Contract - Expert Level Vulnerability Management Engineer
Contract - Expert Level Vulnerability Management EngineerRate: openLocation: RemoteDuration: 4 months CTH*We are unable to provide sponsorship for this role*Qualifications Expert-level experience with high understanding of vulnerabilities, including CVEs, CVSS, vulnerability applicability, exploitability, remediation, mitigation, and false-positive validation.Demonstrated ability to independently investigate and validate vulnerability findings rather than relying solely on vulnerability scanner results or severity ratings.Strong technical understanding of enterprise infrastructure, including operating systems, networking, middleware, servers, common enterprise platforms, and related technologies.Experience with enterprise vulnerability scanning and/or vulnerability management platforms such as Rapid7 InsightVM/Nexpose, Qualys VM, Nucleus, or comparable technologies.Ability to research and interpret vendor security advisories, CVE information, scanner evidence, software versions, patches, configurations, and other technical data when assessing vulnerability findings.Experience coordinating vulnerability remediation with infrastructure, platform, middleware, DevOps, or other technical engineering teams.Experience investigating vulnerabilities affecting middleware, infrastructure platforms, network technologies, operating systems, containers, or DevOps tooling.ResponsibilitiesInvestigate and validate vulnerabilities identified through enterprise vulnerability scanning and aggregation platforms, including Rapid7 InsightVM/Nexpose, Qualys, and Nucleus.Perform technical analysis beyond scanner output to determine whether vulnerabilities are valid, applicable, exploitable, or otherwise relevant within the context of the affected environment.Research CVEs, vendor advisories, security bulletins, affected versions, patches, mitigations, exploitability, and other technical information necessary to accurately assess vulnerability risk.Execute established vulnerability management processes and runbooks consistently and independently.Provide backup support for day-to-day and on-call vulnerability management activities, including investigation and coordination of newly identified or time-sensitive vulnerabilities.Triage vulnerability findings and determine appropriate actions based on severity, exposure, exploitability, affected technology, and established enterprise requirements.Review existing risk acceptances approaching expiration and coordinate remediation, renewal, or escalation as appropriate.Ensure risk acceptance documentation is technically accurate, clearly written, and completed in accordance with established processes and approval requirements.Build productive working relationships with infrastructure, middleware, DevOps, application, security, and other technology teams.Serve as a knowledgeable and pragmatic vulnerability management partner rather than simply distributing scanner findings.Explain vulnerabilities, technical risk, remediation requirements, and security expectations clearly to stakeholders with varying levels of security expertise.