Назад
Company hidden
3 часа назад

Vulnerability Management Engineer (DOD)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Management Engineer (DOD) (Cybersecurity): Identifying, analysing, and supporting the remediation of infrastructure and cloud vulnerabilities with an accent on risk-based triage, regulatory compliance, and AI-assisted security workflows. Focus on validating scan findings, supporting DoD IL4 and FedRAMP preparation, integrating vulnerability management into delivery pipelines, and driving measurable remediation progress.

Location: Hybrid in Austin, United States

Company

hirify.global operates a large-scale global network that protects and accelerates Internet applications for customers worldwide.

What you will do

  • Conduct vulnerability scans and analyse findings from Qualys, Nessus, and Rapid7 to verify accuracy, identify systemic patterns, and filter false positives.
  • Triage, validate, and prioritise vulnerabilities using CVSS and risk-based methodologies.
  • Coordinate with engineering, infrastructure, cloud, compliance, and service teams on remediation actions, timelines, and progress.
  • Develop and document technical remediation guidance for application and infrastructure teams.
  • Support DoD IL4 and FedRAMP preparation by maintaining compliant vulnerability processes, evidence, reporting, and controls.
  • Use AI security tools and automation to improve triage, pattern recognition, risk prioritisation, and remediation workflows.

Requirements

  • 3+ years of vulnerability management experience in a heavily regulated environment.
  • Solid understanding of DoD Impact Level IL4, FedRAMP, SOC 2, and PCI frameworks.
  • Hands-on experience with vulnerability scanning platforms such as Qualys, Nessus, or Rapid7 InsightVM.
  • Strong understanding of CVSS and business-context risk assessment.
  • Strong analytical, written, verbal, and interpersonal communication skills.
  • Bachelor’s degree in Computer Science or Information Security, or relevant security certifications.

Nice to have

  • Python or another scripting language for automation.
  • Experience with JIRA for ticket and task management.
  • Experience integrating LLMs or AI APIs into cybersecurity workflows and automation pipelines.
  • Hands-on experience with infrastructure penetration-testing tools.

Culture & Benefits

  • Mission focused on protecting and improving the free and open Internet.
  • AI-native, iterative approach to solving complex security and infrastructure problems.
  • Applicants reaching the offer stage may be asked to attend an in-person interview at a hirify.global office or hub.
  • Employment may require authorization to receive technology controlled under U.S. export laws without sponsorship for an export license.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →