{"schemaVersion":"jobsearcher.job.v1","id":"cb4e27f911f2a88972fffd84","url":"https://jobsearcher.com/jobs/cb4e27f911f2a88972fffd84","canonicalUrl":"https://jobsearcher.com/jobs/cb4e27f911f2a88972fffd84","title":"Mid-Level Vulnerability Management Engineer","description":"Description:\n\nK2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.\nOur four core values define how we show up every day:\nRespect Others - We lead with respect, building trust and connection.\nInternally Driven - We are relentlessly compelled to accomplish our objectives.\nCollaborative Innovation - We create by listening, sharing, and working together.\nClient Success - We hold our clients' mission as our own.\nWe believe in people who are accountable, curious, and motivated to make an impact that matters.\nOur programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.\nK2Share is seeking a Vulnerability Management Engineer to support a federal health-sector client. In this role, you will lead the identification, analysis, communication, and remediation of vulnerabilities across client-managed systems, devices, and software. You will help reduce operational risk through proactive scanning, disciplined reporting, and close coordination with technical stakeholders across the enterprise.\nThis position supports a large enterprise environment under continuous vulnerability management, including recurring host and application scanning and additional targeted assessments as needed.\nAbout You\nYou are a hands-on vulnerability management professional who understands that effective security work is not just about finding issues. It is about helping organizations act on them quickly and effectively. You are comfortable operating scanning infrastructure, analyzing results, and working with system owners to drive remediation across complex hybrid environments.\nYou know how to balance urgency with rigor. You can identify the highest-risk issues, communicate them clearly, and track them through resolution in accordance with federal policy and operational timelines. You are also comfortable working across technical teams and government stakeholders, bringing structure to ambiguous problems and helping mature an enterprise vulnerability-management program over time.\nYou thrive in a role where your work directly improves the security posture of mission-critical systems. You are detail-oriented, collaborative, and able to move from technical analysis to actionable guidance without losing sight of the larger risk picture.\nYour Impact\nAs the Vulnerability Management Engineer, you will play a central role in strengthening the client's cyber defense posture. You will operate the vulnerability-management function, support enterprise scanning and remediation workflows, and help ensure vulnerabilities are identified, prioritized, and addressed in a timely and compliant manner.\nIn this role, you will:\nManage, operate, and maintain vulnerability-management infrastructure capable of performing credentialed scans across approved client-managed managed systems, devices, and applications.\nPerform host-based, network-based, application, and database vulnerability scanning and deliver actionable remediation guidance.\nAnalyze scan results and network architecture to identify the highest-risk vulnerabilities and recommend appropriate mitigation steps.\nConduct specialized assessments for High Value Assets (HVAs) and other designated systems, ensuring reports meet HVA requirements.\nSupport the implementation, operation, and maintenance of vulnerability-management projects within client's Information Security Project Dashboard.\nAlert technical points of contact to risks posed by vulnerabilities, missing assets, configuration errors, and unauthorized software or hardware.\nEscalate critical vulnerabilities within 24 hours and track remediation to closure in accordance with applicable federal, department, and agency policy and contractual remediation timelines.\nMonitor the CISA Known Exploited Vulnerabilities (KEV) Catalog and other authoritative sources to support timely remediation and compliance with applicable Binding Operational Directives.\nCoordinate with program areas and system owners to prioritize mitigation steps, including end-user mitigation activities when needed.\nProvide risk analysis for identified vulnerabilities and system change requests.\nDrive findings to verified closure through ticketed workflows, coordinating with the separate technical teams that perform system patching, and validate remediation through authenticated re-scans with recorded evidence.\nMaintain regular communication with client and department stakeholders to support collaboration, process improvement, tool tuning, information sharing, and compromise response.\nMonitor government and private-sector vulnerability sources to identify emerging risks that may affect client-managed systems.