Vulnerability Management Engineer

Foresite Cybersecurity

Overland Park (KS)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Foresite Cybersecurity is seeking an enterprise‑level Vulnerability Management Engineer to administer and optimize our Tenable product infrastructure, including multi‑tenant consoles and on‑premise Nessus deployments. You’ll support OT security and all Tenable modules for industrial clients, ensuring robust vulnerability visibility and remediation roadmaps.

Ideal candidates bring 4+ years in cybersecurity operations with hands‑on Tenable administration experience at scale, deep troubleshooting,

Qualifications

  • 4+ years in cybersecurity operations, system administration, or vulnerability management.
  • Hands-on Tenable administration at scale (10,000+ assets).
  • Active mandatory technical certifications related to Tenable products.

Responsibilities

  • Maintain scanner infrastructure, health, and configuration across multi-tenant environments including on-premise Nessus scanners, cloud pools, and agent infrastructure.
  • Configure and maintain RBAC, asset groups, and scanning permissions to enforce least privilege.
  • Maintain data ingestion from Tenable APIs to SIEM/SOAR (Google Chronicle) and ITSM (ServiceNow).
  • Design and execute credentialed and uncredentialed scans across hybrid infrastructures to maximize visibility with minimal network impact.
  • Operate on-prem Tenable Security Center deployments, including repository configuration and analytic queries.
  • Run OT security scans with Tenable OT Security for ICS/critical infrastructure clients where applicable.
  • Create dashboards, reports, filters, and saved templates aligned to client needs and regulatory requirements.
  • Apply Tenable Vulnerability Priority Rating (VPR) and Cyber Exposure Score (CES) to prioritize actions and reduce noise.
  • Translate vulnerability data into remediation roadmaps and conduct periodic technical reviews to track posture.

Skills

Vulnerability management
Cybersecurity operations
System administration
Tenable administration

Tools

Nessus
Tenable Security Center
Tenable OT Security
RBAC tooling

Job description

Foresite is seeking an enterprise-level Vulnerability Management Engineer dedicated to the administration, engineering, and day‑to‑day operations of our Tenable product infrastructure. In this technical role, you will be responsible for building, optimizing, and maintaining our multi‑tenant shared instances and standalone client consoles across Tenable Vulnerability Management and Tenable Security Center, along with Tenable OT Security for industrial clients and all other Tenable Modules.

What you'll do:
  • Maintain scanner infrastructure & configuration hygiene: Monitor the health, availability, and version currency of distributed scanning infrastructure across complex multi‑tenant environments — including on‑premise Nessus scanners, cloud scanner pools, and Tenable Nessus Agents. Identify offline scanners, stale agent check‑ins, plugin update failures, and linked‑scanner issues, then coordinate resolution with client teams.
  • Enforce access control & RBAC: Configure and maintain strict Role‑Based Access Control (RBAC) definitions, custom asset groups, and scanning permissions to enforce least privilege and limit administrative blast radius.
  • Support telemetry integrations: Maintain data ingestion pipelines from Tenable APIs over to enterprise analytical hubs, explicitly optimizing vulnerability telemetry streams for SIEM/SOAR engines like Google SecOps (Chronicle) and ITSM platforms like ServiceNow.
  • Optimize scan & assessment operations: Design, schedule, and execute deep credentialed and uncredentialed vulnerability scans across hybrid infrastructures, optimizing parameters to guarantee extensive visibility without causing network degradation.
  • Administer Security Center: Operate and maintain on‑premise Tenable Security Center deployments for clients requiring self‑hosted vulnerability management, including repository configuration, scan zone design, and analytic query construction.
  • Execute Operational Technology (OT) scanning: Execute specialized scanning profiles using Tenable OT Security to protect industrial control systems (ICS) where applicable for manufacturing and critical infrastructure clients.
  • Build custom reporting & dashboards: Build and maintain custom dashboards, asset filters, and saved scan templates tailored to client business units and regulatory needs.
  • Prioritize organizational risk: Utilize Tenable's Vulnerability Priority Rating (VPR) and Cyber Exposure Score (CES) to filter out operational noise and highlight immediately exploitable threats.
  • Generate actionable remediation roadmaps: Translate complex vulnerability data sets into clear, prioritized technical remediation checklists for client infrastructure teams, conducting recurring technical reviews to track system posture.
Who you are:
  • Experience: 4+ years in cybersecurity operations, system administration, or vulnerability management, with at least 2 years of dedicated, hands‑on Tenable administration at scale (10,000+ assets).
  • Advanced troubleshooting capabilities: Proven ability to troubleshoot complex credentialed scanning failures over SMB and SSH.
  • Multi‑tenant domain knowledge: Demonstrated ability to manage concurrent delivery across multiple client tenants without cross‑contaminating client data, credentials, or findings.
  • Required Certifications: Must hold at least one active mandatory technical certification:
    • Tenable One Vulnerability Management Specialist
    • Tenable Security Center Specialist
    • Tenable One OT Exposure Specialist
Nice to have:
  • Multiple Tenable Certifications: Holding more than one of the required Tenable Specialist certifications listed above.
  • Adjacent Platform & Industry Certifications: Google SecOps / Chronicle Certified Professional, CompTIA Security+ / Network+ / Linux+, or CEH (Certified Ethical Hacker).
  • Helpful Experience with Additional Tenable Modules: Exposure to adjacent modules including Tenable Web App Scanning, Identity Exposure, Cloud Security, Attack Surface Management, Patch Management, Tenable One platform capabilities (Exposure View, Attack Path Analysis), AI Exposure, Enclave Security, PCI ASV, or Nessus Expert.
  • Licensing Familiarity: Understanding of Tenable's licensing model across modules — how asset counts, resource ratios, and add‑on components affect client entitlements in an MSSP environment.
Why Join Foresite?

