Operational Security Engineer

engineeringjobs.net, Inc.

United States

Remote

USD 100,000 - 170,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Premium medical package
Lunch Tickets
Bookster subscription
13th salary/yearly bonuses
Startup-mentality with international展
Flexible remote work

Job summary

Qualysoft, a Vienna-based software engineering company with global reach, seeks a Vulnerability Management and Security Compliance Specialist.

You will manage end-to-end vulnerability lifecycles, perform scans with Qualys, Tanium and PingCastle, and coordinate remediation with IT, security, and business teams.

The role requires strong analytical skills, scripting in Python/PowerShell, and experience with ELK, Power BI, and Power Query to produce security KPIs and dashboards.

Qualifications

  • Hands-on experience with vulnerability management and security compliance in complex enterprise environments.
  • Experience with Qualys, Tanium, and PingCastle.
  • Knowledge of ELK Stack, Power BI, and Power Query for security monitoring.
  • Strong understanding of security frameworks and standards including NIST, CIS Benchmarks, OWASP, ISO 27001, PTES, ISSAF, and OSSTMM.
  • Technical knowledge of Windows, Linux, Cloud, networking, infrastructure security, patch management, and system hardening.
  • Ability to perform detailed analysis of standard network protocols and security-related infrastructure behavior.
  • Scripting and automation skills using Python, PowerShell, and Regular Expressions (Regex).
  • Experience managing vulnerability remediation processes, including SLA tracking, risk assessment, exception management, and stakeholder coordination.
  • Ability to analyze technical vulnerabilities and translate findings into clear remediation actions for technical stakeholders.
  • Experience with Agile environments, project coordination, process design, and continuous improvement.
  • Strong analytical, organizational, and problem-solving skills with high attention to detail.
  • Strong communication and cross-functional collaboration skills.
  • Fluent French, both written and spoken, and a good command of English.

Responsibilities

  • Manage the end-to-end vulnerability and security compliance lifecycle, from scan preparation and execution to analysis, remediation tracking, and reporting.
  • Perform and analyze vulnerability and compliance scans using Qualys, Tanium, PingCastle, and related security tools.
  • Identify vulnerabilities, security weaknesses, configuration issues, and technical non-compliance across Windows, Linux, On-Premises, DMZ, and Cloud environments.
  • Coordinate remediation activities with infrastructure, security, application, and business teams, ensuring vulnerabilities are addressed within defined SLAs.
  • Validate security configurations, patch management, and infrastructure compliance against internal and industry security standards.
  • Define vulnerability ownership, provide remediation recommendations, maintain action plans, and eliminate remediation risks or delays.
  • Produce and maintain security KPIs, dashboards, and operational indicators using tools such as ELK Stack, Power BI, and Power Query.
  • Maintain and improve vulnerability scanning coverage across infrastructure and cloud environments.
  • Ensure operational availability and lifecycle management of vulnerability management platforms, including upgrades, patching, incident resolution, and maintenance.
  • Perform technical assessments and Proofs of Concept (PoCs) for new security capabilities and tooling improvements.
  • Monitor evolving security requirements and identify compliance gaps, proposing remediation and convergence plans.
  • Collaborate with Security, Governance, IT Risk Management, infrastructure, and business security teams on vulnerabilities, exceptions, and security impact assessments.
  • Maintain technical documentation, operational procedures, security guidelines, and contingency plans.
  • Continuously improve vulnerability management processes, automation, reporting, and security controls.

Skills

Vulnerability Management
Security Compliance
Operational Security
Qualys
Tanium
PingCastle
ELK Stack
Power BI
Power Query
Python
PowerShell
Regex
SLA tracking
Automation

Education

Bachelor's degree in CS/IT

Tools

Qualys
Tanium
PingCastle
ELK Stack
Power BI
Power Query
Python
PowerShell

Job description

About Qualysoft

25 years of experience in software engineering, established in Vienna, Austria

Active in Romania since 2007, with office in central Bucharest (Bd. Iancu de Hunedoara 54B)

Delivering End to End IT Consulting Services - From Team Augmentation and Dedicated Teams to Custom Software Development

We deliver scalable enterprise systems, intelligent automation frameworks, and digital transformation platforms

Cross-industry experience by sustaining global players in BSFI (Banking, financial services and insurance), Telecom,Retail & E-commerce, Energy and Utilities, Automotive, Manufacturing, Logitics, High Tech

Global Presence: Switzerland, Germany, Austria, Sweden, Hungary, Slovakia, Serbia, Romania, and Indonesia

International team of 500 software engineers

Strategic partnerships: Microsoft Cloud Certified Partner, Tricentis Solutions Partner in Test Automation and Test Management, Creatio Exclusive Partner, Doxee Implementation Partner

Powered by cutting-edge technologies: AI, Data & Analytics, Cloud, DevOps, IoT, and Test Automation.

