Vulnerability Management Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Centennial, Colorado, United States. Hybrid work is available for associates living within 30 miles of an office location, with remote work part of the week and in-office presence three days per week. United States citizenship and existing authorization to work in the United States are required; visa sponsorship is not available.
Salary: $75,000–$125,000 annually, depending on experience.
Company
is a diversified service company operating across student lending, professional services, consumer lending, payments processing, renewable energy, and K-12 and higher education.
What you will do
- Design, develop, and continuously improve the vulnerability management strategy in alignment with business and security requirements.
- Monitor emerging threats and vulnerabilities and adapt the program accordingly.
- Configure and maintain vulnerability scanning tools and analyze findings to assess risk.
- Develop remediation plans and collaborate with technology teams and business stakeholders to resolve critical vulnerabilities.
- Partner with the SOC, Cyber Threat Intelligence, and Offensive Security teams to validate impact, prioritize remediation, and recommend mitigation or compensating controls.
- Provide accurate and timely reporting on remediation progress and operational risk.
Requirements
- 2+ years of experience in vulnerability management and/or security operations.
- Experience with vulnerability management solutions such as Rapid7, Qualys, or Tenable.
- Experience with patching tools such as Microsoft MECM and administration of EDR platforms including Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Cortex XDR, or Tanium.
- Solid understanding of cloud-hosting platforms and security threats affecting Azure, AWS, and GCP services.
- Knowledge of Python is required.
- Bachelor’s degree in cybersecurity or information systems, or relevant professional experience.
Nice to have
- Knowledge of CIS Benchmarks, DISA STIGs, NSA Hardening Guides, and other security frameworks.
- Cybersecurity certifications such as GIAC GSEC, GCED, GEVA, CompTIA Security+, CySA+, or CISSP.
- Experience with Azure, AWS, and GCP security.
Culture & Benefits
- Medical, dental, and vision insurance.
- HSA and FSA options, life and AD&D insurance, and disability coverage.
- Generous earned time off and a wellness program.
- 401(k), student loan repayment, tuition reimbursement, and employee stock purchase program.
- Employee assistance program and performance-based incentive pay.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →