Security Engineer - Vulnerability & Exposure Management

Alivia Health, LLC

Ayer, Northern (MA, KY)

Hybrid

USD 110,000 - 140,000

Full time

31 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Alivia Health, LLC is seeking a Security Engineer to own vulnerability and exposure management across on‑prem, cloud, and endpoint environments supporting ePHI and clinical operations. You will build automation, integrations, and risk-based remediation programs, coordinating with IT Operations, Compliance, and clinical teams.

The role emphasizes cloud posture and the use of Rapid7 and Microsoft Defender for vulnerability management, with strong PowerShell or Python scripting and API integration

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, or a related field.

Responsibilities

  • Own vulnerability and exposure management lifecycle end to end across servers, endpoints, network, and cloud assets.
  • Define remediation standards, SLAs, and risk-acceptance with Cybersecurity leadership.
  • Perform risk-based prioritization using exploitability, asset criticality, and data sensitivity.
  • Coordinate remediation across IT ops, applications, governance, and clinical teams; report to leadership.
  • Design, build, and maintain security integrations between platforms via APIs.
  • Develop automation across exposure lifecycle: discovery, enrichment, ticketing, remediation, and reporting.
  • Support audits and regulatory requirements (HIPAA, NIST 800-53).

Skills

Strong communication
Cross-team collaboration
Risk-based prioritization

Education

Bachelor's degree in IT/CS or related

Tools

PowerShell
Python
API integrations
Azure

Job description

Security Engineer - Vulnerability & Exposure Management

Information Technology

Role summary

The Security Engineer, Vulnerability and Exposure Management, owns the operation, engineering, and continuous improvement of the organization's vulnerability and exposure management program. The role is accountable for reducing exposure to threats before they can be exploited across servers, endpoints, network, and cloud environments supporting ePHI, pharmacy, and clinical operations, advancing the program from periodic scanning toward continuous exposure management across vulnerabilities, misconfigurations, cloud posture, and external attack surface.

This is a specialized, engineering-oriented role. Beyond operating the program, the engineer builds the automation and system integrations that allow a small security function to scale its coverage and supports the organization's cloud security posture work. As the subject matter expert on exposure risk, the engineer coordinates remediation across systems, working with IT Operations, Applications, Data Governance, Compliance, clinical and pharmacy operations, and external vendors, and translates technical exposure into business and patient-safety risk for leadership.

Key responsibilities

Program ownership and risk decisions

  • Own the vulnerability and exposure management lifecycle end to end across servers, endpoints, network, and cloud assets supporting ePHI and clinical operations, from discovery and scanning through prioritization, remediation, validation, and reporting.
  • Define and maintain remediation standards, service levels, and the exception and risk-acceptance process, in coordination with the Director of Cybersecurity and Compliance.
  • Determine risk-based prioritization using exploitability, asset criticality, data sensitivity, and business context, and perform attack path analysis to identify how individual exposures chain into routes toward critical systems and data.
  • Determine when compensating controls are appropriate in place of full remediation, and document residual risk for acceptance by the appropriate owner.

Security engineering, automation, and integration

  • Design, build, and maintain integrations between security and IT platforms using their APIs, connecting vulnerability management, endpoint security, identity, and workflow and ticketing systems so data and actions flow without manual handoff.
  • Develop automation across the exposure lifecycle, including asset discovery, finding enrichment, ticket creation and assignment, remediation verification, and closure, and build reporting pipelines that produce metrics on a sustained basis rather than through periodic manual compilation.
  • Explore cloud-native services to host automation and internal tooling, applying source control, testing, peer review, and documentation so tooling remains maintainable, and establish reusable engineering patterns that can be adopted across the other security domains.
  • Extend exposure management into the organization's cloud environment, identifying misconfigurations, insecure service configuration, and internet-facing exposure across Azure workloads.
  • Assess cloud network and identity configuration from a security perspective, including segmentation, routing, network security groups, ingress and egress paths, private connectivity, file transfer services, managed identities, service principals, and least-privilege role scoping.
  • Review cloud services adopted by the business for secure configuration, advise project teams on secure design, and contribute to the definition of a cloud security baseline and guardrails in partnership with IT and Data Governance.

