Cybersecurity Engineer - Vulnerability Management

Jane Street Group, LLC

Northern, New York (KY, NY)

Hybrid

USD 225,000 - 300,000

Full time

39 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Jane Street is seeking a Cybersecurity Engineer to mature our vulnerability management program. This hands-on, build-heavy role focuses on automation, triage, remediation tracking, and measurement across the vulnerability lifecycle.

You will work with Rapid7, Tenable, and Qualys, build dashboards, and ensure scalable security while communicating risk and trade-offs to stakeholders. Base salary ranges from $225,000 to $300,000 with discretionary bonus.

Qualifications

  • Hands-on vulnerability management experience in a substantial environment.
  • Experience with automated scanning platforms such as Rapid7, Tenable, or Qualys.
  • Ability to reason about risk, trade-offs, and remediation prioritization.
  • Ability to build and maintain data pipelines and dashboards for security metrics.

Responsibilities

  • Support and improve the vulnerability management lifecycle end to end.
  • Review findings from automated scanners and prioritize based on real exploitability.
  • Validate and deduplicate findings across sources and route to fixes.
  • Measure coverage, data quality, and identify gaps in scanning.
  • Drive automation across vulnerability management tooling and processes.
  • Broaden scanning coverage across asset classes and SBOM data integration.

Skills

Automation
Data analysis
Communication

Tools

Rapid7
Tenable
Qualys
SBOM tooling

Job description

Cybersecurity Engineer - Vulnerability Management

We're looking for a Cybersecurity Engineer to help us mature our vulnerability management program. You'll join our Cybersecurity team, a skilled group of programmers and security experts dedicated to keeping the firm safe.

Vulnerability management is the focus of this role, but it doesn't tell the whole story—we want a well-rounded engineer whose knowledge spans the different facets of cybersecurity, because that broader perspective is what lets you reason well about real risk and where to spend effort.

Vulnerability management is a well-established part of how we keep the firm safe, and as we grow, we're continuing to invest in it, with a particular focus on automation and on scaling the program to keep pace with an expanding environment.

This is a hands-on, build-heavy role. We want someone with a strong technical foundation who isn't afraid to build something themselves, who has good judgment about what actually matters, and who can explain the "why" behind a risk and its mitigation. Manual triage doesn't scale at our size, so you'll lean on automation, including AI tooling paired with good judgment, knowing where it helps and when we need a human in the loop.

Your work will also include:

  • Supporting and improving the vulnerability management lifecycle end to end, from discovery and validation through triage, assignment, remediation tracking, and verification
  • Reviewing new findings from automated scanning tools, threat intel, and security advisories, then prioritizing based on real exploitability and exposure rather than severity score alone, so we act on what genuinely matters
  • Validating and deduplicating findings across sources, confirming whether an affected product or component is actually present, and routing work to the team that owns the fix
  • Measuring scanning coverage and data quality and knowing what isn't being scanned, where scans are stale, and where authentication is failing, rather than assuming coverage is complete
  • Driving automation across vulnerability management tooling and processes
  • Broadening scanning coverage across asset classes, including evaluating and migrating scanning platforms as needed
  • Bringing software inventory and SBOM data into the picture so we can answer where a vulnerable component is used across our software, not just what's running on a given host
  • Building dashboards and metrics that measure coverage, SLAs, and progress
About You
  • You automate rather than do things by hand, keep your code and configs in version control by default, work comfortably under code review, and care about leaving things maintainable
  • You’re comfortable working with data, querying and shaping it, and building and debugging the data pipelines and integrations that stitch messy, inconsistent inputs into something dependable
  • You have hands-on vulnerability management experience in a substantial environment, including experience with an automated scanning platform such as Rapid7, Tenable, or Qualys, and an understanding of how scanning, asset inventory, and remediation tracking fit together
  • You’re a measured responder who reasons about trade-offs and context, understands threat modeling, and knows not every finding deserves the same urgency
  • You follow cybersecurity developments and can tell the difference between an interesting hack and what matters day-to-day
  • You understand and practice good personal cybersecurity hygiene, and can talk to others about it
  • You’re a clear communicator across audiences, who writes things down so others can follow
  • You have a positive and collaborative attitude; You understand that a key component of cybersecurity is bringing others along with you on the journey

Base salary is $225,000 - $300,000. Base salary is only one part of Jane Street total compensation, which includes an annual discretionary bonus.

Jane Street is an Equal Opportunity Employer

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer: Vulnerability Management & Automation
Cybersecurity Engineer: Vulnerability Management & Automation

Jane Street Group, LLC • Northern (KY), New York (NY)

Hybrid
USD 225,000 - 300,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Group 1001 • United States

On-site
USD 190,000 - 230,000
Cybersecurity Engineer
Cybersecurity Engineer

Jane Street Group, LLC • Northern (KY), New York (NY)

Hybrid
USD 225,000 - 300,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

United States Digital Space LLC • Seattle (WA), San Francisco (CA)

On-site
USD 110,000 - 150,000
Vulnerability Management Manager
Vulnerability Management Manager

Considine Search • New York (NY)

On-site
USD 200,000 - 215,000
Manager, Vulnerability Management
Manager, Vulnerability Management

Optimum • Norwalk (CT)

On-site
USD 133,000 - 220,000
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation

New York Life • New York (NY)

On-site
USD 147,500 - 211,000
IT Security Engineer
IT Security Engineer

Jane Street Group, LLC • Northern (KY), New York (NY)

Hybrid
USD 175,000 - 250,000
Vulnerability Analyst — External Attack Surface & VDP
Vulnerability Analyst — External Attack Surface & VDP

Vanguard • Malvern

Hybrid
USD 80,000 - 110,000
Growth pathways in security roles
Hybrid working model
Cyber Security Vulnerability Management Specialist - Associate
Cyber Security Vulnerability Management Specialist - Associate

Socket.dev • Salt Lake City (UT)

Hybrid
USD 70,000 - 90,000
Annual performance bonus
Employer matched retirement plan
Dental coverage
+5