Назад
Company hidden
8 дней назад

Senior Vulnerability & Security Engineer (Cybersecurity)

150 000 - 195 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Vulnerability & Security Engineer (Cybersecurity): Advancing enterprise vulnerability management and security configuration programs with an accent on risk-based vulnerability analysis, secure configuration baselines, and automated compliance assessment. Focus on evaluating exploitability and business impact, engineering remediation workflows, and translating complex security findings into actionable recommendations.

Location: Jersey City, New Jersey, United States

Salary: $150,000–$195,000 annual base salary for New Jersey, plus annual target bonus.

Company

hirify.global is a global financial services firm providing investor services, capital partnerships, specialist expertise, and technology solutions.

What you will do

  • Analyze vulnerabilities from enterprise scanning, EDR, application security testing, penetration testing, and threat intelligence sources.
  • Assess CVEs, vendor advisories, attack vectors, exploitability, business impact, mitigation options, and residual risk.
  • Partner with infrastructure, cloud, application, platform, and engineering teams to develop and evaluate remediation strategies.
  • Design and improve vulnerability and security configuration management capabilities, including secure configuration baselines and automated compliance monitoring.
  • Integrate configuration findings with vulnerability management workflows to improve cyber-risk visibility and prioritization.
  • Act as a technical escalation point, provide subject-matter expertise, and mentor cybersecurity team members.

Requirements

  • 7+ years of cybersecurity experience, preferably in financial services or another highly regulated industry.
  • Strong knowledge of enterprise infrastructure, operating systems, networking, databases, applications, and cloud platforms.
  • Experience operating vulnerability management and security configuration management programs.
  • Experience with vulnerability exceptions, compensating controls, risk acceptance, remediation governance, and compliance evaluation.
  • Knowledge of NIST, ISO 27001, OWASP, NYDFS Part 500, DORA, CIS, and STIG frameworks and regulations.
  • Strong analytical, problem-solving, stakeholder management, communication, and influencing skills.

Nice to have

  • CISSP or equivalent certification.
  • Automation and scripting experience with PowerShell, Python, or similar tools.
  • Advanced PowerPoint and Excel skills for executive risk reporting, dashboards, metrics, and presentations.

Culture & Benefits

  • Long-term employment within a private partnership with a 200-year history.
  • Collaborative environment focused on collective problem-solving, knowledge sharing, and mentoring.
  • Benefits include long-term savings, healthcare, income protection, professional development, and paid time off.
  • Compensation includes base salary, discretionary bonuses, and profit-sharing.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →