Vulnerability Management & Security Controls Engineer

AVG

Tempe (AZ)

On-site

USD 110,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Gen is seeking an independent security professional who thrives at the intersection of security, DevOps, and delivery. You will translate legal and security requirements into actionable vulnerability management programs that operate across Security and DevOps teams.

You will design and improve the vulnerability management lifecycle from identification to remediation, integrate SAST/DAST/SCA into CI/CD, and collaborate with a Senior PM to align scope, timelines and reporting to senior leadership.

Qualifications

  • A degree in IT or a related field, ideally with a focus on cybersecurity.
  • 3+ years in vulnerability management, security engineering, or security program delivery in a cloud/software environment.
  • Ability to work independently and drive outcomes across multiple teams.
  • Understanding of regulatory security requirements and demonstrated experience with frameworks (ISO 27001, NIS2, SOC 2, GDPR, PCI DSS).
  • Strong translation skills: turn policy into developer-ready user stories, acceptance criteria, remediation tasks, and runbooks.
  • Hands-on with work tracking tools (Jira, Azure DevOps) and crafting leadership dashboards.
  • Strong communication; able to analyze vulnerability trends and root causes.
  • Understanding of modern SDLC/DevOps practices (CI/CD, IaC).
  • Experience in cloud environments (AWS/Azure/GCP).
  • Wry sense of humor is a plus.

Responsibilities

  • Translate requirements into prioritized, testable tasks for engineering and platform teams.
  • Own the vulnerability management lifecycle across infrastructure, cloud, apps, containers, and third‑party components.
  • Integrate security into CI/CD with SAST, DAST, SCA, container, IaC, and cloud configuration scanning.
  • Coordinate work across multiple security domains and DevOps/Platform teams.
  • Build delivery plans, track milestones, manage dependencies, and maintain Jira/Azure Boards.
  • Align with product owners, architects, and security SMEs; resolve blockers.
  • Develop actionable dashboards showing vulnerability aging, SLAs, backlog trends and risk.
  • Map vulnerability practices to regulatory frameworks and collect evidence for audits.
  • Standardize templates and automate playbooks to reduce manual triage.
  • Work with a Senior PM to align scope, timelines, and deadlines.

Skills

Vulnerability management
Cross-team ownership
Regulatory frameworks
Policy to requirements
Jira/Azure DevOps
Communication
SDLC/DevOps
Cloud (AWS/Azure/GCP)
Humor

Education

IT/related degree

Tools

Jira
Azure DevOps

Job description

Gen is seeking an independent security professional who thrives at the intersection of security, DevOps, and delivery. You will translate legal and security requirements into actionable vulnerability management programs that operate across Security and DevOps teams.

You will design and improve the vulnerability management lifecycle from identification to remediation, integrate SAST/DAST/SCA into CI/CD, and collaborate with a Senior PM to align scope, timelines and reporting to senior leadership.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Controls Engineer
Security Controls Engineer

AVG • Tempe (AZ)

On-site
USD 110,000 - 160,000
Vulnerability Management Engineer — AI-Driven Security
Vulnerability Management Engineer — AI-Driven Security

AppFolio • San Diego (CA)

On-site
USD 104,000 - 130,000
Senior Vulnerability Management Engineer (Hybrid)
Senior Vulnerability Management Engineer (Hybrid)

Datadog • New York (NY)

Hybrid
USD 180,000 - 250,000
New hire RSUs
Employee stock purchase plan
Career development
+4
Vulnerability Management Engineer — AI-Driven Security
Vulnerability Management Engineer — AI-Driven Security

AppFolio • Santa Barbara (CA)

Hybrid
USD 104,000 - 130,000
Senior Remote Vulnerability Management Engineer
Senior Remote Vulnerability Management Engineer

Agility Technologies Inc • United States

Remote
USD 110,000 - 150,000
401(k) matching
Dental insurance
Health insurance
+3
Vulnerability Management Lead: Drive Security Remediation
Vulnerability Management Lead: Drive Security Remediation

Altice USA • Norwalk (CT)

Hybrid
USD 150,000 - 210,000
Vulnerability Management Lead: Risk & Remediation Strategy
Vulnerability Management Lead: Risk & Remediation Strategy

VOLTO Consulting • Dallas (TX)

On-site
Confidential
Vulnerability Management Engineer, AI-Driven Remediation
Vulnerability Management Engineer, AI-Driven Remediation

Steelcase • Grand Rapids (MI)

Hybrid
USD 110,000 - 150,000
Hybrid work schedule
Continuing education and learning
Inclusive culture
+1
Vulnerability Management Specialist – Drive Secure SaaS
Vulnerability Management Specialist – Drive Secure SaaS

AppFolio • Chicago (IL)

On-site
USD 104,000 - 130,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

PCI Professional Services • United States

On-site
USD 110,000 - 160,000