Vulnerability Management & Response Engineer
Core
Operate and continuously improve the enterprise Vulnerability Management (VM) program, owning end-to-end processes from identification to remediation validation across on-premises and cloud environments.
Role type
Vulnerability Management & Response Engineer
Builds
Enterprise VM program capabilities, automated remediation workflows, and risk-informed decision frameworks.
Domain
Cybersecurity / Vulnerability Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Tenable administration, enterprise VM program operations, CVSS scoring, threat intelligence correlation, risk-based prioritization, patching strategy leadership, process improvement, cross-functional collaboration
Preferred skills
SOAR/SIEM integration, container security, cloud-native security controls (Azure/AWS/GCP), API-based vulnerability exposure, CMDB reconciliation, executive risk reporting
Technologies
Tenable, SCCM, Intune, SOAR, SIEM, ServiceNow, Remedyforce, Azure, AWS, GCP
Responsibilities
Operate Tenable platform (scan configuration, scheduling, coverage monitoring, credentials management, troubleshooting); Lead triage, assignment, and validation of vulnerability remediation tasks; Define and enforce SLA-based remediation with escalation and executive reporting; Integrate VM findings with SCCM, Intune, SOAR, SIEM, and ticketing systems; Conduct quarterly reconciliation of scanner output with CMDB; Maintain auditable exception register with risk acceptance and compensating controls; Produce VM program metrics and reporting; Run VM governance cadence for backlog and coverage review; Support internal audit and regulatory reviews.
Seniority
Mid-Senior, hands-on IC