Summary
✨ AI‑Generated
A cybersecurity team is seeking an engineer to strengthen vulnerability management programs across cloud, endpoints, networks, and applications. The role involves detection, prioritization, reporting, and remediation of security risks.
Highlights
Contract role focused on enterprise cybersecurity, risk reduction, vulnerability detection, and security operations improvement.
Description
Position: Vulnerability Management Engineer
Type: 12 Month Contract
Location: Seattle WA - Hybrid
**Purpose:** Advance the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate.
### Responsibilities
**Detect**
- Maintain and expand scan and sensor coverage across endpoints, servers, cloud workloads, containers, network devices, and SaaS
- Close asset visibility gaps, including shadow IT, unmanaged devices, and assets provisioned outside IT
- Tune authenticated scanning, credential health, agent health, and scan cadence to reduce false negatives
- Reconcile vulnerability data across multiple sources into a single authoritative inventory
**Prioritize**
- Build and operate risk-based prioritization that blends CVSS severity, EPSS likelihood, CISA KEV exploitation status, and SSVC decision logic
- Enrich findings with business context: asset criticality, data classification, internet exposure, compensating controls, application owner, and business unit
- Replace severity-only queues with defensible, tiered remediation SLAs
- Operate the exception and risk acceptance workflow, including expiration and re-review
**Report**
- Design and publish program metrics: coverage, mean time to remediate by tier, backlog aging, SLA compliance, and burndown
- Deliver executive and operational dashboards, including Power BI reporting fed by automated pipelines
- Produce audit and assurance evidence on request
- Translate technical findings into business risk language for non-technical stakeholders
**Remediate**
- Drive remediation campaigns in partnership with IT operations, endpoint, cloud, and application teams
- Automate ticket creation, routing, and closure into the ITSM platform
- Perform closed-loop verification that remediation actually reduced exposure
- Support emergency response for actively exploited vulnerabilities
**Platform and program**
- Direct, hands-on experience implementing or migrating to a new enterprise vulnerability management platform, including requirements definition, proof of concept, integration, data migration, and rollout
- Direct experience driving continuous improvement to an established VM program, including maturity assessment, process redesign, and runbook development
### Required Qualifications
- 5+ years hands-on vulnerability management or security engineering
- Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium)
- Demonstrated experience building prioritization models that incorporate business context, not severity alone
- Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration
- Working fluency with KQL or an equivalent query language for security data
- Experience integrating VM data with CMDB, ITSM, and BI platforms
- Cloud vulnerability management experience across Azure and at least one other provider
- Ability to work independently and produce written deliverables without heavy oversight
### Preferred
- Experience with Tanium and Microsoft Defender for Endpoint as data sources
- Container and image scanning experience
- Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns
- Exposure to CTEM or exposure management program models
- Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500