Cybersecurity Engineer

TechWish

Walnut Creek (CA)

On-site

USD 140,000 - 190,000

Full time

24 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CSAA Insurance Group seeks a Senior Vulnerability Management Engineer to lead enterprise vulnerability coverage across on-premises, cloud, and hybrid environments. You will drive asset visibility, risk-based remediation, and exposure analysis, translating findings into actionable guidance for multiple technology teams.

The role emphasizes hands-on platform expertise, collaboration across security and IT teams, and continuous improvement of remediation workflows and data quality.

Qualifications

  • Five+ years in vulnerability management or related cybersecurity discipline.
  • Hands-on experience administering enterprise vulnerability management platforms, scanners, agents, policies, credentials, and integrations.
  • Experience designing and troubleshooting credentialed and unauthenticated vulnerability scans across Windows, Linux, network, and cloud environments.
  • Strong understanding of TCP/IP, DNS, routing, firewalls, load balancers, and network segmentation.
  • Ability to translate complex vulnerability and network information into actionable guidance for technical and non-technical stakeholders.

Responsibilities

  • Own and optimize enterprise vulnerability scanning across on-premises, cloud, endpoint, and network environments, including scanners, agents, scan policies, schedules, credentials, platform health, upgrades, and integrations.
  • Analyze scan coverage and troubleshoot gaps related to asset discovery, authentication, agent deployment, scanner placement, routing, firewall rules, network segmentation, and onboarding.
  • Maintain accurate vulnerability asset visibility by identifying unmanaged, duplicate, stale, or improperly classified assets and resolving asset-correlation and data-quality issues.
  • Develop and maintain asset tagging and classification strategies that support ownership, prioritization, reporting, and remediation workflows.
  • Analyze critical and high-risk vulnerabilities using exploitability, reachability, threat intelligence, asset criticality, internet exposure, compensating controls, and business context.
  • Identify vulnerabilities and assets requiring prioritized remediation and provide clear technical recommendations to infrastructure, network, cloud, database, application, and endpoint teams.
  • Support vulnerability triage, false-positive validation, assignment and ownership resolution, rescans, remediation verification, and recurring-issue analysis.
  • Maintain and improve integrations and workflows between Tenable, Wiz, ServiceNow Vulnerability Response, and other enterprise systems.
  • Contribute technical expertise to assignment rules, risk scoring, dashboards, metrics, reporting, and vulnerability workflow enhancements.
  • Develop or support automation using APIs, PowerShell, Python, or similar technologies, and document technical procedures and operational practices.

Skills

Analytical skills
Troubleshooting
Collaboration
Documentation
Communication

Education

Bachelor's degree in Cybersecurity, IT, CS, or Engineering

Tools

Tenable Vulnerability Management
Nessus
Nessus Agents
Wiz
ServiceNow Vulnerability Response

Job description

As a Senior Vulnerability Management Engineer, you will serve as a technical leader within CSAA Insurance Group's Cybersecurity organization, helping drive enterprise vulnerability management, asset visibility, exposure analysis, and remediation effectiveness across on-premises, cloud, and hybrid environments.

This role combines hands-on vulnerability management platform expertise with strong knowledge of network architecture, asset discovery, vulnerability analysis, and the end-to-end remediation lifecycle. You will ensure broad and reliable vulnerability coverage, identify visibility gaps, translate technical findings into actionable guidance, and partner with technology teams to focus remediation on the assets and vulnerabilities that present the greatest actual risk.

Your work
  • Own and optimize enterprise vulnerability scanning across on-premises, cloud, endpoint, and network environments, including scanners, agents, scan policies, schedules, credentials, platform health, upgrades, and integrations.
  • Analyze scan coverage and troubleshoot gaps related to asset discovery, authentication, agent deployment, scanner placement, routing, firewall rules, network segmentation, and onboarding.
  • Maintain accurate vulnerability asset visibility by identifying unmanaged, duplicate, stale, or improperly classified assets and resolving asset-correlation and data-quality issues.
  • Develop and maintain asset tagging and classification strategies that support ownership, prioritization, reporting, and remediation workflows.
  • Analyze critical and high-risk vulnerabilities using exploitability, reachability, threat intelligence, asset criticality, internet exposure, compensating controls, and business context.
  • Identify vulnerabilities and assets requiring prioritized remediation and provide clear technical recommendations to infrastructure, network, cloud, database, application, and endpoint teams.
  • Support vulnerability triage, false-positive validation, assignment and ownership resolution, rescans, remediation verification, and recurring-issue analysis.
  • Maintain and improve integrations and workflows between Tenable, Wiz, ServiceNow Vulnerability Response, and other enterprise systems.
  • Contribute technical expertise to assignment rules, risk scoring, dashboards, metrics, reporting, and vulnerability workflow enhancements.
  • Develop or support automation using APIs, PowerShell, Python, or similar technologies, and document technical procedures and operational practices.
  • Partner across technology and security teams to remove remediation blockers and continuously improve vulnerability coverage, data quality, prioritization, and remediation outcomes.
Required Experience, Education, And Skills
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent practical experience.
  • Five or more years of experience in vulnerability management, security engineering, infrastructure engineering, network engineering, or a related cybersecurity discipline.
  • Hands-on experience administering and optimizing enterprise vulnerability management platforms, scanners, agents, policies, credentials, and integrations.
  • Experience designing, operating, and troubleshooting credentialed and unauthenticated vulnerability scans across Windows, Linux, network, and cloud environments.
  • Strong understanding of TCP/IP, DNS, routing, firewalls, load balancers, network segmentation, authentication, and common enterprise infrastructure.
  • Experience analyzing vulnerability findings, validating false positives, prioritizing risk, and supporting remediation through closure.
  • Ability to translate complex vulnerability and network information into clear, actionable guidance for technical and non-technical stakeholders.
  • Strong analytical, troubleshooting, collaboration, documentation, and communication skills.
Preferred Experience And Skills
  • Experience with Tenable Vulnerability Management (not required), Nessus scanners, Nessus Agents, Wiz, and ServiceNow Vulnerability Response or Unified Security Exposure Management.
  • Experience with exposure management, attack-surface analysis, exploitability assessment, threat intelligence, and risk-based vulnerability prioritization.
  • Experience supporting AWS, Azure, hybrid cloud, virtualized, containerized, or epithelial infrastructure.
  • Experience integrating vulnerability platforms with ServiceNow, SIEM, privileged-access, asset-management, cloud, or automation technologies.
  • Experience developing automation with PowerShell, Python, REST APIs, Bash, Ansible, or similar technologies.
  • Relevant cybersecurity or vulnerability management certifications. Internal role intent: A senior, hands-on vulnerability management engineer who can own the technology, understand the network, validate actual exposure, and help drive findings from discovery through remediation.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

PCI Professional Services • United States

On-site
USD 110,000 - 160,000
Vulnerability Management Engineer (Tenable)
Vulnerability Management Engineer (Tenable)

Alluvial Concepts • Rockville (MD)

On-site
USD 120,000 - 180,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Fortis Industries, Inc. DBA - LTS, Inc. • Atmore (AL)

On-site
USD 100,000 - 140,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Compunnel, Inc. • Irving (TX)

On-site
USD 100,000 - 130,000
Tenable Vulnerability Management Engineer
Tenable Vulnerability Management Engineer

Symmetrio • Pennsylvania

Hybrid
USD 115,000 - 130,000
Health benefits
PTO
401(k) plan
Sr. Cyber Security Engineer, Exposure Management
Sr. Cyber Security Engineer, Exposure Management

Community Health Systems • United States

On-site
USD 120,000 - 150,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Interactive Resources • Jacksonville (FL)

On-site
USD 110,000 - 160,000
Senior Vulnerability Management Engineer – Exposure & Remediation
Senior Vulnerability Management Engineer – Exposure & Remediation

TechWish • Walnut Creek (CA)

On-site
USD 140,000 - 190,000
cybersecurity Analyst with vulnerability management
cybersecurity Analyst with vulnerability management

Themesoft Inc. • Burlington (MA)

On-site
USD 70,000 - 90,000
Info Security Analyst for Vulnerability Remediation - locals only
Info Security Analyst for Vulnerability Remediation - locals only

Value Innovation Labs • San Antonio (TX)

On-site
USD 90,000 - 120,000