- Must be living in the following states to be considered: Florida (FL), Georgia (GA) , Illinois (IL), Iowa (IA), Nevada (NV), North Carolina (NC), South Dakota (SD), Texas (TX), Washington (WA), Virginia (VA), Wisconsin (WI)
Vulnerability Management Engineer
About the Role
Teleion is seeking an experienced Vulnerability Management (VM) Engineer to advance our clients' enterprise VM programs. This is a hands‑on, client‑facing contract role focused on operationalizing detection, risk‑based prioritization, reporting, and remediation across complex enterprise environments. The ideal candidate brings deep platform expertise, strong scripting skills, and the ability to translate technical exposure data into business risk language for executive audiences.
Responsibilities
- Implement, migrate, or optimize enterprise VM platforms (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium) to ensure comprehensive scan coverage across endpoints, servers, cloud workloads, containers, network infrastructure, and SaaS applications.
- Build and maintain risk‑based vulnerability prioritization models that go beyond CVSS severity – incorporating EPSS likelihood scores, CISA KEV exploitation status, SSVC decision logic, asset criticality, data classification, internet exposure, compensating controls, and business unit context.
- Develop tiered remediation SLA frameworks and drive remediation campaigns across IT ops, endpoint, cloud, and application teams with closed‑loop verification.
- Design and automate reporting pipelines and executive dashboards (Power BI preferred) covering coverage metrics, MTTR by tier, SLA compliance, backlog aging, and burndown.
- Integrate VM data with CMDB, ITSM platforms (ServiceNow), and BI tools using Python and PowerShell automation and REST API integration.
- Author and maintain KQL queries for vulnerability data analysis across Microsoft security platforms.
- Lead emergency response to actively exploited vulnerabilities from detection through verified remediation.
- Develop VM program maturity assessments, runbooks, exception and risk‑acceptance workflows, and audit evidence packages.
- Serve as a trusted technical advisor to client stakeholders, presenting program metrics and risk findings to executive audiences.
- Perform tasks as assigned.
Requirements
- 5 or more years of hands‑on vulnerability management or security engineering experience in enterprise environments.
- Direct implementation or migration experience with at least one enterprise VM platform: Tenable, Qualys, Rapid7, Microsoft Defender VM, or Tanium.
- Demonstrated ability to build risk‑based prioritization models incorporating EPSS, CISA KEV, SSVC, and business context signals beyond CVSS severity.
- Proficiency in Python and PowerShell for VM program automation, REST API integration, and reporting pipeline development.
- Experience with KQL or equivalent security query languages for vulnerability and asset data analysis.
- Hands‑on experience with cloud vulnerability management across Azure and at least one additional cloud provider (AWS or GCP).
- Familiarity with ITSM integration patterns for ticket lifecycle management and closed‑loop remediation.
- Experience building executive‑facing dashboards and translating technical vulnerability data into business risk language.
- Certifications preferred: CISSP, GIAC (GEVA, GCIA), or AZ-500.
- Familiarity with CTEM/exposure management concepts and Tanium + Microsoft Defender for Endpoint as data sources is a plus.
- full benefits
- PTO
- holiday
- 401(k)
See how other employees have reviewed us on Glassdoor.
We are excited to announce we have made in on Seattle Business Magazines "Washingtons Best Place to Work" for the 6th year in a row.
Teleion is minority owned and an Equal Opportunity Employer – We welcome all races, sexual orientations, gender identities, veterans, religions and disabilities.
Salary range: $100,000 - $175,000 - Based on experience