Назад
Company hidden
12 часов назад

Vulnerability Management Engineer (Cybersecurity)

75 000 - 125 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Management Engineer (Cybersecurity): Designing and improving an enterprise vulnerability management program, configuring scanning tools, analyzing vulnerability data, and driving remediation with technology and business teams with an accent on attack-surface reduction, risk prioritization, and security operations collaboration. Focus on validating vulnerability impact, developing mitigation plans, administering vulnerability and EDR platforms, and securing cloud-hosted services.

Location: Centennial, Colorado, United States. Hybrid work is available for associates living within 30 miles of an office location, with remote work part of the week and in-office presence three days per week. United States citizenship and existing authorization to work in the United States are required; visa sponsorship is not available.

Salary: $75,000–$125,000 annually, depending on experience.

Company

hirify.global is a diversified service company operating across student lending, professional services, consumer lending, payments processing, renewable energy, and K-12 and higher education.

What you will do

  • Design, develop, and continuously improve the vulnerability management strategy in alignment with business and security requirements.
  • Monitor emerging threats and vulnerabilities and adapt the program accordingly.
  • Configure and maintain vulnerability scanning tools and analyze findings to assess risk.
  • Develop remediation plans and collaborate with technology teams and business stakeholders to resolve critical vulnerabilities.
  • Partner with the SOC, Cyber Threat Intelligence, and Offensive Security teams to validate impact, prioritize remediation, and recommend mitigation or compensating controls.
  • Provide accurate and timely reporting on remediation progress and operational risk.

Requirements

  • 2+ years of experience in vulnerability management and/or security operations.
  • Experience with vulnerability management solutions such as Rapid7, Qualys, or Tenable.
  • Experience with patching tools such as Microsoft MECM and administration of EDR platforms including Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Cortex XDR, or Tanium.
  • Solid understanding of cloud-hosting platforms and security threats affecting Azure, AWS, and GCP services.
  • Knowledge of Python is required.
  • Bachelor’s degree in cybersecurity or information systems, or relevant professional experience.

Nice to have

  • Knowledge of CIS Benchmarks, DISA STIGs, NSA Hardening Guides, and other security frameworks.
  • Cybersecurity certifications such as GIAC GSEC, GCED, GEVA, CompTIA Security+, CySA+, or CISSP.
  • Experience with Azure, AWS, and GCP security.

Culture & Benefits

  • Medical, dental, and vision insurance.
  • HSA and FSA options, life and AD&D insurance, and disability coverage.
  • Generous earned time off and a wellness program.
  • 401(k), student loan repayment, tuition reimbursement, and employee stock purchase program.
  • Employee assistance program and performance-based incentive pay.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →