Security Engineer - Vulnerability Management

PCI Professional Services

United States

On-site

USD 110,000 - 160,000

Full time

1 hour ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

PCI Federal Services (PCIFS) is seeking a Security Engineer - Vulnerability Management Specialist to lead and mature the organization's vulnerability management program across systems, networks, and applications. You will identify, assess, and mitigate risks, collaborating with IT, security, and development teams to strengthen posture.

The role requires 4–6 years in vulnerability management, hands-on experience with Nessus, Qualys, Rapid7, and OpenVAS, and familiarity with CVSS, NIST 800-53, and

Qualifications

  • Minimum 4–6 years in vulnerability management or related info security role.
  • Knowledge of CVSS, NIST 800-53, OWASP Top 10.
  • Understanding of Windows, Linux, macOS vulnerabilities.
  • Familiarity with patch management and compliance like FISMA/SOX.
  • Experience with vulnerability reporting and risk communication.
  • Bachelor's degree or equivalent work experience.

Responsibilities

  • Manage and enhance the vulnerability management program across systems, networks, and apps.
  • Identify, assess, and mitigate security vulnerabilities.
  • Collaborate with IT, security, and development teams to improve posture.
  • Communicate risks to stakeholders and drive remediation.
  • Continuously improve processes, tooling, and reporting.

Skills

Vulnerability management
PoC development
Incident response
Threat modeling
SIEM integration
Log analysis
Event correlation
Compliance knowledge

Education

Bachelor's degree in Cybersecurity

Tools

Tenable Nessus
Qualys
Rapid7
OpenVAS
SCAP/CIS-CAT
Metasploit
AWS Inspector
Azure Security Center
GCP Security Command Center
Splunk
QRadar

Job description

Role Description

As a Security Engineer - Vulnerability Management Specialist, you will be responsible for managing and enhancing the organization's vulnerability management program. Your primary focus will be on identifying, assessing, and mitigating security vulnerabilities across the organization's systems, networks, and applications. You will work closely with IT, security, and development teams to ensure a robust security posture and compliance with industry standards.

As a Security Engineer - Vulnerability Management Specialist, you will be responsible for managing and enhancing the organization's vulnerability management program. Your primary focus will be on identifying, assessing, and mitigating security vulnerabilities across the organization's systems, networks, and applications. You will work closely with IT, security, and development teams to ensure a robust security posture and compliance with industry standards.

The role requires a proactive approach to identifying and addressing security gaps, implementing best practices, and communicating risks effectively to stakeholders. You will also contribute to the continuous improvement of vulnerability management processes, tools, and reporting mechanisms.

Minimum Skills

  • Minimum of 4-6 years of experience in vulnerability management or a related information security role.
  • Advanced knowledge of vulnerability management tools and platforms such as Tenable Nessus, Qualys, Rapid7, OpenVAS, or similar.
  • Strong understanding of vulnerability scanning, assessment, and risk prioritization.
  • Familiarity with common vulnerability scoring systems and frameworks (e.g., CVSS, NIST 800-53, OWASP Top 10).
  • Understanding of operating systems (Windows, Linux, macOS) and their associated vulnerabilities.
  • Knowledge of network protocols and components (e.g., TCP/IP, DNS, firewalls, routers, and switches).
  • Experience with patch management processes and tools.
  • Basic understanding of compliance requirements, such as FISMA, and SOX.
  • Familiarity with security frameworks such as NIST Cybersecurity Framework, ISO 27001, and CIS critical security controls.
  • Ability to assess vulnerabilities, identify risks, and assist in incident response processes when vulnerabilities have been exploited.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent work experience).

Preferred Skills

  • Advanced skills in vulnerability exploitation and proof of concept (PoC) development.
  • Familiarity with exploit frameworks like Metasploit.
  • Experience with cloud security tools and platforms (e.g., AWS Inspector, Azure - Security Center, or GCP Security Command Center).
  • Expertise in identifying and mitigating critical vulnerabilities in complex environments.
  • Experience with configuration assessment tools such as SCAP or CIS-CAT.
  • Knowledge of threat intelligence tools and processes to correlate vulnerabilities with real-world threats.
  • Understanding of threat modeling and attack surface analysis.
  • Experience with SIEM tools (e.g., Splunk, QRadar) and integration with vulnerability management processes.
  • Knowledge of log analysis and event correlation.
  • Advanced certifications, such as:
  • GIAC Certified Vulnerability Analyst (GCVA)
  • Offensive Security Certified Professional (OSCP).
  • Certified Information Systems Security Professional (CISSP).
  • Certified Information Security Manager (CISM).

PCI Federal Services (PCIFS) and its subsidiaries is an equal-opportunity employer. PCIFS does not discriminate on the basis of age, sex, race, national origin, religion, marital status, sexual orientation or identity, Veterans or Disability status.

Preference may be extended to qualified Native American Indian candidates.

in accordance with applicable federal law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Fortis Industries, Inc. DBA - LTS, Inc. • Atmore (AL)

On-site
USD 100,000 - 140,000
Vulnerability Management Engineer (Tenable)
Vulnerability Management Engineer (Tenable)

Alluvial Concepts • Rockville (MD)

On-site
USD 120,000 - 180,000
Senior Vulnerability Assessment Analyst
Senior Vulnerability Assessment Analyst

Base One Technologies • Washington

Hybrid
USD 120,000 - 180,000
Vulnerability Management Analyst
Vulnerability Management Analyst

Morph Enterprise • United States

On-site
USD 90,000 - 130,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Compunnel, Inc. • Irving (TX)

On-site
USD 100,000 - 130,000
Vulnerability Management Analyst
Vulnerability Management Analyst

Soho Square Solutions • New York (NY)

On-site
USD 90,000 - 130,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Jobtailor • Arizona

On-site
USD 120,000 - 180,000
Data Privacy and Compliance Analyst
Data Privacy and Compliance Analyst

Comtech LLC • Atlanta (GA)

On-site
USD 80,000 - 100,000
Remote Security Engineer — Vulnerability Management
Remote Security Engineer — Vulnerability Management

PCI Professional Services LLC • United States

Remote
USD 100,000 - 140,000
Systems Administrator (Vulnerability Management)
Systems Administrator (Vulnerability Management)

Dillard's Inc. • River Ridge Manor (AR)

On-site
USD 75,000 - 110,000