About the Role
We are seeking a Cybersecurity Engineer to enhance our vulnerability management program. This role focuses on vulnerability management but requires a well-rounded engineer with broad cybersecurity knowledge to effectively assess real risks and prioritize efforts. The position involves hands-on work, emphasizing automation and building solutions to scale the program in a growing environment. You will leverage automation, including AI tooling, to manage vulnerabilities efficiently, ensuring a human in the loop for critical decisions.
Responsibilities
- Support and improve the vulnerability management lifecycle from discovery and validation through triage, assignment, remediation tracking, and verification.
- Review new findings from automated scanning tools, threat intelligence, and security advisories, prioritizing based on exploitability and exposure.
- Validate and deduplicate findings across sources, confirming affected products or components and routing work to the appropriate teams.
- Measure scanning coverage and data quality, identifying gaps, stale scans, and authentication failures.
- Drive automation across vulnerability management tooling and processes.
- Expand scanning coverage across asset classes, including evaluating and migrating scanning platforms.
- Integrate software inventory and SBOM data to track vulnerable components across the software landscape.
- Build dashboards and metrics to measure coverage, SLAs, and progress.
Requirements
- Automate tasks and maintain code and configurations in version control.
- Work comfortably under code review and prioritize maintainability.
- Process and query data, building and debugging data pipelines and integrations.
- Possess hands-on vulnerability management experience in a substantial environment.
- Experience with automated scanning platforms (e.g., Rapid7, Tenable, Qualys).
- Understand the integration of scanning, asset inventory, and remediation tracking.
- Reason about trade-offs and context, understand threat modeling, and prioritize findings.
- Stay current with cybersecurity developments.
- Practice and communicate good personal cybersecurity hygiene.
- Communicate clearly across different audiences, both verbally and in writing.
- Maintain a positive and collaborative attitude, fostering buy-in from others.
Skills
- Vulnerability Management
- Automation
- AI Tooling
- Data Analysis
- Data Pipelines
- Integrations
- Automated Scanning Platforms (Rapid7, Tenable, Qualys)
- Threat Modeling
- Cybersecurity Developments
- Personal Cybersecurity Hygiene
- Clear Communication
- Collaboration
About the Company
- A firm dedicated to keeping its environment safe through a skilled Cybersecurity team.
- Investing in vulnerability management with a focus on automation and scaling.
