Engineer III, Vulnerability Management

MWI Animal Health

Philadelphia, Northern (Philadelphia County, KY)

Hybrid

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

MWI Animal Health is seeking an Engineer III - Vulnerability Management to lead advanced vulnerability analysis across enterprise environments including infrastructure, cloud, endpoints, and applications. You will help mature CTEM, optimize attack surface and external posture management, and drive risk-based remediation with cross-functional teams.

You will create dashboards and reports, translate findings into remediation guidance, and mentor junior staff as part of the Vulnerability and

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Engineering, or a related field, or equivalent practical experience.
  • 7-10+ years of combined IT and security experience.
  • At least 4 years in vulnerability/exposure/attack surface management and related functions.
  • Active cybersecurity certification such as CISSP, CISM, Security+, CySA+, GSEC, CCSP, OSCP or similar.

Responsibilities

  • Perform advanced vulnerability analysis across infrastructure, cloud, endpoints, networks, applications, SaaS, and externally facing assets.
  • Lead and support CTEM processes including scoping, discovery, prioritization, validation, mobilization, and ongoing risk reduction.
  • Operate and improve vulnerability management, attack surface management, external posture management, and cloud/SaaS posture capabilities.
  • Analyze vulnerability data from multiple sources, normalize findings, and develop risk-based remediation priorities.
  • Drive remediation with cross-functional teams and track governance and reporting.
  • Create dashboards, metrics, and reporting for vulnerability trends and program maturity.
  • Mentor junior engineers and analysts in vulnerability triage and remediation governance.

Skills

Cybersecurity concepts
Vulnerability management
CTEM coordination
Data analysis
Stakeholder management

Education

Bachelor’s degree in Cybersecurity/CS/IT/Engineering

Tools

Qualys
Tenable
Rapid7 InsightVM
Microsoft Defender Vulnerability Management
Wiz
Armis