\nContribute to vulnerability management reporting and ad hoc compliance deliverables supporting department, DHS, and FISMA requirements.\nRequirements:\n\nBachelor's degree in a related field, or equivalent experience as allowed by company and contract policy.\nFive or more years of hands-on enterprise vulnerability management and scanning experience.\nExperience administering enterprise scanning platforms such as Tenable.sc, Nessus, Qualys, Rapid7, or similar tools.\nExperience performing credentialed scanning at scale across hybrid environments.\nExperience with host-based, network-based, application, and database vulnerability scanning.\nDirect experience tracking and remediating vulnerabilities against the CISA KEV Catalog and CISA Binding Operational Directives 22-01 and 26-04, successor directives.\nFamiliarity with High Value Asset (HVA) assessment requirements.\nWorking knowledge of NIST SP 800-53 Rev. 5, FISMA, and FIPS 199.\nStrong analytical, organizational, and communication skills with the ability to work effectively across technical and government stakeholders.\nAbility to meet federal background investigation requirements.\nPreferred Qualifications\nActive certification such as CISSP, GIAC (GWAPT, GPEN, GCIA), CompTIA Security+/CySA+, or vendor certifications for Tenable or Qualys.\nExperience with cloud vulnerability scanning in AWS and/or Azure.\nScripting or automation experience using Python, PowerShell, or similar tools.\nPrior support to federal civilian agency cybersecurity programs.\nBenefits\nWe're invested in the people who make our success possible. As a K2United employee, you'll enjoy a comprehensive benefits package designed to support your professional and personal well-being, including:\n401(k) with employer matching\nLow-cost medical coverage for employees and their families\nPaid time off\nPaid leave for jury duty, military service, voting, and other qualifying events\nWellness stipend, including fitness reimbursement\nTuition assistance\nCasual work environment\nTechnical training and certification support\nComplimentary access to CareerSafe online training courses for employees and their immediate family\nEqual Opportunity Employer\nK2United is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status, or any other characteristic protected by applicable law.","company":"K2share","rawCompany":"k2share","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-15T13:16:53.265Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Mid-Level Vulnerability Management Engineer","description":"Description:\n\nK2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.\nOur four core values define how we show up every day:\nRespect Others - We lead with respect, building trust and connection.\nInternally Driven - We are relentlessly compelled to accomplish our objectives.\nCollaborative Innovation - We create by listening, sharing, and working together.\nClient Success - We hold our clients' mission as our own.\nWe believe in people who are accountable, curious, and motivated to make an impact that matters.\nOur programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.\nK2Share is seeking a Vulnerability Management Engineer to support a federal health-sector client. In this role, you will lead the identification, analysis, communication, and remediation of vulnerabilities across client-managed systems, devices, and software. You will help reduce operational risk through proactive scanning, disciplined reporting, and close coordination with technical stakeholders across the enterprise.\nThis position supports a large enterprise environment under continuous vulnerability management, including recurring host and application scanning and additional targeted assessments as needed.\nAbout You\nYou are a hands-on vulnerability management professional who understands that effective security work is not just about finding issues. It is about helping organizations act on them quickly and effectively. You are comfortable operating scanning infrastructure, analyzing results, and working with system owners to drive remediation across complex hybrid environments.\nYou know how to balance urgency with rigor. You can identify the highest-risk issues, communicate them clearly, and track them through resolution in accordance with federal policy and operational timelines. You are also comfortable working across technical teams and government stakeholders, bringing structure to ambiguous problems and helping mature an enterprise vulnerability-management program over time.\nYou thrive in a role where your work directly improves the security posture of mission-critical systems. You are detail-oriented, collaborative, and able to move from technical analysis to actionable guidance without losing sight of the larger risk picture.