Tenable Vulnerability Management Engineer

Symmetrio

Pennsylvania

Hybrid

USD 115,000 - 130,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
PTO
401(k) plan

Job summary

Symmetrio is seeking a seasoned Tenable Vulnerability Management Engineer Consultant for a hybrid position in Philadelphia, PA. You will advance a large enterprise program by shaping configurations, automation, and risk-based prioritization across Tenable Vulnerability Management and Web App Scanning.

Strong PowerShell/Python scripting is essential to automate tasks, integrate data sources, and extend capabilities with APIs and AI-assisted workflows. 3–5 years Tenable experience required.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field; 3–5 years Tenable experience acceptable in lieu of education.
  • Certifications (CISSP, CEH, GIAC) are highly desirable.
  • Recent Tenable experience including Tenable.io and Nessus with deployment and configuration.
  • Experience with Tenable Web App Scanning and Tenable APIs.

Responsibilities

  • Conduct vulnerability assessments using Tenable to identify vulnerabilities across systems, networks, and applications.
  • Collaborate with cross-functional teams to prioritize vulnerabilities by risk and impact.
  • Develop and implement vulnerability management processes to ensure timely remediation and reporting.
  • Monitor remediation progress and track vulnerabilities within defined timelines.
  • Stay updated on vulnerabilities and best practices to improve the program maturely.

Skills

PowerShell
Python
Tenable.io
Nessus
Automation
APIs
AI tooling

Education

Bachelor's degree in CS/InfoSec

Tools

Tenable Web App Scanning
SIEM/SOAR
CMDBs

Job description

Symmetrio is recruiting a hybrid Tenable Vulnerability Management Engineer Consultant for our customer, a large government organization in Philadelphia, PA. This role is intended for an experienced, hands-on Tenable practitioner who can elevate and mature a large enterprise vulnerability management program.

The successful candidate will bring recent, deep experience across the Tenable platform and will be expected to optimize how Tenable is configured, operated, automated, and used to drive risk-based vulnerability identification, prioritization, remediation, and executive reporting. This individual should be excited to expand the program beyond traditional infrastructure scanning by leveraging Tenable Vulnerability Management, Tenable Web App Scanning, APIs, automation, and other applicable Tenable capabilities. The candidate will also help advance the use of AI-enabled tools and techniques to analyze vulnerability data, identify patterns and exposures, improve prioritization, accelerate investigation, and support remediation decisions across a complex enterprise environment.

Strong PowerShell and/or Python scripting skills are essential to automate repetitive activities, integrate data sources, enrich findings, and improve the efficiency and scale of the vulnerability management lifecycle. The ideal candidate is not simply a scanner operator; they are a vulnerability management engineer and program builder who can identify opportunities to improve coverage, data quality, risk prioritization, automation, metrics, and overall program maturity.

This is a hybrid position, with 1–2 days per week required onsite at the Philadelphia office for team meetings, strategic planning, and stakeholder discussions. The position offers a salary range of $115,000–$130,000, along with competitive health benefits, PTO, and a 401(k) plan.

