Vulnerability Management & Response Engineer

Starr Insurance Holdings, Inc.

Destin (FL)

On-site

USD 90,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Starr Insurance Holdings, Inc. is seeking a Vulnerability Management & Response Engineer in Destin, Florida. This role focuses on managing and improving our enterprise Vulnerability Management program, ensuring effective remediation across all environments.

The ideal candidate has over 5 years of relevant experience, including hands-on work with Tenable. Responsibilities include cross-functional collaboration and driving risk-informed decisions. Join us in enhancing our security posture and governance.

Qualifications

  • 5+ years of experience running an enterprise Vulnerability Management program with a focus on governance and remediation.
  • Hands-on experience with Tenable including configuration and troubleshooting.
  • Strong documentation and process improvement capabilities.

Responsibilities

  • Manage day-to-day operations of the Tenable platform including scan configuration.
  • Lead vulnerability remediation tasks across stakeholders.
  • Produce metrics and reports on overall Vulnerability Management program performance.

Skills

Vulnerability Management program
Tenable experience
Collaboration skills
Documentation skills
Cloud security knowledge

Tools

SCCM
Intune
SOAR
SIEM

Job description

Position Summary

We are seeking a highly skilled Vulnerability Management & Response Engineer to help operate and continuously improve our enterprise Vulnerability Management (VM) program. This role is responsible for owning core VM processes end-to-end—identification, assessment, prioritization, exception handling, remediation tracking, and validation—across on-premises and cloud environments using Tenable. The position drives risk‑informed decisions and facilitates remediations with the asset owners. This role will partner cross‑functionally with Infrastructure, Development, Risk, and Compliance teams to maintain continuous scanning coverage, meet remediation SLAs, and mature the VM program through automation, reporting, and governance.

Key Responsibilities
  • Own day‑to‑day operations of the Tenable platform (e.g., scan configuration, scheduling, coverage monitoring, credentials management, and results troubleshooting).
  • Lead triage, assignment, and validation of vulnerability remediation tasks across infrastructure and application stakeholders.
  • Define, maintain, and enforce SLA‑based remediation, including escalation and executive reporting for SLA drift.
  • Integrate Tenable findings and remediation workflows with SCCM, Intune, SOAR, SIEM, and ticketing systems to enable automated assignment, tracking, and validation.
  • Conduct quarterly reconciliation of Tenable scanner output with CMDB and asset inventories to validate coverage, ownership, and data quality.
  • Maintain an auditable exception register with documented risk acceptance, compensating controls, approvals, and expiration controls.
  • Produce VM program metrics and reporting (weekly, monthly, quarterly, and annually), including risk trends, SLA performance, and remediation outcomes.
  • Run a recurring VM governance cadence (e.g., quarterly working sessions) to review SLA drift, backlog health, scanner coverage, and tool‑to‑tool integrations.
  • Support internal audit and regulatory review of the Vulnerability Management program by providing evidence, metrics, and control narratives.
Required Qualifications
  • 5+ years of hands‑on experience running an enterprise Vulnerability Management program (process, governance, metrics, and remediation outcomes), not just point‑in‑time scanning.
  • Hands‑on experience with Tenable (scan configuration, credentialed scanning, reporting, and troubleshooting).
  • Deep understanding of vulnerability scoring systems (CVSS), threat intelligence correlation, and risk‑based prioritization to drive remediation sequencing.
  • Experience leading or contributing to patching strategies using SCCM, Intune, or similar tools.
  • Strong documentation and process improvement skills.
  • Proven ability to collaborate across technical and non‑technical teams.
Preferred Qualifications
  • Experience integrating VM tools with SOAR, SIEM, or ticketing platforms like Remedyforce or ServiceNow.
  • Knowledge of container security, cloud‑native security controls (Azure, AWS, GCP), and API‑based vulnerability exposure.
  • Exposure to CMDB reconciliation and asset discovery in dynamic environments.
  • Experience presenting technical risk summaries to executive or audit stakeholders.
Equal Opportunity Employer

Starr is an equal opportunity employer, which means we'll consider all suitably qualified applicants regardless of gender identity or expression, ethnic origin, nationality, religion or beliefs, age, sexual orientation, disability status or any other protected characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management & Response Engineer
Vulnerability Management & Response Engineer

Dormont Manufacturing Co • Destin (FL)

On-site
USD 110,000 - 160,000
Vulnerability Management & Response Engineer
Vulnerability Management & Response Engineer

Starr • Destin (FL)

On-site
USD 95,000 - 120,000
First-class training and development opportunities
Inclusive environment for all employees
Senior Vulnerability Management & Response Engineer
Senior Vulnerability Management & Response Engineer

Dormont Manufacturing Co • Destin (FL)

On-site
USD 110,000 - 160,000
Vulnerability Management & Response Engineer
Vulnerability Management & Response Engineer

Starr Companies • Town of Florida (NY)

Hybrid
USD 100,000 - 130,000
First class training and development opportunities
Inclusive environment
Lead Enterprise Vulnerability Management & Response Engineer
Lead Enterprise Vulnerability Management & Response Engineer

Starr Companies • Town of Florida (NY)

Hybrid
USD 100,000 - 130,000
First class training and development opportunities
Inclusive environment
Vulnerability Manager
Vulnerability Manager

Green Key Resources • New York (NY)

On-site
USD 110,000 - 170,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Corporate Vice President - Head of Enterprise Vulnerability Management
Corporate Vice President - Head of Enterprise Vulnerability Management

New York Life • New York (NY)

On-site
USD 147,000 - 211,000
Vulnerability Management Lead
Vulnerability Management Lead

K2Share LLC • Washington

On-site
USD 120,000 - 180,000
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000