Project beneficiaries ranging from large-scale enterprises to startups

Stable growth and revenue increase year over year, a resilient organisation in volatile IT market conditions

Quality-first mindset, culture of innovation, and long-term client partnerships

Global and local reach -- trusted by key industry players in Europe and the US

Responsibilities
  • Manage the end-to-end vulnerability and security compliance lifecycle, from scan preparation and execution to analysis, remediation tracking, and reporting.
  • Perform and analyze vulnerability and compliance scans using Qualys, Tanium, PingCastle, and related security tools.
  • Identify vulnerabilities, security weaknesses, configuration issues, and technical non-compliance across Windows, Linux, On-Premises, DMZ, and Cloud environments.
  • Coordinate remediation activities with infrastructure, security, application, and business teams, ensuring vulnerabilities are addressed within defined SLAs.
  • Validate security configurations, patch management, and infrastructure compliance against internal and industry security standards.
  • Define vulnerability ownership, provide remediation recommendations, maintain action plans, and eliminate remediation risks or delays.
  • Produce and maintain security KPIs, dashboards, and operational indicators using tools such as ELK Stack, Power BI, and Power Query.
  • Maintain and improve vulnerability scanning coverage across infrastructure and cloud environments.
  • Ensure operational availability and lifecycle management of vulnerability management platforms, including upgrades, patching, incident resolution, and maintenance.
  • Perform technical assessments and Proofs of Concept (PoCs) for new security capabilities and tooling improvements.
  • Monitor evolving security requirements and identify compliance gaps, proposing remediation and convergence plans.
  • Collaborate with Security, Governance, IT Risk Management, infrastructure, and business security teams on vulnerabilities, exceptions, and security impact assessments.
  • Maintain technical documentation, operational procedures, security guidelines, and contingency plans.
  • Continuously improve vulnerability management processes, automation, reporting, and security controls.
Qualifications

Strong experience in Vulnerability Management, Security Compliance, and Operational Security within complex enterprise environments.

  • Hands-on experience with Qualys and Tanium, including vulnerability, compliance, SelfAssessment, API, and Comply capabilities.
  • Experience with security assessment and compliance tools such as PingCastle.
  • Good knowledge of ELK Stack, Power BI, and Power Query for security monitoring, analysis, and reporting.
  • Strong understanding of security frameworks and standards including NIST, CIS Benchmarks, OWASP, ISO 27001, PTES, ISSAF, and OSSTMM.
  • Good technical knowledge of Windows, Linux, Cloud, networking, infrastructure security, patch management, and system hardening.
  • Ability to perform detailed analysis of standard network protocols and security-related infrastructure behavior.
  • Scripting and automation skills using Python, PowerShell, and Regular Expressions (Regex).
  • Experience managing vulnerability remediation processes, including SLA tracking, risk assessment, exception management, and stakeholder coordination.
  • Ability to analyze technical vulnerabilities and translate findings into clear remediation actions for technical stakeholders.
  • Experience with Agile environments, project coordination, process design, and continuous improvement.
  • Strong analytical, organizational, and problem-solving skills with high attention to detail.
  • Strong communication and cross-functional collaboration skills.
  • Fluent French, both written and spoken, and a good command of English.
What We Offer
  • Premium medical package
  • Lunch Tickets & Pluxee Card
  • Bookster subscription
  • 13th salary/yearly bonuses
  • Enterprise job security with a startup mentality (diverse & engaging environment, international exposure, flat hierarchy) under the stability of a secure multinational
  • A supportive culture (we value ownership, autonomy, and healthy work-life balance) with great colleagues, team events and activities
  • Flexible working program and openness to remote work
  • Collaborative mindset -- employees shape their own benefits, tools, team events and internal practices
  • Diverse opportunities in Software Development with international exposure
  • Flexibility to choose projects aligned with your career path and technical goals
  • Access to leading learning platforms, courses, and certifications (Pluralsight, Udemy, Microsoft, Google Cloud)
  • Career growth & learning -- mentorship programs, certifications, professional development opportunities, and above-market salary

We are an equal opportunity employer and value diversity. All employment decisions are made without regard to age, gender, disability, race, ethnicity, religion, sexual orientation, or any other protected characteristic. We encourage applicants from all backgrounds to apply.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Frontend Engineer
Senior Frontend Engineer

Remote Jobs • United States

Remote
USD 90,000 - 130,000
Premium medical package
Lunch Tickets
Bookster subscription
+4
Qualys Integration Engineer
Qualys Integration Engineer

UltraViolet Cyber • Washington, Northern (KY)

Hybrid
USD 90,000 - 115,000
401(k) match
Medical, Dental, Vision
Disability insurance
+2
Security Solutions Architect, Cloud Specialist
Security Solutions Architect, Cloud Specialist

Qualys • Denver (CO)

On-site
USD 165,000 - 195,000
Comprehensive benefits package
Security Solutions Architect, Cloud Specialist
Security Solutions Architect, Cloud Specialist

Qualys • Las Vegas (NV)

On-site
USD 165,000 - 195,000
Security Solutions Architect, Cloud Specialist
Security Solutions Architect, Cloud Specialist

Qualys • Salt Lake City (UT)

On-site
USD 165,000 - 195,000
Security Solutions Architect, Cloud Specialist
Security Solutions Architect, Cloud Specialist

Qualys • Phoenix (AZ)

On-site
USD 165,000 - 195,000
Comprehensive benefits package
Travel opportunities
Application Security Engineer
Application Security Engineer

Softswiss • Town of Poland (NY)

On-site
USD 120,000 - 150,000
Private health insurance
Sports benefits
Free English lessons (online)
+3
Engineering Manager, Information Security
Engineering Manager, Information Security

Qualia • Austin (TX)

On-site
USD 180,000 - 230,000
Health plans
401k
Commuter benefits
+6
Security Solutions Architect
Security Solutions Architect

Qualys • Netherlands (MO)

On-site
USD 100,000 - 130,000
Cyber Security Architect
Cyber Security Architect

Qualco Group • Kentucky

On-site
USD 120,000 - 180,000
Competitive compensation
Private health insurance
Flexible working model
+4