Quick Overview
Job Description
***We are unable to sponsor for this 4+ month contract role, possible CTH, no 3rd party candidates will be considered***
Prestigious Enterprise Company is currently seeking a Cyber Vulnerability Management Engineer with strong CVEs experience. Candidate will provide hands-on support for the Secure Technology Solutions Sustainability service by augmenting the existing vulnerability management team in executing core vulnerability management operations. This is a senior-level technical role requiring strong vulnerability analysis, infrastructure knowledge, sound technical judgment, and the ability to work effectively with both engineering teams and technology leadership. This role will primarily support vulnerabilities affecting enterprise infrastructure, middleware, platforms, and DevOps technologies.
Responsibilities:
Vulnerability Investigation & Validation
- Investigate and validate vulnerabilities identified through enterprise vulnerability scanning and aggregation platforms, including Rapid7 InsightVM/Nexpose, Qualys, and Nucleus.
- Perform technical analysis beyond scanner output to determine whether vulnerabilities are valid, applicable, exploitable, or otherwise relevant within the context of the affected environment.
- Research CVEs, vendor advisories, security bulletins, affected versions, patches, mitigations, exploitability, and other technical information necessary to accurately assess vulnerability risk.
- Analyze affected infrastructure, middleware, operating systems, network technologies, platforms, and DevOps technologies to understand vulnerability applicability and appropriate remediation.
- Identify potential false positives, configuration issues, version discrepancies, or other conditions requiring additional investigation.
- Work directly with technical teams to gather evidence, validate findings, troubleshoot discrepancies, and determine appropriate remediation or mitigation approaches.
Vulnerability Management Operations
- Execute established vulnerability management processes and runbooks consistently and independently.
- Provide backup support for day-to-day and on-call vulnerability management activities, including investigation and coordination of newly identified or time-sensitive vulnerabilities.
- Triage vulnerability findings and determine appropriate actions based on severity, exposure, exploitability, affected technology, and established enterprise requirements.
- Create and distribute vulnerability advisories that clearly communicate affected technologies, risk, required actions, remediation guidance, and timelines.
- Create, route, track, and follow up on remediation tickets with responsible technology teams.
- Monitor outstanding vulnerability work and proactively engage stakeholders to drive remediation to completion.
- Support both newly identified vulnerabilities and existing vulnerability backlog as needed.
- Maintain accurate records and documentation throughout the vulnerability lifecycle.
Risk Acceptance
- Facilitate established vulnerability risk acceptance processes for findings that cannot be remediated within required timelines.
- Work with technical teams to understand remediation constraints, compensating controls, exposure, and residual risk.
- Review existing risk acceptances approaching expiration and coordinate remediation, renewal, or escalation as appropriate.
- Ensure risk acceptance documentation is technically accurate, clearly written, and completed in accordance with established processes and approval requirements.
- Communicate effectively with engineers, managers, and technology leadership regarding vulnerability risk and remediation decisions.
Qualifications:
- Significant hands-on experience in vulnerability management, vulnerability analysis, infrastructure security, or a closely related security engineering discipline.
- Senior-level understanding of vulnerabilities, including CVEs, CVSS, vulnerability applicability, exploitability, remediation, mitigation, and false-positive validation.
- Demonstrated ability to independently investigate and validate vulnerability findings rather than relying solely on vulnerability scanner results or severity ratings.
- Strong technical understanding of enterprise infrastructure, including operating systems, networking, middleware, servers, common enterprise platforms, and related technologies.
- Experience with enterprise vulnerability scanning and/or vulnerability management platforms such as Rapid7 InsightVM/Nexpose, Qualys VM, Nucleus, or comparable technologies.
- Ability to research and interpret vendor security advisories, CVE information, scanner evidence, software versions, patches, configurations, and other technical data when assessing vulnerability findings.
- Experience coordinating vulnerability remediation with infrastructure, platform, middleware, DevOps, or other technical engineering teams.
- Ability to learn and consistently execute established operational processes and runbooks with minimal oversight.
- Strong organizational skills and ability to independently manage multiple concurrent vulnerability investigations, remediation efforts, and stakeholder interactions.
- Excellent written and verbal communication skills.
- Strong interpersonal and relationship-management skills, with demonstrated ability to work effectively with both highly technical engineers and technology leadership.
Preferred Skills:
- Direct experience with Rapid7 InsightVM/Nexpose, Nucleus, and/or Qualys Vulnerability Management.
- Experience supporting enterprise-scale vulnerability management programs and large, heterogeneous technology environments.
- Experience managing vulnerability advisories, remediation ticketing workflows, vulnerability exceptions, and/or formal risk acceptance processes.
- Experience investigating vulnerabilities affecting middleware, infrastructure platforms, network technologies, operating systems, containers, or DevOps tooling.
- Familiarity with vulnerability intelligence sources, exploitability analysis, CISA KEV, EPSS, vendor advisories, and other risk-prioritization inputs.
- Experience working within defined vulnerability remediation SLAs and escalation processes.
- Familiarity with workflow/ticketing platforms such as Jira or Ivanti.
Similar jobs
- NG
Industrial Security Analyst with Security Clearance
Northrop Grumman
Redondo Beach, CA🇺🇸$75.8k - $113.8k/yrHybrid5 weeks agoHTTPTechnology - GU
Cybersecurity Risk - Senior Consultant with Security Clearance
Guidehouse
McLean, VA🇺🇸$113k - $188k/yrHybrid2 weeks agoTechnology - GU
Cybersecurity Consultant with Security Clearance
Guidehouse
McLean, VA🇺🇸$85k - $141k/yrHybrid4 weeks agoPower BITechnology - BO
Network Security Engineer with Security Clearance
Boeing
Colorado Springs, CO🇺🇸$102k - $138k/yrOn-site5 weeks agoTCP/IPAnsibleMicrosoft PowerPoint+3Technology - AM
ADC Engineer, Cryptography / Identity with Security Clearance
Amazon
Bellevue, WA🇺🇸$116.9k - $167.4k/yrHybrid6 weeks agoEngineering - SO
Senior Cloud Security Specialist with Security Clearance
NewSystem One Holdings, LLC
Washington, DC🇺🇸On-site23 hours agoAWSZero TrustTechnology