Senior Vulnerability Management Engineer – Exposure & Remediation

TechWish

Walnut Creek (CA)

On-site

USD 140,000 - 190,000

Full time

42 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

CSAA Insurance Group seeks a Senior Vulnerability Management Engineer to lead enterprise vulnerability coverage across on-premises, cloud, and hybrid environments. You will drive asset visibility, risk-based remediation, and exposure analysis, translating findings into actionable guidance for multiple technology teams.

The role emphasizes hands-on platform expertise, collaboration across security and IT teams, and continuous improvement of remediation workflows and data quality.

Qualifications

  • Five+ years in vulnerability management or related cybersecurity discipline.
  • Hands-on experience administering enterprise vulnerability management platforms, scanners, agents, policies, credentials, and integrations.
  • Experience designing and troubleshooting credentialed and unauthenticated vulnerability scans across Windows, Linux, network, and cloud environments.
  • Strong understanding of TCP/IP, DNS, routing, firewalls, load balancers, and network segmentation.
  • Ability to translate complex vulnerability and network information into actionable guidance for technical and non-technical stakeholders.

Responsibilities

  • Own and optimize enterprise vulnerability scanning across on-premises, cloud, endpoint, and network environments, including scanners, agents, scan policies, schedules, credentials, platform health, upgrades, and integrations.
  • Analyze scan coverage and troubleshoot gaps related to asset discovery, authentication, agent deployment, scanner placement, routing, firewall rules, network segmentation, and onboarding.
  • Maintain accurate vulnerability asset visibility by identifying unmanaged, duplicate, stale, or improperly classified assets and resolving asset-correlation and data-quality issues.
  • Develop and maintain asset tagging and classification strategies that support ownership, prioritization, reporting, and remediation workflows.
  • Analyze critical and high-risk vulnerabilities using exploitability, reachability, threat intelligence, asset criticality, internet exposure, compensating controls, and business context.
  • Identify vulnerabilities and assets requiring prioritized remediation and provide clear technical recommendations to infrastructure, network, cloud, database, application, and endpoint teams.
  • Support vulnerability triage, false-positive validation, assignment and ownership resolution, rescans, remediation verification, and recurring-issue analysis.
  • Maintain and improve integrations and workflows between Tenable, Wiz, ServiceNow Vulnerability Response, and other enterprise systems.
  • Contribute technical expertise to assignment rules, risk scoring, dashboards, metrics, reporting, and vulnerability workflow enhancements.
  • Develop or support automation using APIs, PowerShell, Python, or similar technologies, and document technical procedures and operational practices.

Skills

Analytical skills
Troubleshooting
Collaboration
Documentation
Communication

Education

Bachelor's degree in Cybersecurity, IT, CS, or Engineering

Tools

Tenable Vulnerability Management
Nessus
Nessus Agents
Wiz
ServiceNow Vulnerability Response

Job description

CSAA Insurance Group seeks a Senior Vulnerability Management Engineer to lead enterprise vulnerability coverage across on-premises, cloud, and hybrid environments. You will drive asset visibility, risk-based remediation, and exposure analysis, translating findings into actionable guidance for multiple technology teams.

The role emphasizes hands-on platform expertise, collaboration across security and IT teams, and continuous improvement of remediation workflows and data quality.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

TechWish • Walnut Creek (CA)

On-site
USD 140,000 - 190,000
Senior Vulnerability Management Engineer: Risk & Remediation
Senior Vulnerability Management Engineer: Risk & Remediation

Interactive Resources • Jacksonville (FL)

On-site
USD 110,000 - 160,000
Senior Vulnerability Governance & Risk Analyst
Senior Vulnerability Governance & Risk Analyst

System One • Knoxville (TN)

On-site
USD 120,000 - 180,000
Senior Vulnerability Management & Risk Lead
Senior Vulnerability Management & Risk Lead

System One • Birmingham (AL)

On-site
USD 110,000 - 150,000
Senior Vulnerability Risk Engineer
Senior Vulnerability Risk Engineer

Vertex Computer Systems • New York (NY)

On-site
USD 110,000 - 160,000
Senior Exposure Security Engineer - External Attack Surface
Senior Exposure Security Engineer - External Attack Surface

CHS Corporate • United States

On-site
USD 140,000 - 190,000
Senior Vulnerability & Threat Exposure Lead (Remote)
Senior Vulnerability & Threat Exposure Lead (Remote)

Hidden Jobs • United States

Remote
USD 176,000 - 263,000
Medical benefits
Retirement matching
Bonus eligibility
+1
Sr. Cyber Security Engineer, Exposure Management
Sr. Cyber Security Engineer, Exposure Management

Community Health Systems • United States

On-site
USD 120,000 - 150,000
Senior Vulnerability & Exposure Management Lead
Senior Vulnerability & Exposure Management Lead

Xtreme Solutions Inc • Atlanta (GA)

On-site
USD 135,000 - 170,000
Senior Vulnerability Management Analyst
Senior Vulnerability Management Analyst

System One • Lafayette (LA)

On-site
USD 110,000 - 150,000