Назад
Company hidden
14 часов назад

Vulnerability Management Engineer (Cybersecurity)

75 000 - 125 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Management Engineer (Cybersecurity): Designing and improving an enterprise vulnerability management program, configuring scanning tools, analyzing vulnerability data, and driving remediation with technology and business teams with an accent on attack-surface reduction, risk prioritization, and security operations. Focus on validating vulnerability impact, developing mitigation plans, administering EDR and patching tools, and securing cloud-hosted services across Azure, AWS, and GCP.

Location: Hybrid in Centennial, Colorado; candidates must live within 30 miles of an office and work in the office three days per week. The role requires United States citizenship and existing authorization to work in the United States without current or future visa sponsorship.

Salary: $75,000–$125,000 annually, depending on experience.

Company

hirify.global is a diversified service and financial technology company operating across student lending, payments processing, renewable energy, and K–12 and higher education.

What you will do

  • Design, develop, and continuously improve the enterprise vulnerability management strategy.
  • Configure and maintain vulnerability scanning solutions and analyze vulnerability data to assess risk.
  • Develop remediation plans and collaborate with technology teams and business stakeholders to resolve critical vulnerabilities.
  • Partner with the SOC, Cyber Threat Intelligence, and Offensive Security teams to validate vulnerability impact and refine prioritization.
  • Advise system owners on mitigation strategies and compensating controls while providing timely remediation reporting.
  • Track emerging threats and vulnerabilities and adapt the program to changing security risks.

Requirements

  • At least 2 years of experience in vulnerability management and/or security operations.
  • Experience with vulnerability management platforms such as Rapid7, Qualys, or Tenable.
  • Experience with Microsoft MECM patching tools and EDR administration, including Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Networks Cortex XDR, or Tanium.
  • Understanding of cloud-hosting security threats across Azure, AWS, and GCP.
  • United States citizenship and authorization to work in the United States without visa sponsorship are required.
  • Bachelor’s degree in cybersecurity or information systems, or relevant professional experience; Python programming is required.

Nice to have

  • Knowledge of CIS Benchmarks, DISA STIGs, NSA Hardening Guides, and other security frameworks.
  • Cybersecurity certifications such as GIAC GSEC, GCED, GEVA, CompTIA Security+, CySA+, or ISC2 CISSP.

Culture & Benefits

  • Hybrid work environment with flexibility and regular in-office collaboration.
  • Medical, dental, vision, HSA, and FSA benefits.
  • Earned time off, 401(k), student loan repayment, life and disability insurance, and employee assistance programs.
  • Employee stock purchase program, tuition reimbursement, performance-based incentive pay, and wellness support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →