As a Senior Vulnerability Management Engineer, you will serve as a technical leader within CSAA Insurance Group's Cybersecurity organization, helping drive enterprise vulnerability management, asset visibility, exposure analysis, and remediation effectiveness across on-premises, cloud, and hybrid environments.
This role combines hands-on vulnerability management platform expertise with strong knowledge of network architecture, asset discovery, vulnerability analysis, and the end-to-end remediation lifecycle. You will ensure broad and reliable vulnerability coverage, identify visibility gaps, translate technical findings into actionable guidance, and partner with technology teams to focus remediation on the assets and vulnerabilities that present the greatest actual risk.
Your work
- Own and optimize enterprise vulnerability scanning across on-premises, cloud, endpoint, and network environments, including scanners, agents, scan policies, schedules, credentials, platform health, upgrades, and integrations.
- Analyze scan coverage and troubleshoot gaps related to asset discovery, authentication, agent deployment, scanner placement, routing, firewall rules, network segmentation, and onboarding.
- Maintain accurate vulnerability asset visibility by identifying unmanaged, duplicate, stale, or improperly classified assets and resolving asset-correlation and data-quality issues.
- Develop and maintain asset tagging and classification strategies that support ownership, prioritization, reporting, and remediation workflows.
- Analyze critical and high-risk vulnerabilities using exploitability, reachability, threat intelligence, asset criticality, internet exposure, compensating controls, and business context.
- Identify vulnerabilities and assets requiring prioritized remediation and provide clear technical recommendations to infrastructure, network, cloud, database, application, and endpoint teams.
- Support vulnerability triage, false-positive validation, assignment and ownership resolution, rescans, remediation verification, and recurring-issue analysis.
- Maintain and improve integrations and workflows between Tenable, Wiz, ServiceNow Vulnerability Response, and other enterprise systems.
- Contribute technical expertise to assignment rules, risk scoring, dashboards, metrics, reporting, and vulnerability workflow enhancements.
- Develop or support automation using APIs, PowerShell, Python, or similar technologies, and document technical procedures and operational practices.
- Partner across technology and security teams to remove remediation blockers and continuously improve vulnerability coverage, data quality, prioritization, and remediation outcomes.
Required Experience, Education, And Skills
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent practical experience.
- Five or more years of experience in vulnerability management, security engineering, infrastructure engineering, network engineering, or a related cybersecurity discipline.
- Hands-on experience administering and optimizing enterprise vulnerability management platforms, scanners, agents, policies, credentials, and integrations.
- Experience designing, operating, and troubleshooting credentialed and unauthenticated vulnerability scans across Windows, Linux, network, and cloud environments.
- Strong understanding of TCP/IP, DNS, routing, firewalls, load balancers, network segmentation, authentication, and common enterprise infrastructure.
- Experience analyzing vulnerability findings, validating false positives, prioritizing risk, and supporting remediation through closure.
- Ability to translate complex vulnerability and network information into clear, actionable guidance for technical and non-technical stakeholders.
- Strong analytical, troubleshooting, collaboration, documentation, and communication skills.
Preferred Experience And Skills
- Experience with Tenable Vulnerability Management (not required), Nessus scanners, Nessus Agents, Wiz, and ServiceNow Vulnerability Response or Unified Security Exposure Management.
- Experience with exposure management, attack-surface analysis, exploitability assessment, threat intelligence, and risk-based vulnerability prioritization.
- Experience supporting AWS, Azure, hybrid cloud, virtualized, containerized, or epithelial infrastructure.
- Experience integrating vulnerability platforms with ServiceNow, SIEM, privileged-access, asset-management, cloud, or automation technologies.
- Experience developing automation with PowerShell, Python, REST APIs, Bash, Ansible, or similar technologies.
- Relevant cybersecurity or vulnerability management certifications. Internal role intent: A senior, hands-on vulnerability management engineer who can own the technology, understand the network, validate actual exposure, and help drive findings from discovery through remediation.