Vulnerability Management & Security Controls Engineer

AVG

Tempe (AZ)

On-site

USD 110,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gen is seeking an independent security professional who thrives at the intersection of security, DevOps, and delivery. You will translate legal and security requirements into actionable vulnerability management programs that operate across Security and DevOps teams.

You will design and improve the vulnerability management lifecycle from identification to remediation, integrate SAST/DAST/SCA into CI/CD, and collaborate with a Senior PM to align scope, timelines and reporting to senior leadership.

Qualifications

  • A degree in IT or a related field, ideally with a focus on cybersecurity.
  • 3+ years in vulnerability management, security engineering, or security program delivery in a cloud/software environment.
  • Ability to work independently and drive outcomes across multiple teams.
  • Understanding of regulatory security requirements and demonstrated experience with frameworks (ISO 27001, NIS2, SOC 2, GDPR, PCI DSS).
  • Strong translation skills: turn policy into developer-ready user stories, acceptance criteria, remediation tasks, and runbooks.
  • Hands-on with work tracking tools (Jira, Azure DevOps) and crafting leadership dashboards.
  • Strong communication; able to analyze vulnerability trends and root causes.
  • Understanding of modern SDLC/DevOps practices (CI/CD, IaC).
  • Experience in cloud environments (AWS/Azure/GCP).
  • Wry sense of humor is a plus.

Responsibilities

  • Translate requirements into prioritized, testable tasks for engineering and platform teams.
  • Own the vulnerability management lifecycle across infrastructure, cloud, apps, containers, and third‑party components.
  • Integrate security into CI/CD with SAST, DAST, SCA, container, IaC, and cloud configuration scanning.
  • Coordinate work across multiple security domains and DevOps/Platform teams.
  • Build delivery plans, track milestones, manage dependencies, and maintain Jira/Azure Boards.
  • Align with product owners, architects, and security SMEs; resolve blockers.
  • Develop actionable dashboards showing vulnerability aging, SLAs, backlog trends and risk.
  • Map vulnerability practices to regulatory frameworks and collect evidence for audits.
  • Standardize templates and automate playbooks to reduce manual triage.
  • Work with a Senior PM to align scope, timelines, and deadlines.

Skills

Vulnerability management
Cross-team ownership
Regulatory frameworks
Policy to requirements
Jira/Azure DevOps
Communication
SDLC/DevOps
Cloud (AWS/Azure/GCP)
Humor

Education

IT/related degree

Tools

Jira
Azure DevOps

Job description

Gen is seeking an independent security professional who thrives at the intersection of security, DevOps, and delivery. You will translate legal and security requirements into actionable vulnerability management programs that operate across Security and DevOps teams.

You will design and improve the vulnerability management lifecycle from identification to remediation, integrate SAST/DAST/SCA into CI/CD, and collaborate with a Senior PM to align scope, timelines and reporting to senior leadership.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Controls Engineer
Security Controls Engineer

AVG • Tempe (AZ)

On-site
USD 110,000 - 160,000
Security Controls Engineer
Security Controls Engineer

Gen • Tempe (AZ)

On-site
USD 90,000 - 150,000
Vulnerability & Exposure Security Engineer
Vulnerability & Exposure Security Engineer

Datavant2 • United States

On-site
USD 152,000 - 185,000
Vulnerability Management Analyst - Drive Global Security
Vulnerability Management Analyst - Drive Global Security

Inspired-Thinking-Group- • Birmingham (AL)

On-site
USD 90,000 - 130,000
25 days holiday
Wellbeing Day
Family-friendly leave
Senior Vulnerability & Platform Engineering Leader
Senior Vulnerability & Platform Engineering Leader

Capgemini • New York (NY)

On-site
USD 67,733 - 108,811
Vacation time 12-25 days
Medical, dental, and vision coverage
401(k) retirement plan
Vulnerability Management Leader, Senior Security
Vulnerability Management Leader, Senior Security

Alter Domus • New York (NY)

On-site
USD 180,000 - 240,000
Professional accreditations support
Flexible work arrangements
Generous holidays
+3
Vulnerability & Cloud Security Architect (Senior)
Vulnerability & Cloud Security Architect (Senior)

Francisco Partners • United States

On-site
USD 140,000 - 190,000
Vulnerability Management Engineer (Hybrid)
Vulnerability Management Engineer (Hybrid)

Ulta Beauty, Inc. • Bolingbrook (IL)

Hybrid
USD 91,000 - 120,000
Health insurance
Paid time off
Life insurance
+1
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Cybersecurity Engineer - Vulnerability Management
Cybersecurity Engineer - Vulnerability Management

Janestreet • New York (NY)

On-site
USD 100,000 - 130,000