We are looking for an experienced Senior Vulnerability Management Engineer to join an enterprise security team in Jacksonville, FL. This is a hands-on role focused on managing enterprise vulnerability scanning, analyzing and prioritizing security findings, coordinating remediation, and improving vulnerability reporting and metrics.
The ideal candidate will have strong experience administering enterprise vulnerability management platforms such as Rapid7 InsightVM/Nexpose, Tenable or Qualys and working directly with infrastructure, cloud and application teams to reduce security risk.
Key Responsibilities
- Administer and support enterprise vulnerability management and scanning platforms
- Configure and maintain vulnerability scans, asset coverage, scan policies and reporting
- Analyze and prioritize vulnerabilities using CVSS, exploitability data and business risk
- Work directly with infrastructure, cloud and application teams to coordinate remediation
- Track vulnerabilities through remediation and validate closure of findings
- Monitor remediation SLAs, vulnerability trends, scanning coverage and outstanding risk
- Develop vulnerability dashboards, metrics and executive-level reporting
- Troubleshoot scanning, asset discovery and vulnerability management issues
- Identify opportunities to automate vulnerability reporting and operational processes
- Support security audits, risk assessments and compliance requirements
Required Experience
- 5+ years of cybersecurity, vulnerability management or related security experience
- 3+ years of hands-on vulnerability management experience in an enterprise environment
- Hands-on experience administering Rapid7 InsightVM/Nexpose, Tenable/Nessus or Qualys
- Experience with vulnerability analysis, prioritization and remediation tracking
- Strong understanding of CVSS, exploitability and risk-based vulnerability prioritization
- Experience partnering with technical teams to drive vulnerability remediation
- Experience creating vulnerability reports, dashboards, SLA metrics and management summaries
Preferred Experience
- Advanced experience with InsightVM/Nexpose, including scan configuration, asset management, reporting and troubleshooting
- Experience with Power BI, Splunk, PowerShell, Python or API-based automation
- Experience working in financial services or another highly regulated environment
- Familiarity with security and compliance frameworks such as NIST, FFIEC and PCI DSS
- Experience supporting security audits and providing vulnerability-management evidence