick Overview

Work Type
Remote
Level
Mid Senior

Job Description

Title: Vulnerability Management Engineer
Start: ASAP

Location: Remote

Duration: 14 Weeks (possible CTH)

MOI: Video

Requirements:

Detailed job description / scope

Contract Vulnerability Management Engineer to stand up a mature, sustainable vulnerability management program across Alliant's large and continuously changing asset estate. Over a 12 16 week engagement the resource will: (1) reconcile an authoritative asset inventory across Tenable, CrowdStrike, identity/endpoint sources, and the ServiceNow CMDB, with coverage-gap identification; (2) baseline current-state vulnerability posture, enriched with exploit intelligence (CVSS, EPSS, CISA KEV, validated-exploitable); (3) build a ServiceNow Vulnerability Response remediation workflow with risk-based prioritization and SLAs, and drive initial remediation waves; and (4) author runbooks and operate the program in steady state. This is a build-and-operate role - the ServiceNow Vulnerability Response workflow is the core deliverable.

Day-to-day responsibilities

  • Reconcile asset data across Tenable, CrowdStrike, Okta / Active Directory / Intune, and the ServiceNow CMDB; identify scanner and agent coverage gaps.
  • Aggregate and de-duplicate vulnerability findings; baseline posture; enrich with CVSS, EPSS, CISA KEV, and NodeZero validated-exploitable status; produce a risk-ranked register.
  • Build and configure the ServiceNow remediation workflow (intake prioritize assign track verify/re-scan close); define SLAs; stand up the exception / risk-acceptance process.
  • Drive initial remediation waves on highest-risk exposures in partnership with asset owners; report program metrics.
  • Author operational runbooks and operate the program in steady state; provide weekly status.
  • Apply frontier AI models (ChatGPT Enterprise, Claude) to accelerate de-duplication and analysis, prioritization, reporting, and workflow design.

Criteria, expectations, must-haves, nice-to-haves

Must-haves

  • Hands-on experience operating enterprise vulnerability tooling - Tenable and CrowdStrike (Falcon Spotlight / Exposure Management) at minimum.
  • Risk-based prioritization using CVSS, EPSS, and CISA KEV; validated-exploitability a plus.
  • ServiceNow Vulnerability Response / SecOps workflow build. Non-negotiable; this is the engagement's core (capital) deliverable.
  • Remediation orchestration across infrastructure and application owners; SLA design; metrics and executive-ready reporting.
  • Proficiency with AI frontier models (e.g., ChatGPT Enterprise, Claude) applied to security-engineering work, with an understanding of secure, governed AI use in an enterprise setting.

Nice-to-haves

  • NodeZero or other autonomous-pentest familiarity; patch and change-management integration; CMDB reconciliation.
  • Insurance, financial-services, or other regulated-industry experience.

Expectations: Self-directed build-and-operate; comfortable driving remediation through other teams and holding SLAs.

Environmental details (work setting, culture, tools)

Fully remote. Collaborative, fast-paced IT Security engineering team operating in a SAFe Agile model. ServiceNow is used for ITSM and SecOps; Zoom for collaboration. The culture is AI-forward, with frontier models actively used across security workflows. A heavy M&A cadence means the environment changes constantly.

Technology they will be supporting

Tenable; CrowdStrike (Falcon Spotlight / Exposure Management, NG-SIEM); NodeZero; Okta, Active Directory, Intune / MDM; ServiceNow (Vulnerability Response, SecOps, CMDB); ChatGPT Enterprise and Claude.

Projects the resource will be involved in upon start

The Vulnerability Management project: asset and coverage inventory, current-state vulnerability assessment, the ServiceNow Vulnerability Response remediation workflow build with SLAs and initial remediation, and operational runbooks with steady-state operation.

Must-have certifications or skills (if not already covered above): ServiceNow Vulnerability Response / SecOps build proficiency and AI frontier model proficiency (ChatGPT Enterprise / Claude) are required. Relevant security certifications are preferred but not required where hands-on experience is strong - for example, CISSP, GIAC, or vendor certifications for Tenable or CrowdStrike.

Senior Talent Acquisition

E-

STELLENT IT A Nationally Recognized Minority Certified Enterprise

Skills

Agile
SAFe

Similar jobs