Назад
Company hidden
3 дня назад

Vulnerability Management Specialist (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Management Specialist (Cybersecurity): Executing continuous vulnerability scanning and remediation coordination across enterprise endpoints, servers, cloud resources, and applications with an accent on risk prioritization, SLA enforcement, and security compliance. Focus on validating findings, assessing exploitability, developing PowerShell workflows, and coordinating remediation with infrastructure, endpoint, cloud, application, threat intelligence, and SOC teams.

Location: Hybrid schedule: 3 days in the Dallas, TX or Cincinnati, OH office and 2 days remote. No relocation assistance is offered.

Company

hirify.global is an insurance company offering professional development opportunities and employee benefits.

What you will do

  • Conduct continuous vulnerability scanning across endpoints, servers, cloud resources, applications, and other enterprise assets using Qualys and related tools.
  • Analyze scan results, validate findings, remove false positives, assess exploitability, and prioritize risk using CVSS, QDS, asset criticality, and business impact.
  • Enforce remediation SLAs: Critical within 7 days, High within 30 days, Medium within 60 days, and Low within 180 days.
  • Coordinate remediation with Infrastructure, Endpoint, Cloud, Application, Threat Intelligence, and SOC teams.
  • Support remediation and validation using Qualys, Intune, JAMF, PolicyPak, and Microsoft Defender.
  • Develop PowerShell scripts and workflows for remediation, reporting, and validation.

Requirements

  • 4+ years of experience in vulnerability management, security engineering, or threat operations.
  • Hands-on experience with vulnerability scanning platforms; Qualys is preferred, while Tenable or Rapid7 are acceptable.
  • Experience with Intune, JAMF, or similar endpoint management tools.
  • Strong understanding of CVSS scoring, risk prioritization, patch management, remediation workflows, and endpoint, server, and cloud security fundamentals.
  • Ability to communicate technical risk clearly to non-security teams, with strong documentation and organizational skills.
  • Must be authorized to work for any employer in the United States; employment visa sponsorship or transfer is not available.

Nice to have

  • CompTIA Security+ certification.
  • Qualys Vulnerability Management certifications.
  • GIAC certifications such as GSEC or GCIH.
  • CISSP certification or progress toward certification.

Culture & Benefits

  • Hybrid work arrangement with two remote days per week.
  • Professional development and advancement opportunities.
  • Medical, dental, vision, and life insurance.
  • Short- and long-term disability coverage.
  • Company-matched 401(k) plan with 100% matching on up to a 6% contribution.
  • Employee Assistance Plan, Health Savings Account, Flexible Spending Account, Health Reimbursement Account, and wellness program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →