US_East | Data Engineer_L2
Vulnerability Management EngineerLocation: New York (Face-to-Face Interview Required)We are seeking an experienced Vulnerability Management Engineer to lead enterprise vulnerability management initiatives and strengthen the organization's security posture. The ideal candidate will have hands-on experience with vulnerability assessment, remediation, security governance, risk management, and collaboration with infrastructure, application, and cloud engineering teams. This role requires strong technical expertise, leadership skills, and the ability to communicate effectively with both technical teams and executive stakeholders.Key Responsibilities:Lead enterprise vulnerability management programs across infrastructure, cloud, applications, and endpoints.Perform vulnerability assessments, risk analysis, and remediation planning.Collaborate with development, infrastructure, cloud, and security teams to remediate identified vulnerabilities.Develop and maintain vulnerability management processes, standards, and security policies.Prioritize vulnerabilities based on business impact, exploitability, and risk.Monitor security posture and provide executive reporting on vulnerability trends and remediation metrics.Support security compliance initiatives and audit requirements.Drive automation and continuous improvement within vulnerability management processes.Partner with engineering teams to integrate security into the SDLC and DevSecOps pipelines.Provide technical leadership and guidance during security incidents and remediation activities.Required Qualifications:Strong experience in Vulnerability Management and Security Engineering.Experience leading engineering or security initiatives across enterprise environments.Deep understanding of vulnerability assessment methodologies and remediation processes.Hands-on experience with vulnerability scanning and security management tools.Strong knowledge of security best practices, risk management, and compliance frameworks.Experience working with infrastructure, cloud, application, and DevOps teams.Excellent analytical, troubleshooting, and problem-solving skills.Strong communication and stakeholder management abilities.Preferred Technical Skills:Vulnerability Management Platforms (Tenable, Qualys, Rapid7, or similar)SIEM and Security MonitoringDevSecOpsCI/CD PipelinesSecurity AutomationInfrastructure SecurityApplication SecurityIdentity & Access ManagementWindows and Linux SecurityNetwork SecurityCloud Security (AWS, Azure, or GCP)Nice to Have:Experience with AI/GenAI-enabled security solutions.SRE or Platform Engineering experience.Kubernetes and container security.Infrastructure as Code (Terraform, Ansible, etc.).Cloud security certifications.CISSP, Security+, CEH, GSEC, or related security certifications.Top 5 Must-Have Skills:Vulnerability ManagementSecurity Engineering & Risk AssessmentVulnerability Scanning & RemediationSecurity Governance & ComplianceStakeholder Communication & Cross-Functional CollaborationThe ideal candidate is a senior security professional with strong vulnerability management expertise who can lead enterprise security initiatives, collaborate across multiple engineering teams, and communicate effectively with leadership. Experience in cloud security, DevSecOps, security automation, and modern security practices is highly desirable."All qualified applicants will be considered without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status."