We are a mission‑driven partner helping organizations navigate an increasingly complex threat landscape. Founded by security practitioners, we’ve grown into a global leader in SecOps and MDR by staying true to our core value: radical transparency. When you join Foresite, you are part of a "humans‑first" culture where your expertise is valued, and your well‑being is a priority. We leverage our Google Cloud Premier SecOps Partnership to stay at the cutting edge, but we know that our greatest asset is our people.

What we offer:
  • Comprehensive Health & Wellness: Robust medical insurance options to keep you and your family healthy.
  • Employer‑Covered Insurance: We fully provide employer‑paid Dental coverage, as well as Short‑Term (STD) and Long‑Term Disability (LTD).
  • Recharge & Refuel: We believe in a true work‑life balance. You’ll start with 3 weeks of paid vacation, plus additional sick leave and paid company holidays to ensure you have time to recharge.
  • Growth & Mentorship: Access to world‑class training and mentorship. We support your career trajectory, whether you’re looking to deepen your technical skills or move into leadership.
  • Impactful Work: Help protect global clients using the latest AI‑enhanced security tools and GCP native technologies.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Engineer
Vulnerability Management Engineer

Foresite MSP • Olathe (KS)

On-site
USD 90,000 - 130,000
Health insurance
Dental coverage
Paid vacation (3 weeks)
+2
Certified Tanium Administration / Service Lead
Certified Tanium Administration / Service Lead

Foresite Cybersecurity • Overland Park (KS)

On-site
USD 120,000 - 170,000
Health insurance
Paid vacation
Mentorship & growth opportunities
+1
Certified Tanium Administration / Service Lead
Certified Tanium Administration / Service Lead

Foresite MSP • Olathe (KS)

On-site
USD 140,000 - 190,000
Comprehensive Health & Wellness
Employer-Covered Dental
3 weeks vacation + holidays
Security Engineer
Security Engineer

Foresite MSP • Olathe (KS)

On-site
USD 110,000 - 150,000
Comprehensive Health & Wellness
Dental coverage
STD & LTD insurance
+1
Threat Analyst
Threat Analyst

Foresite MSP • Olathe (KS)

On-site
USD 90,000 - 130,000
Health insurance
Dental coverage
Short-Term Disability
+2
Threat Analyst
Threat Analyst

Foresite Cybersecurity • Overland Park (KS)

On-site
USD 90,000 - 120,000
Health insurance
Paid time off
Professional development
+2
Senior Fullstack Engineer
Senior Fullstack Engineer

Foresite • Overland Park (KS)

Hybrid
USD 90,000 - 120,000
Radical transparency
Mission-driven culture
Flexible working arrangements
Cloud Security Engineer
Cloud Security Engineer

Foresite MSP • Olathe (KS)

On-site
USD 90,000 - 130,000
Health insurance
Dental coverage
STD
+5
Senior Applied AI Engineer
Senior Applied AI Engineer

Foresite MSP • Olathe (KS)

On-site
USD 140,000 - 190,000
Health coverage
PTO & holidays
401(k) match
+1
Cloud Security Engineer
Cloud Security Engineer

Foresite Cybersecurity • Overland Park (KS)

On-site
USD 100,000 - 130,000
Comprehensive Health & Wellness
Employer-Covered Insurance
Generous Time Off
+2