Coordination, reporting, and compliance

  • Serve as the primary point of contact for vulnerability and exposure risk across the organization, coordinating with IT Operations, Help Desk, Applications, Data Governance, and business and clinical system owners, and driving patching and secure configuration to closure.
  • Advise project teams and solution owners on exposure risk during the evaluation of new systems and infrastructure, and collaborate with the detection and response and identity functions on threat-informed prioritization and identity-related exposure.
  • Develop and present vulnerability and exposure metrics, baselines, and risk reporting to IT leadership, governance committees, and Compliance, translating technical findings into business and patient-safety risk terms.
  • Support internal and external audits and accreditation activities, including OCR, CMS, URAC, and NCQA, and maintain program documentation, runbooks, and remediation records aligned with the HIPAA Security Rule, NIST 800-40, and NIST 800-53.
  • Ensures compliance with all applicable regulatory, legal, and accreditation requirements, and internal policies and procedures. Participates in internal control documentation, testing, and remediation activities as required. Maintains ongoing awareness of compliance obligations and supports audit processes to uphold operational integrity and accountability across all functions.
  • Completes all mandatory and role-specific training requirements within established deadlines, in accordance with applicable regulatory, legal, and accreditation standards, and internal organizational policies. Maintains required certifications and participates in continuing education to ensure ongoing competence and compliance with industry best practices.

Growth roadmap

The position carries a defined progression as capability is demonstrated, advancing toward senior-level ownership of the exposure management program.

  • Independently owning the full exposure lifecycle across on-premises, cloud, and external attack surface.
  • Building and maintaining automation and integrations that materially reduce manual effort and time to remediation.
  • Extending cloud security coverage into posture management, entitlement review, and secure architecture advisory.
  • Leading validation activities, including penetration test scoping and remediation strategy.
  • Setting prioritization strategy and influencing remediation planning across IT and business functions.
  • Mentoring peers and establishing engineering practices adopted across the other security domains.

Required experience and competencies

  • Bachelor's degree in Information Technology, Computer Science, or a related field, or a minimum of 75 approved credits and equivalent progressive experience in the field.
  • Three or more years of combined experience in IT infrastructure, systems administration, or security, including hands-on exposure to vulnerability management or security operations.
  • Infrastructure and networking foundation, including server administration, networking and routing, firewalls, and directory services, with the ability to reason about how systems are exposed.
  • Demonstrated scripting and automation capability with PowerShell or Python, and experience integrating systems through APIs.
  • Working knowledge of a major cloud platform, Azure preferred, including core services, networking, and identity concepts, with the ability to extend that knowledge into cloud security.
  • Experience with vulnerability management or endpoint security platforms and remediation workflows. Rapid7 and Microsoft Defender preferred.
  • Understanding of risk-based prioritization concepts, including CVSS, EPSS, and known exploited vulnerability sources.
  • Demonstrated ability to coordinate technical work across multiple teams and influence outcomes without direct authority, with strong written and verbal communication including presenting technical risk to leadership.
  • Understanding of healthcare compliance requirements, including HIPAA and HITECH, and their application to vulnerability and exposure management.
  • Relevant industry certifications such as CompTIA Security+, Linux+, or Microsoft security certifications are preferred. Willingness to pursue certification is expected.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Engineer III, Vulnerability Management
Engineer III, Vulnerability Management

MWI Animal Health • Philadelphia, Northern (KY)

Hybrid
USD 120,000 - 180,000
Sr. Security Engineer
Sr. Security Engineer

HKS, Inc. • Dallas (TX)

On-site
USD 90,000 - 130,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Fortis Industries, Inc. DBA - LTS, Inc. • Atmore (AL)

On-site
USD 100,000 - 140,000
AVP Solutions Architecture
AVP Solutions Architecture

ScionHealth Corporate Support Center • Louisville (KY)

On-site
USD 180,000 - 240,000
Sr. Security Engineer
Sr. Security Engineer

HKS, Inc • Dallas (TX)

On-site
USD 120,000 - 160,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

PCI Professional Services • United States

On-site
USD 110,000 - 160,000
Principal Vulnerability Management Engineer
Principal Vulnerability Management Engineer

Zscaler • United States

Hybrid
USD 150,000 - 190,000
Cybersecurity Engineer
Cybersecurity Engineer

TechWish • Walnut Creek (CA)

On-site
USD 140,000 - 190,000
Senior Security Engineer
Senior Security Engineer

HealthDrive Corporation • Framingham (MA)

Hybrid
USD 85,000 - 115,000
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation

New York Life • New York (NY)

On-site
USD 147,500 - 211,000