Find Jobs
Find Jobs Near You – Available Work in Your Location
Vulnerability Management Engineer
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Colorado data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$107,473 / year median in Colorado
+6% projected growth
Job Description
JOB RESPONSIBILITIES
- Lead the design, development, and continuous improvement of the organization's vulnerability management strategy, aligning with business objectives and security requirements.
- Stay up to date on emerging security threats and vulnerabilities, and ensure the program adapts accordingly.
- Oversee the configuration and maintenance of vulnerability scanning tools.
- Analyze vulnerability data to assess risk and recommend appropriate mitigation strategies.
- Develop and implement vulnerability remediation plans, working collaboratively with all technology teams and the business.
- Collaborate with cross-functional teams to assess vulnerability risks, prioritize remediation efforts, and ensure timely resolution of critical vulnerabilities to minimize security risks and operational impact.
- Knowledge of CIS benchmarks, DISA STIGs, NSA Hardening Guides, and other industry security frameworks.
- Demonstrated passion for continuous learning.
EDUCATION
Bachelor's degree in cyber security or information systems OR relevant work experience. Cyber Security related certifications such as GIAC GSEC, GCED, GEVA, CompTIA Security+ , CySA+, ISC2 CISSP are a plus.EXPERIENCE
- 2+ years of experience in vulnerability management and/or security operations.
- Experience with Vulnerability management solutions (Rapid 7, Qualys, Tenable, etc.)
- Experience with patching tools like Microsoft MECM.
- Experience with EDR administration (Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Network Cortex XDR, Tanium etc.)
- Solid understanding of cloud-based hosting platforms, with background on security threats deriving from Azure, AWS and GCP hosted services being preferred.
- Partner with the SOC, Cyber Threat Intel, Offensive Security Team, and other stakeholders to refine prioritization, to validate impact of suspected vulnerabilities, to advise owners on mitigation strategies or compensating controls, and to provide accurate & timely reporting that informs remediation progress.
- Knowledge of python programming language is required.