Senior Security Engineer (Vulnerability Management)
Vaco is hiring a Senior Security Engineer for a contract opportunity with a leading enterprise client. This role will join the Vulnerability Management team and play a key role in helping technology teams identify, prioritize, and remediate security vulnerabilities across complex environments. The ideal candidate brings deep vulnerability management expertise, strong technical communication skills, and the ability to work independently with minimal ramp-up time.
Location: Remote or Hybrid (must work EST hours)
Duration: 6+ month contract with strong extension potential
Openings: 2
What You’ll Do
- Support the full vulnerability management lifecycle, from identification and assessment through remediation and tracking.
- Administer and support vulnerability scanning platforms, including Tenable Security Center.
- Analyze security findings and assess risk across applications, infrastructure, cloud environments, and operating systems.
- Develop remediation recommendations and compensating controls when vulnerabilities cannot be fully remediated.
- Partner with application owners, infrastructure teams, and security stakeholders to prioritize and coordinate remediation efforts.
- Create clear technical documentation and remediation guidance.
- Support the ingestion, analysis, and management of security findings within vulnerability management platforms such as Brinqa.
- Assist with vulnerability management efforts across Windows, Linux, cloud, and operational technology (OT) environments.
- Ensure vulnerability management activities align with compliance requirements including PCI, HIPAA, and SOX.
- Stay current on emerging threats, vulnerabilities, and industry best practices.
Required Qualifications
- 5+ years of cybersecurity experience with a strong focus on vulnerability management.
- Deep understanding of the vulnerability management lifecycle and risk-based remediation strategies.
- Hands‑on experience with Tenable vulnerability scanning tools, including Tenable Security Center.
- Experience evaluating security findings and developing actionable remediation guidance.
- Working knowledge of Windows and Linux operating systems.
- Strong written communication and documentation skills.
- Ability to explain complex security risks and findings to technical teams and business stakeholders.
- Proven ability to coordinate security initiatives across multiple teams.
Preferred Qualifications
- Experience with Azure and GCP cloud environments.
- Knowledge of PCI, HIPAA, and SOX compliance requirements.
- Familiarity with scripting languages such as Python, Perl, Ruby, or shell scripting.
- Experience with Brinqa or similar vulnerability management platforms.
- Exposure to Operational Technology (OT) security and vulnerability management.
Ideal Background
We're looking for a senior-level security professional with experience supporting vulnerability or exposure management programs in large, complex enterprise environments. The right candidate can quickly ramp up, operate independently, and effectively partner with application and infrastructure teams to reduce organizational risk.