\nYour Impact\nAs the Vulnerability Management Engineer, you will play a central role in strengthening the client's cyber defense posture. You will operate the vulnerability-management function, support enterprise scanning and remediation workflows, and help ensure vulnerabilities are identified, prioritized, and addressed in a timely and compliant manner.\nIn this role, you will:\nManage, operate, and maintain vulnerability-management infrastructure capable of performing credentialed scans across approved client-managed managed systems, devices, and applications.\nPerform host-based, network-based, application, and database vulnerability scanning and deliver actionable remediation guidance.\nAnalyze scan results and network architecture to identify the highest-risk vulnerabilities and recommend appropriate mitigation steps.\nConduct specialized assessments for High Value Assets (HVAs) and other designated systems, ensuring reports meet HVA requirements.\nSupport the implementation, operation, and maintenance of vulnerability-management projects within client's Information Security Project Dashboard.\nAlert technical points of contact to risks posed by vulnerabilities, missing assets, configuration errors, and unauthorized software or hardware.\nEscalate critical vulnerabilities within 24 hours and track remediation to closure in accordance with applicable federal, department, and agency policy and contractual remediation timelines.\nMonitor the CISA Known Exploited Vulnerabilities (KEV) Catalog and other authoritative sources to support timely remediation and compliance with applicable Binding Operational Directives.\nCoordinate with program areas and system owners to prioritize mitigation steps, including end-user mitigation activities when needed.\nProvide risk analysis for identified vulnerabilities and system change requests.\nDrive findings to verified closure through ticketed workflows, coordinating with the separate technical teams that perform system patching, and validate remediation through authenticated re-scans with recorded evidence.\nMaintain regular communication with client and department stakeholders to support collaboration, process improvement, tool tuning, information sharing, and compromise response.\nMonitor government and private-sector vulnerability sources to identify emerging risks that may affect client-managed systems.\nContribute to vulnerability management reporting and ad hoc compliance deliverables supporting department, DHS, and FISMA requirements.\nRequirements:\n\nBachelor's degree in a related field, or equivalent experience as allowed by company and contract policy.\nFive or more years of hands-on enterprise vulnerability management and scanning experience.\nExperience administering enterprise scanning platforms such as Tenable.sc, Nessus, Qualys, Rapid7, or similar tools.\nExperience performing credentialed scanning at scale across hybrid environments.\nExperience with host-based, network-based, application, and database vulnerability scanning.\nDirect experience tracking and remediating vulnerabilities against the CISA KEV Catalog and CISA Binding Operational Directives 22-01 and 26-04, successor directives.\nFamiliarity with High Value Asset (HVA) assessment requirements.\nWorking knowledge of NIST SP 800-53 Rev. 5, FISMA, and FIPS 199.\nStrong analytical, organizational, and communication skills with the ability to work effectively across technical and government stakeholders.\nAbility to meet federal background investigation requirements.\nPreferred Qualifications\nActive certification such as CISSP, GIAC (GWAPT, GPEN, GCIA), CompTIA Security+/CySA+, or vendor certifications for Tenable or Qualys.\nExperience with cloud vulnerability scanning in AWS and/or Azure.\nScripting or automation experience using Python, PowerShell, or similar tools.\nPrior support to federal civilian agency cybersecurity programs.\nBenefits\nWe're invested in the people who make our success possible. As a K2United employee, you'll enjoy a comprehensive benefits package designed to support your professional and personal well-being, including:\n401(k) with employer matching\nLow-cost medical coverage for employees and their families\nPaid time off\nPaid leave for jury duty, military service, voting, and other qualifying events\nWellness stipend, including fitness reimbursement\nTuition assistance\nCasual work environment\nTechnical training and certification support\nComplimentary access to CareerSafe online training courses for employees and their immediate family\nEqual Opportunity Employer\nK2United is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status, or any other characteristic protected by applicable law.","datePosted":"2026-08-15T13:16:53.265Z","dateModified":"2026-08-15T13:16:53.265Z","hiringOrganization":{"@type":"Organization","name":"K2share","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"cb4e27f911f2a88972fffd84"},"url":"https://jobsearcher.com/jobs/cb4e27f911f2a88972fffd84"}}