Live opening · Posted 12 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Senior Cyber Risk & Vulnerability Engineer
Job Overview
We are seeking a Senior Cyber Risk Management Engineer to support enterprise vulnerability management operations. This is a hands-on senior-level role focused on investigating, validating, prioritizing, and driving remediation of vulnerabilities across infrastructure, middleware, platforms, and DevOps technologies.
The ideal candidate has strong technical vulnerability analysis skills, enterprise infrastructure knowledge, and experience working directly with engineering teams and technology leadership.
Key Responsibilities
Investigate and validate vulnerabilities using platforms such as Rapid7 InsightVM/Nexpose, Qualys, and Nucleus.
Analyze CVEs, CVSS, exploitability, affected versions, configurations, patches, and vendor advisories.
Identify false positives and determine vulnerability applicability and exposure beyond scanner results.
Coordinate remediation with infrastructure, middleware, DevOps, platform, and security teams.
Create vulnerability advisories, remediation tickets, and stakeholder communications.
Track findings through remediation, mitigation, escalation, or formal risk acceptance.
Manage vulnerability exceptions and expiring risk acceptances.
Support vulnerability SLAs, escalation processes, and backlog reduction.
Clearly communicate technical risk and remediation requirements to engineers, managers, and leadership.
Maintain accurate vulnerability records and documentation.
Required Qualifications
10+ years of combined hands-on vulnerability management, cyber risk, infrastructure security, or related security engineering experience.
Strong knowledge of CVEs, CVSS, vulnerability validation, exploitability, remediation, mitigation, and false-positive analysis.
Strong understanding of enterprise infrastructure, including Windows/Linux, networking, servers, middleware, platforms, and DevOps technologies.
Experience with Rapid7, Qualys, Nucleus, or comparable vulnerability management tools.
Ability to independently investigate findings and validate scanner results using technical evidence.
Experience coordinating remediation with technical engineering teams.
Strong organizational, analytical, written, and verbal communication skills.
Ability to manage multiple investigations and remediation efforts with minimal supervision.
Experience with Rapid7 InsightVM/Nexpose, Qualys VM, and/or Nucleus.
Enterprise-scale vulnerability management experience.
Experience with vulnerability advisories, remediation workflows, exceptions, and risk acceptance.
Exposure to containers, network technologies, middleware, operating systems, and DevOps tooling.
Familiarity with CISA KEV, EPSS, vulnerability intelligence, and exploitability analysis.
Experience with vulnerability remediation SLAs and escalation processes.
Familiarity with Jira or Ivanti.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.