Vulnerability Management Engineer

nelnet

Centennial (CO)

Hybrid

USD 75,000 - 125,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical benefits
Dental benefits
Vision benefits
HSA/FSA
401K

Job summary

Nelnet's Cyber Security Group seeks an experienced Vulnerability Operations professional to lead and evolve the organization’s vulnerability management program.

You will collaborate with SOC, Offensive Operations, and other teams to identify, assess, and remediate risks across cloud and on-prem environments, ensuring continuous improvement and compliance with industry standards.

Qualifications

  • Bachelor's degree in cyber security or information systems or relevant work experience.
  • Cyber Security related certifications such as GIAC GSEC, GCED, GEVA, CompTIA Security+ , CySA+, ISC2 CISSP are a plus.

Responsibilities

  • Lead the design, development, and continuous improvement of the organization's vulnerability management strategy.
  • Stay up to date on emerging security threats and vulnerabilities and ensure the program adapts accordingly.
  • Oversee the configuration and maintenance of vulnerability scanning tools.
  • Analyze vulnerability data to assess risk and recommend mitigation strategies.
  • Develop and implement vulnerability remediation plans with technology teams and the business.
  • Collaborate with teams to prioritize remediation and ensure timely resolution of critical vulnerabilities.
  • Knowledge of CIS benchmarks, DISA STIGs, NSA Hardening Guides and other industry security frameworks.

Skills

Python programming
Vulnerability management
Security operations
Cloud security
Threat intel collaboration

Education

Bachelor's degree in cybersecurity or information systems

Tools

Rapid7
Qualys
Tenable
Microsoft MECM
EDR tools (Defender/CrowdStrike)

Job description

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.


The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.


Nelnet Cyber Security Group (CSG) is looking for an experienced and skilled individual to join the Vulnerability Operations (VO) team. Nelnet's Vulnerability Operations team is responsible for managing the attack surface and collaboration with various business units to assess risk by identifying vulnerabilities and threats to our organization and working to drive remediation of identified security risks. The Vulnerability Operations team sits with in the larger Nelnet Cyber Security Group and works closely with the Nelnet Security Operations Center (SOC) and Offensive Operations team. Join Nelnet to lead and improve our efforts to identify, understand, and reduce the attack surface of Nelnet while helping our business units achieve the Nelnet core values for our customers, employees and communities we serve.


This position requires work in support of the Company's contract with the United States Department of Education (\"ED\"). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance. Effective June 1, 2018, ED has informed Nelnet that security clearance applications for foreign nationals are not being accepted or processed. In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions.


This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates Living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week.


Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship.


JOB RESPONSIBILITIES:


  • Lead the design, development, and continuous improvement of the organization's vulnerability management strategy, aligning with business objectives and security requirements.

  • Stay up to date on emerging security threats and vulnerabilities, and ensure the program adapts accordingly.

  • Oversee the configuration and maintenance of vulnerability scanning tools.

  • Analyze vulnerability data to assess risk and recommend appropriate mitigation strategies.

  • Develop and implement vulnerability remediation plans, working collaboratively with all technology teams and the business.

  • Collaborate with cross-functional teams to assess vulnerability risks, prioritize remediation efforts, and ensure timely resolution of critical vulnerabilities to minimize security risks and operational impact.

  • Knowledge of CIS benchmarks, DISA STIGs, NSA Hardening Guides, and other industry security frameworks.

  • Demonstrated passion for continuous learning.


EDUCATION:

Bachelor's degree in cyber security or information systems OR relevant work experience.


Cyber Security related certifications such as GIAC GSEC, GCED, GEVA, CompTIA Security+ , CySA+, ISC2 CISSP are a plus.


EXPERIENCE:


  • 2+ years of experience in vulnerability management and/or security operations.

  • Experience with Vulnerability management solutions (Rapid 7, Qualys, Tenable, etc.)

  • Experience with patching tools like Microsoft MECM.

  • Experience with EDR administration (Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Network Cortex XDR, Tanium etc.)

  • Solid understanding of cloud-based hosting platforms, with background on security threats deriving from Azure, AWS and GCP hosted services being preferred.

  • Partner with the SOC, Cyber Threat Intel, Offensive Security Team, and other stakeholders to refine prioritization, to validate impact of suspected vulnerabilities, to advise owners on mitigation strategies or compensating controls, and to provide accurate & timely reporting that informs remediation progress.

  • Knowledge of python programming language is required.


Pay range for this role is $75,000-$125,000 annually, depending on experience.


#LI-CW1


#LI-Hybrid


Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance p

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Engineer
Vulnerability Management Engineer

Nelnet, Inc. • Centennial (CO)

Hybrid
USD 75,000 - 125,000
Medical
Dental
Vision
+6
Manager, Exposure Management
Manager, Exposure Management

Nelnet • Centennial (CO)

Hybrid
USD 120,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+4
CyberSecurity Senior Analyst
CyberSecurity Senior Analyst

Nelnet • Centennial (CO)

Hybrid
USD 85,000 - 130,000
Medical insurance
401K and student loan repayment
Tuition reimbursement
Cybersecurity Application Security Engineer
Cybersecurity Application Security Engineer

Nelnet, Inc. • Centennial (CO)

Hybrid
USD 90,000 - 125,000
Medical
CyberSecurity Senior Analyst
CyberSecurity Senior Analyst

Nelnet, Inc. • Centennial (CO)

Hybrid
USD 85,000 - 130,000
Medical
Dental
Vision
+3
Cybersecurity Application Security Engineer
Cybersecurity Application Security Engineer

nelnet • Centennial (CO)

Hybrid
USD 110,000 - 150,000
Hybrid work option
Sr Application Security Engineer
Sr Application Security Engineer

Nelnet, Inc. • Oklahoma

Hybrid
USD 135,000 - 150,000
Medical
Dental
Vision
+9
Cybersecurity Application Security Engineer
Cybersecurity Application Security Engineer

Nelnet, Inc. • Northern (KY)

Hybrid
USD 90,000 - 125,000
Medical insurance
Dental insurance
Vision insurance
+10
Sr Application Security Engineer
Sr Application Security Engineer

nelnet • Lincoln (NE)

On-site
USD 135,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+6
Hybrid Vulnerability Management Engineer
Hybrid Vulnerability Management Engineer

Nelnet, Inc. • Centennial (CO)

Hybrid
USD 75,000 - 125,000
Medical
Dental
Vision
+6