Lead Information Security Engineer (Vulnerability Management)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Lead Information Security Engineer (Vulnerability Management): Supporting the continuous vulnerability remediation process and reducing the attack surface across infrastructure, endpoints, and applications with an accent on deep investigative analysis, CVE triage, and risk-based remediation. Focus on designing sophisticated remediation plans, interpreting complex scanning output, and implementing cybersecurity frameworks like NIST and ISO.
Location: Virtual (US) — this position is not available for immigration sponsorship
Salary: $82,100 - $172,500 Annual
Company
is a major financial institution dedicated to connecting great people to opportunities and improving the lives of its customers and communities.
What you will do
- Serve as the primary SME for the most complex and high-risk remediation issues across cloud, containers, applications, and on-prem infrastructure.
- Own the end-to-end intake, investigation, and mitigation process for critical vulnerabilities, emerging threats, and executive escalations.
- Design and maintain reporting dashboards and workflows utilizing PowerBI, ServiceNow, and Brinqa.
- Collaborate with infrastructure and development teams to embed security from design through deployment and into operations.
- Mentor junior and mid-level engineers through structured coaching and direct involvement in complex cases.
Requirements
- At least 6 years of recent hands-on experience in Vulnerability Management.
- Must be based in the US and possess valid work authorization (no immigration sponsorship provided).
- Strong expertise in security architecture, networking, operating systems, identity, and cloud services.
- Bachelor’s degree in computer science, information systems, or equivalent combination of education and experience.
- Relevant certifications such as CISSP, CISM, Security+, GIAC, or AWS certifications.
Nice to have
- Working knowledge of scripting (Python, PowerShell, SQL) for data analysis and workflow automation.
- Experience with cloud security, container security, application security, or code scanning programs.
- Hands-on experience implementing NIST CSF, NIST 800-53, CIS Controls, ISO 27001, and PCI DSS.
- Experience embedding security controls into CI/CD pipelines and DevSecOps workflows.
Culture & Benefits
- Comprehensive benefits programs encompassing physical, financial, emotional, and social well-being.
- Eligibility for an incentive compensation plan based on individual and company performance.
- Inclusive culture promoting equal employment opportunity for all.
- Flexible virtual work environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →