Senior Vulnerability Management Engineer

Group 1001

United States

On-site

USD 190,000 - 230,000

Full time

4 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Group 1001 is seeking a Senior Vulnerability Management Engineer who blends security expertise with infrastructure know-how to identify, prioritize, and drive remediation across cloud, on-prem, applications, and OT systems.

You will automate the vulnerability lifecycle with SOAR, integrate scanners and cloud platforms, and develop KPI-driven reporting to reduce risk and noise while mentoring teammates.

Qualifications

  • Bachelor's degree in CS or related field or equivalent experience.
  • 5–7 years in information security, preferably in financial services.
  • Experience deploying enterprise vulnerability scanning (Tenable/Defender/Wiz/Tanium).
  • Experience automating security platforms (Swimlane/Elastic).
  • Strong cloud security knowledge across AWS/Azure/GCP.
  • Familiarity with DevSecOps and CI/CD pipelines.
  • Knowledge of NIST/ISO/CIS; strong communication and collaboration.

Responsibilities

  • Own end-to-end vulnerability management pipeline from discovery to closure.
  • Build data-driven prioritization using CVSS, EPSS, KEV and business context.
  • Automate workflow via SOAR, APIs, queues and custom scripts.
  • Develop KPIs, metrics and trend analyses for risk reduction.
  • Integrate scanners, CMDB/EDR, and cloud providers into a single pipeline.
  • Dedupe, suppress known-benign, and auto-close on remediation evidence.
  • Lead technical response for emergency patch cycles across platforms.

Skills

Automation
SOAR
Cloud security
Vulnerability management

Education

Bachelor's degree in CS/InfoSec

Tools

Tenable
Microsoft Defender
Wiz
Tanium
Swimlane
Elastic

Job description

As a Senior Vulnerability Management Engineer at Group 1001, you are equal parts security practitioner and infrastructure engineer. You will combine your deep vulnerability expertise with systems engineering prowess to identify, prioritize, and drive remediation of risks across cloud, on-prem, applications, and OT/embedded systems.

You will be responsible for shaping the Vulnerability Management function into a system optimized with significant automation. Your goal is to discover, contextualize, and mitigate the increasingly rapid volume, velocity, and nature of vulnerability exploitation in a post-AI world. This role exists to deliver this goal by using systems for discovery, assessment, contextual prioritization, and assignment to the responsible technology owners. Where human effort is required, your expertise helps navigate the edge cases, framework tuning, and hardening the pipeline.

How You'll Contribute:
  • Own the end-to-end vulnerability management pipeline: asset discovery > scanning > enrichment > prioritization > assignment > verification > closure.
  • Build, codify, and iterate a data-driven prioritization framework (blending CVSS, EPSS, KEV, exploit availability, asset criticality, exposure/reachability, compensating controls, and business context).
  • Automate the full workflow via SOAR playbooks, webhooks, REST/GraphQL APIs, message queues, and custom scripts where needed.
  • Develop and improve KPIs, metrics, and trending for vulnerability management functions, and bring leadership attention to root-cause issues driving systemic vulnerability risk.
  • Integrate scanners, CMDB/asset inventory, EDR, cloud providers (AWS/Azure/GCP), and others into a single pipeline for management.
  • Continuously reduce noise: dedupe, suppress known-benign, correlate related findings, and auto-close on evidence of remediation.
  • Evaluate and integrate AI/LLM tooling for triage, false-positive suppression, remediation guidance, and vulnerability research — with appropriate guardrails.
  • Lead technical response for emergency patch cycles on various technical platforms.
What We're Looking For:
  • Bachelor's degree in Computer Science, Information Security, or related academic field or equivalent experience.
  • 5-7 years of professional experience in information security, with focus on the financial sector.
  • Hands-on experience deploying, configuring, and managing vulnerability scanning solutions at enterprise scale, including policy design, tuning for noise reduction, and managing performance impact (e.g. Tenable, Microsoft Defender, Wiz, Tanium.)
  • Hands-on experience engineering, integrating, and optimizing for automation of security platforms (e.g. Swimlane, Elastic).
  • Strong knowledge of public cloud platforms (e.g., AWS, Azure, GCP) from an infrastructure and development aspect and their related security features.
  • Familiarity with DevSecOps practices and CI/CD pipelines.
  • Understanding of industry security frameworks, standards, and best practices (e.g., NIST, ISO, CIS).
  • Strong communication and collaboration skills, with the ability to work closely with engineering, operations and infrastructure teams.
  • Familiarity with compliance standards and regulations.
  • Creativity and critical thinking with the ability to work both independently and collaboratively in a fast-paced environment.
  • Be able to serve as a mentor or subject matter expert to other members within the organization, particularly in the areas of vulnerability management and systems engineering.
Compensation:

Our compensation reflects the cost of labor across several U.S. geographic markets. The base pay for this position ranges from $190,000/year in our lowest geographic market up to $230,000/year plus bonus in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer - Vulnerability Management
Cybersecurity Engineer - Vulnerability Management

Jane Street Group, LLC • Northern (KY), New York (NY)

Hybrid
USD 225,000 - 300,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

United States Digital Space LLC • Seattle (WA), San Francisco (CA)

On-site
USD 110,000 - 150,000
Vulnerability Management Manager
Vulnerability Management Manager

Considine Search • New York (NY)

On-site
USD 200,000 - 215,000
Manager, Vulnerability Management
Manager, Vulnerability Management

Optimum • Norwalk (CT)

On-site
USD 133,000 - 220,000
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation

New York Life • New York (NY)

On-site
USD 147,500 - 211,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Compunnel, Inc. • Irving (TX)

On-site
USD 100,000 - 130,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Jobtailor • Arizona

On-site
USD 120,000 - 180,000
Vulnerability Analyst — External Attack Surface & VDP
Vulnerability Analyst — External Attack Surface & VDP

Vanguard • Malvern

Hybrid
USD 80,000 - 110,000
Growth pathways in security roles
Hybrid working model
Vulnerability Management Specialist
Vulnerability Management Specialist

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

Hybrid
USD 80,000 - 100,000
Medical, dental, vision, and life insurance
Short and long-term disability insurance
401(k) plan with company match
+1
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000