Job description

# **Job Details****Job Summary**The Engineer III - Vulnerability Management is a senior technical contributor responsible for identifying, analyzing, prioritizing, reporting, and driving remediation of vulnerabilities and posture findings across enterprise environments. This role supports and helps mature a unified, risk-based Vulnerability and Posture Management capability spanning infrastructure, endpoints, cloud workloads, network devices, applications, SaaS platforms, external attack surface, and other critical assets. The Engineer III will help lead Continuous Threat Exposure Management (CTEM) activities, operate and optimize attack surface management and vulnerability management tools, and partner with technology, security, and business stakeholders to measurably reduce cyber risk.**Primary Responsibilities*** Perform advanced vulnerability analysis across infrastructure, cloud, endpoint, network, application, SaaS, and externally facing assets.* Lead and support Continuous Threat Exposure Management (CTEM) processes, including scoping, discovery, prioritization, validation, mobilization, and ongoing risk reduction activities.* Operate and improve vulnerability management, attack surface management, external posture management, cloud posture and SaaS posture capabilities.* Analyze vulnerability and posture data from multiple sources, normalize findings, and develop actionable risk-based remediation priorities.* Assess vulnerabilities using business context, asset criticality, exploitability, threat intelligence, exposure, compensating controls, and regulatory or compliance impact.* Drive remediation and risk treatment efforts with infrastructure, cloud, network, application, endpoint, DevOps, and business technology teams.* Lead emerging vulnerability and critical exposure response activities, including impact analysis, stakeholder coordination, mitigation tracking, and executive-level status reporting.* Create and maintain dashboards, metrics, and reporting for vulnerability trends, remediation progress, SLA performance, exposure reduction, attack surface changes, and program maturity.* Support implementation and optimization of unified vulnerability management workflows, including ticketing, ownership assignment, exception handling, rescan validation, remediation automation, and governance routines.* Evaluate and recommend improvements to scanning coverage, asset inventory quality, vulnerability data integrity, risk scoring, and stakeholder reporting.* Translate complex technical findings into clear remediation guidance for technical teams and concise risk summaries for leadership.* Contribute to security standards, procedures, playbooks, process documentation, and continuous improvement initiatives for the Vulnerability and Posture Management program.* Mentor junior engineers and analysts by providing technical guidance, quality review, and support for vulnerability triage and remediation governance.**Required Qualifications*** Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Engineering, or a related field, or equivalent practical experience.* 7-10 years of combined experience in information technology, cybersecurity, systems administration, cloud operations, network security, application security, security engineering, or related disciplines.* At least 4 years of hands-on experience in vulnerability management, exposure management, attack surface management, configuration assurance, or a closely related cybersecurity function.* At least one active cybersecurity certification, such as CISSP, CISM, Security+, CySA+, GSEC, CCSK, CCSP, OSCP, GIAC certification, or another recognized security certification.* Strong understanding of vulnerability lifecycle management, including discovery, validation, prioritization, remediation, exception handling, rescan validation, and reporting.* Experience using vulnerability assessment or vulnerability management platforms such as Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Wiz, Armis, or comparable tools.* Experience with attack surface, posture, or exposure management capabilities such as CAASM, EASM, RBVM, CSPM, SSPM, external posture management, or security ratings platforms.* Ability to interpret vulnerability findings, CVEs, CVSS, EPSS, threat intelligence, exploitability indicators, asset context, and compensating controls to prioritize risk.* Experience working with enterprise asset data, CMDB data, ownership models, assignment groups, and business criticality attributes.* Strong analytical skills with experience using Excel, Power BI, SQL, data lakes, reporting platforms, or other data analysis and visualization tools.* Working knowledge of common security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Critical Security Controls, PCI DSS, HIPAA, GDPR, OWASP Top 10, SANS Top 25, and MITRE ATT&CK.* Excellent written and verbal communication skills, with the ability to explain technical risk to both technical and non-technical audiences.* Demonstrated ability to coordinate cross-functional remediation activities in a complex enterprise environment.**Preferred Qualifications*** Experience helping build or mature a CTEM, exposure management, or unified risk-based vulnerability management program.* Experience with vulnerability workflow automation, ServiceNow SecOps, Jira, SOAR, or similar remediation workflow platforms.* Experience consolidating and normalizing vulnerability data across multiple source tools and integrating results into dashboards, remediation queues, or governance workflows.* Experience with cloud security and cloud posture management across AWS, Azure, Google Cloud, or hybrid environments.* Experience with external attack surface management, SaaS security posture management, configuration assurance, or third-party exposure management.* Experience supporting regulatory, audit, customer assurance, or compliance reporting related to vulnerability and exposure management.* Familiarity with scripting or automation using Python, PowerShell, APIs, or query languages to improve reporting, remediation tracking, and data quality.* Ability to influence without direct authority and lead cross-functional initiatives across technical teams, business stakeholders, and security leadership.**Tools and Technologies**The successful candidate should be comfortable working with a broad ecosystem of vulnerability, posture, exposure, and reporting technologies. Relevant tools may include vulnerability scanners, endpoint vulnerability platforms, cloud security posture tools, external attack surface management tools, SaaS posture tools, risk-based vulnerability management platforms, workflow automation solutions, SIEM or threat intelligence platforms, ServiceNow, Power BI, Excel, SQL, and data integration technologies.**Key Competencies*** Risk-based decision making and prioritization* Strong technical analysis and investigative discipline* Enterprise stakeholder management and cross-functional coordination* Clear communication of technical risk and business impact* Operational excellence, process improvement, and automation mindset* Data quality awareness and ability to reconcile conflicting tool outputs* Ownership, accountability, and ability to lead initiatives with limited direction* Ability to balance tactical remediation urgency with strategic program maturity**Success Measures*** Improved visibility and coverage across enterprise assets, including cloud, endpoint, network, application, SaaS, and externally exposed environments.* Reduced critical and high-risk vulnerability exposure through effective prioritization, remediation governance, and stakeholder engagement.* Improved mean time to remediate, vulnerability closure rate, and SLA adherence.* Increased adoption of risk-based vulnerability management and CTEM practices across security and technology teams.* Improved quality, consistency, and usability of vulnerability reporting, dashboards, ownership mapping, and remediation workflows.* Demonstrated progress in reducing attack surface risk and improving overall security posture.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Cyber Security Engineer, Exposure Management
Sr. Cyber Security Engineer, Exposure Management

Community Health Systems • United States

On-site
USD 120,000 - 150,000
Cybersecurity Engineer
Cybersecurity Engineer

TechWish • Walnut Creek (CA)

On-site
USD 140,000 - 190,000
Sr. Security Engineer
Sr. Security Engineer

HKS Inc • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 190,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Compunnel, Inc. • Irving (TX)

On-site
USD 100,000 - 130,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

PCI Professional Services • United States

On-site
USD 110,000 - 160,000
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

Hidden Jobs • United States

On-site
USD 110,000 - 160,000
Flexible spending account
Health savings account
Hybrid work flexibility
+1
Senior Cyber Intelligence Analyst
Senior Cyber Intelligence Analyst

State Employees' Credit Union • Raleigh (NC)

Hybrid
USD 150,000 - 190,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Interactive Resources • Jacksonville (FL)

On-site
USD 110,000 - 160,000
Sr. Cyber Security Engineer, Exposure Management
Sr. Cyber Security Engineer, Exposure Management

CHS Corporate • United States

On-site
USD 140,000 - 190,000
Sr. Cloud Security Engineer (Remote)
Sr. Cloud Security Engineer (Remote)

inspiracareers • Oak Brook (IL)

Hybrid
USD 160,000 - 190,000