Responsibilities
  • Conduct vulnerability assessments using Tenable to identify potential security vulnerabilities within our systems, networks, and applications.
  • Collaborate with cross-functional teams to analyze and prioritize vulnerabilities based on risk levels and potential impact.
  • Develop and implement vulnerability management processes, procedures, and best practices to ensure timely identification, remediation, and reporting of vulnerabilities.
  • Monitor and track the remediation of identified vulnerabilities, ensuring that they are addressed within defined timelines.
  • Stay updated with the latest security vulnerabilities, threats, and industry best practices to continuously improve the vulnerability management program.
  • Perform regular vulnerability scanning and penetration testing to proactively identify and address potential security weaknesses.
  • Work closely with IT teams to provide guidance and support in remediating vulnerabilities, including suggesting configuration changes, patches, and other remediation actions.
  • Provide technical expertise and guidance to internal stakeholders on vulnerability management issues and best practices.
  • Collaborate with the Incident Response team to investigate and respond to security incidents related to vulnerabilities.
  • Bachelor's degree in Computer Science, Information Security, or a related field, preferred but not required with acceptable experience. 3-5 years of recent, hands-on experience administering and engineering Tenable solutions in a large enterprise environment is acceptable in replacement of education. Relevant certifications (e.g., CISSP, CEH, GIAC), including Tenable or other vendor certifications, are highly desirable.
  • Demonstrated recent experience with the Tenable platform, with strong hands-on expertise in Tenable Vulnerability Management (Tenable.io) and Nessus, including scanner deployment and management, scan configuration, asset discovery, tagging, credentialed scanning, plugin management, troubleshooting, dashboards, reporting, and platform optimization.
  • Experience using Tenable Web App Scanning to identify and assess vulnerabilities in web applications and APIs; experience with additional Tenable services and capabilities is strongly preferred.
  • Proven experience designing, operating, and maturing an enterprise vulnerability management program, including vulnerability discovery, validation, risk-based prioritization, remediation tracking, exception management, metrics, reporting, and continuous improvement.
  • Advanced scripting and automation skills, particularly PowerShell; Python or similar scripting experience is highly desirable. Must be able to create and maintain scripts that automate Tenable administration, data collection, enrichment, reporting, integrations, remediation workflows, and other vulnerability management activities.
  • Experience working with Tenable APIs and integrating Tenable vulnerability and asset data with enterprise technologies such as ticketing systems, SIEM/SOAR platforms, CMDBs, asset inventories, dashboards, or other security tools.
  • Demonstrated ability and interest in leveraging AI tools to assist with vulnerability analysis, data correlation, pattern identification, prioritization, remediation research, scripting, reporting, and other vulnerability management use cases while applying appropriate validation and security controls to AI-generated outputs.
  • Strong understanding of vulnerability intelligence and risk-based prioritization, including CVE, CVSS, CISA Known Exploited Vulnerabilities (KEV), exploitability, threat intelligence, asset criticality, exposure, compensating controls, and business impact.
  • Solid understanding of common vulnerabilities, attack vectors, mitigation techniques, network and application security concepts, and the ability to distinguish actionable risk from scanner noise or false positives.
  • Experience with network scanning, authenticated/credentialed scanning, web application scanning, vulnerability validation, and penetration testing or vulnerability exploitation techniques.
  • Knowledge of industry standards and frameworks such as CVSS, CVE, OWASP, NIST, and vulnerability management best practices.
  • Strong analytical, troubleshooting, communication, and problem-solving skills, with the ability to translate technical vulnerability data into clear remediation guidance and risk information for infrastructure teams, application owners, leadership, and other stakeholders.
  • Demonstrated ability to independently identify gaps in vulnerability coverage, tooling, processes, automation, reporting, and governance and recommend and implement improvements that measurably increase vulnerability management program maturity.
  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k)
  • Paid Time Off (Vacation, Sick & Public Holidays)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Tenable VM Engineer & Program Lead
Hybrid Tenable VM Engineer & Program Lead

Symmetrio • Pennsylvania

Hybrid
USD 115,000 - 130,000
Health benefits
PTO
401(k) plan
Vulnerability Management Engineer
Vulnerability Management Engineer

WideNet Consulting Group • Seattle (WA)

Hybrid
USD 103,000 - 117,000
Technical Support Engineer (Hybrid/Columbia MD)
Technical Support Engineer (Hybrid/Columbia MD)

Tenable • Ellicott City (MD)

Hybrid
USD 75,000 - 110,000
Vulnerability Management Analyst
Vulnerability Management Analyst

DANE LLC • Chantilly (VA)

Hybrid
USD 70,000 - 90,000
Life/STD/LTD insurance
401(k) plan
Paid time off
+5
Senior Security Analyst Vulnerability Management
Senior Security Analyst Vulnerability Management

Compass Pointe Consulting, LLC • Bethesda (MD)

On-site
USD 110,000 - 140,000
Vulnerability Management Analyst
Vulnerability Management Analyst

DANE, LLC • Chantilly (VA)

Hybrid
USD 75,000 - 95,000
Life/STD/LTD
FSA/DCA
401(k)
+7
Security Engineer, Infrastructure Operations
Security Engineer, Infrastructure Operations

11:11 Systems Inc. • Northern (KY)

Hybrid
USD 120,000 - 160,000
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000
Vulnerability Management Lead
Vulnerability Management Lead

K2Share LLC • Washington

On-site
USD 120,000 - 180,000
cybersecurity Analyst with vulnerability management
cybersecurity Analyst with vulnerability management

Themesoft Inc. • Burlington (MA)

On-site
USD 70,000 - 90,000