Why This Role Stands Out
This hybrid role offers a fantastic opportunity to deepen your expertise in cloud security and DevSecOps within a reputable consulting firm, managing the full vulnerability lifecycle across Azure and AWS. You'll thrive here if you're a proactive mid-senior engineer eager to collaborate with diverse technical teams and drive impactful security initiatives. Apply today to advance your career in cutting-edge cloud environments.
Quick Overview
Job Description
Job Description – Cloud Vulnerability Management Engineer
Technology Focus: Hybrid Cloud / Azure / AWS / Apache Spark
Role Focus: Cloud Vulnerability Management / DevSecOps / Cloud Security
Day to Day Job Duties:
(What this person will do on a daily/weekly basis)
- Manage the end-to-end vulnerability management lifecycle for enterprise applications and infrastructure hosted across hybrid cloud, Microsoft Azure, and AWS environments.
- Analyze vulnerability scan results and identify security vulnerabilities affecting cloud infrastructure, operating systems, containers, application dependencies, open-source libraries, and cloud-hosted data platforms.
- Perform vulnerability assessment and prioritization based on CVE/CVSS severity, exploitability, application criticality, external exposure, and overall business risk.
- Work closely with Application Development, Cloud Engineering, DevOps, SRE, Infrastructure, and Cybersecurity teams to define and execute vulnerability remediation plans.
- Support identification and remediation of vulnerabilities across AWS and Azure cloud services, Linux/Windows servers, Kubernetes, containers, Docker images, Java applications, and open-source components.
- Support vulnerability management for Apache Spark-based applications and data-processing platforms, including Spark runtime versions, Java/JVM dependencies, libraries, packages, and associated cloud infrastructure.
- Work with engineering teams to troubleshoot the technical root cause of vulnerabilities and recommend appropriate remediation, including patching, dependency upgrades, configuration changes, infrastructure changes, or compensating controls.
- Validate successful remediation through rescanning, technical verification, and security evidence collection.
- Track Critical and High vulnerabilities against established remediation SLAs and proactively escalate overdue vulnerabilities, blockers, and risks.
- Identify recurring vulnerability patterns and recommend systemic solutions and preventive controls to reduce repeat findings.
- Integrate vulnerability and security scanning into CI/CD and DevSecOps pipelines, enabling earlier identification of vulnerabilities during the software development lifecycle.
- Support cloud security posture assessments and remediation of configuration weaknesses across Azure, AWS, and hybrid-cloud environments.
- Develop scripts and automation to improve vulnerability identification, remediation tracking, validation, reporting, and compliance evidence collection.
- Create dashboards and reports covering open vulnerabilities, remediation aging, SLA compliance, risk acceptance, remediation trends, and vulnerability reduction.
- Participate in vulnerability governance and operational review meetings and communicate technical risks, remediation status, dependencies, and blockers to engineering and management stakeholders.
Basic Qualifications:
(What are the skills required for this job with minimum years of experience on each)
- Minimum 7+ years of experience in IT engineering, Cloud Engineering, DevOps/SRE, Cybersecurity, Application Security, or Vulnerability Management within enterprise environments.
- Minimum 4+ years of hands-on experience in Vulnerability Management / Application Security / Cloud Security, including vulnerability analysis, prioritization, remediation, and validation.
- Minimum 4+ years of experience working with public cloud technologies, with strong hands-on knowledge of AWS and/or Microsoft Azure.
- Minimum 2+ years of experience supporting hybrid-cloud or multi-cloud environments, preferably involving application migration or transformation between Azure and AWS.
- Minimum 3+ years of experience using enterprise vulnerability/security platforms such as Qualys, Tenable, Rapid7, Wiz, Prisma Cloud, Microsoft Defender for Cloud, AWS Inspector, or comparable tools.
- Minimum 3+ years of experience analyzing and remediating CVE/CVSS-based vulnerabilities, including operating-system vulnerabilities, application dependencies, open-source libraries, containers, and cloud infrastructure.
- Minimum 2+ years of experience supporting security or vulnerability management for Apache Spark, Databricks, EMR, Hadoop, or similar large-scale data-processing platforms.
- Minimum 2+ years of experience working with Java/JVM applications and open-source dependency vulnerability remediation, including upgrading vulnerable libraries and packages.
- Minimum 2+ years of experience working with containers and container orchestration technologies such as Docker and Kubernetes, including container/image vulnerability management.
- Minimum 2+ years of experience with CI/CD and DevSecOps technologies such as GitLab CI, GitHub Actions, Jenkins, Azure DevOps, or comparable platforms.
- Minimum 2+ years of experience integrating or working with security controls such as SAST, DAST, Software Composition Analysis (SCA), container scanning, secrets scanning, and Infrastructure-as-Code scanning.
- Minimum 2+ years of experience with scripting or automation using Python, Bash, PowerShell, or equivalent technologies.
- Strong understanding of AWS and Azure security concepts, including IAM/access controls, cloud configuration, network security, logging/monitoring, and cloud security posture management.
- Strong knowledge of vulnerability-management concepts including CVE, CVSS, risk-based prioritization, patch management, vulnerability SLAs, remediation validation, security exceptions, and risk acceptance.
- Strong analytical, troubleshooting, and communication skills with the ability to translate security findings into actionable technical remediation for engineering teams.
Similar jobs
- PT
Cloud Architect with Enterprise Security focus
NewPeakLnk Technologies, Inc.
Wilmington, MA🇺🇸HybridYesterdayShellAWSLoad Balancing+9Technology - PG
Cloud Engineer
NewPTR Global
Plano, TX🇺🇸$65 - $70/hrHybridYesterdayMicroservicesSQLScala+9Technology - EN
Secure Network Engineer with Security Clearance
NewEntarian
Boulder, CO🇺🇸$150k/yrHybridYesterdayTechnology - VI
ONLY W2 CLOUD ENGINEER WITH AZURE AND VULNERABILITY
NewVirisha LLC
United States🇺🇸RemoteYesterdayAWSAnsibleAzure+12Technology - TI
Sr Lead Systems Cloud Engineer-1
NewTIAA
Raleigh, NC🇺🇸$58 - $85/hrOn-siteYesterdayShellAWSSAML+8Technology - ST
Virtualization Engineer
NewStefanini
Dearborn, MI🇺🇸On-siteYesterdayEngineering