JOBSEARCHER

Vulnerability Management Security Engineer (Fully Remote)

ARCHIVED
BettercloudRemoteL6 LeadMay 8th, 2026

We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.

About Katapult Our mission is clear: to unlock financial possibilities through innovative technology. Our vision is to remove financial barriers and transform the shopping experience with technology that simplifies and enhances access for consumers. Our core values reflect how we operate—we aim to uplift our employees, customers, and retail partners by offering transparent and innovative financial solutions. We deliver outstanding results through dedication, integrity, and teamwork, creating opportunities for success and growth every day. Inclusion is at the heart of who we are; together, we achieve more. We work hard, play hard, and celebrate big wins.At Katapult, we believe that opportunity is everything, and our people drive our success. We seek individuals who are committed to excellence, eager to learn, and ready to bring their best every day. With a competitive benefits package, an engaging culture, and ample opportunities for career advancement, Katapult is committed to investing in its people.About the Role The Vulnerability Management Security Engineer owns and continuously improves the enterprise vulnerability management program across endpoints, servers, network devices, cloud resources, and Microsoft 365. This role leads vulnerability validation and risk‐based prioritization, defines remediation standards and SLAs, and drives cross‐functional execution with internal teams and outsourced IT providers. The position produces executive‐ready risk reporting, guides secure configuration/hardening practices, and supports email security administration and tuning in Proofpoint to reduce phishing and malware exposure.Own the vulnerability management lifecycle and operating model: asset discovery, authenticated scanning, validation/triage, risk‐based prioritization, remediation tracking, and exception handlingAdminister and tune vulnerability scanning tools (e.g., Tenable/Qualys/Rapid7), including scan policies, schedules, credentials, coverage monitoring, and false‐positive reductionMaintain accurate vulnerability scope by partnering with IT and outsourced IT to improve inventory/CMDB data, ownership, tagging, and coverage for servers, endpoints, network devices, and cloud resourcesDrive remediation with system owners by translating technical findings into actionable tickets, validating fixes, and escalating overdue/high‐risk items based on defined SLAsDefine vulnerability remediation standards (severity definitions, SLAs, exception criteria) and manage the risk acceptance/exception process with appropriate approvals and audit‐ready evidenceCoordinate patch and configuration remediation activities with internal IT and outsourced IT, including maintenance windows, validation scans, and change control documentationProduce executive‐ready risk reporting and program metrics (dashboards/scorecards); communicate trends, exposure drivers, and remediation performance to leadership and technical teamsSupport secure configuration and hardening efforts by aligning remediation guidance to recognized standards (e.g., CIS Benchmarks, vendor guidance) and validating compliance via scanning and spot checksCoordinate external penetration tests and vulnerability assessments; intake findings, assist with remediation plans, and track closure through retestingPerform vulnerability validation and prioritization, including exploitability context (e.g., KEV/exploit intel), business criticality, and exposure (internet‐facing, privilege level, lateral movement)Lead rapid exposure assessments and remediation coordination for emerging threats (e.g., zero‐days, CISA KEV additions), including stakeholder communications and mitigation trackingPartner with Security Operations (SOC) and Incident Response to perform rapid exposure assessments during emerging threats and support containment/mitigation actions as neededManage vulnerability‐related tickets/workflows in the organization's service management platform (e.g., ServiceNow/Jira), including SLA tracking, evidence collection, and audit‐ready documentationLead continuous improvement for vulnerability management, including automation, coverage expansion, authenticated scanning maturity, and integrations with patching/endpoint management, CMDB, and ticketing systemsProvide security oversight and governance for outsourced IT/MSP vulnerability remediation deliverables (patching, endpoint protection, scanning credential management, hardening), including KPI/SLA review, quality assurance, and escalationsLead vendor and outsourced IT coordination to ensure timely remediation and accurate reporting; define expectations, participate in QBRs, and manage escalations for recurring security gapsOwn and improve Microsoft 365 security and identity controls relevant to vulnerability reduction (e.g., Entra ID, Conditional Access, MFA, privileged access/secure admin practices, security baselines) in coordination with ITOwn Proofpoint email security configuration and tuning for Office 365/Exchange Online mail flow (e.g., anti‐spam/anti‐malware, URL defense, attachment sandboxing, anti‐phishing/BEC protection), including incident‐driven rule updates, metrics/reporting, and continuous reduction of false positives/negativesJob Requirements & Qualifications Education:Bachelor's Degree in Computer Science (or equivalent)Relevant security certification preferred (e.g., Security+, SSCP, CISSP, or GIAC)Relevant technical certification preferred (e.g., OSCP/OSCE, GIAC (GSEC/GPEN/GCIH), Microsoft SC‐200/SC‐300/SC‐100)Experience/KSAs:6+ years of experience in vulnerability management, security engineering, or a closely related cyber security roleHands‐on experience with vulnerability management platforms and scanners (e.g., Tenable, Qualys, Rapid7) and interpreting CVEs/CVSS and vendor advisoriesDemonstrated experience defining vulnerability prioritization models, remediation SLAs, and governance (exceptions/risk acceptance), including executive‐ready reporting and metricsStrong working knowledge of Windows and Linux patching/configuration, endpoint management, and common enterprise infrastructure (AD/Entra ID, virtualization, networking, cloud services)Experience with Microsoft 365 security administration and Exchange Online mail flow concepts, plus hands‐on experience administering or partnering on Proofpoint email security filtering and policy tuningExperience managing or overseeing outsourced IT providers/MSPs, including ticket quality, SLA performance, security deliverables, and escalation managementProven ability to influence and drive remediation across teams (including outsourced providers) without direct authority; excellent written and verbal communication with technical and executive stakeholdersAbility to mentor teammates and uplift partner teams by providing clear remediation guidance, repeatable runbooks, and training on vulnerability management processesAbility to analyze data, validate findings, and independently drive tasks to closure with sound judgment and attention to detailFamiliarity with ticketing/workflow tools (e.g., ServiceNow/Jira) and producing audit‐ready evidence of remediation and exceptionsScripting/automation skills (PowerShell and/or Python) to support reporting, data normalization, and process automationPreferred: experience integrating vulnerability data with SIEM/SOAR, asset/attack surface management, or cloud security tooling to improve prioritization and responseUnderstanding of vulnerability and exposure intelligence sources (e.g., CISA KEV, vendor advisories) and how to apply them to prioritizationKnowledge of security best practices for managing, controlling, and monitoring cyber controls; familiarity with common frameworks (e.g., NIST CSF, CIS Controls) is preferredWork Environment/Other InfoMinimal Travel Required. Travel limited to training, occasional team meetings, and projectsOn‐call after hours or weekend support may be required, as neededCollaborative and inclusive work environment with opportunities for personal growth#J-18808-Ljbffr