Vulnerability Management Specialist

Core Specialty Insurance Holdings, Inc.

Cincinnati (OH)

Hybrid

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental insurance
Life insurance
401(k) plan with company match
Wellness program

Job summary

A specialized insurance firm seeks a Vulnerability Management Specialist to manage their vulnerability program. The role involves conducting vulnerability scans, analyzing findings, and coordinating remediation efforts while ensuring compliance with security standards. Ideal candidates will have 4+ years in the field and knowledge of tools like Qualys. This position offers competitive salary and benefits, including health insurance and a retirement plan, while working in a hybrid environment between the Cincinnati and Dallas offices.

Qualifications

  • 4+ years of experience in vulnerability management, security engineering, or threat operations.
  • Hands-on experience with vulnerability scanning platforms, preferably Qualys.
  • Experience with endpoint management tools like Intune or JAMF.

Responsibilities

  • Conduct continuous vulnerability scanning across enterprise assets.
  • Analyze scan results to validate findings and assess exploitability.
  • Enforce remediation SLAs aligned to severity levels.

Skills

Analytical skills
Detail-oriented
Communication skills
Documentation skills

Tools

Qualys
PowerShell
Intune
JAMF

Job description

The Vulnerability Management Specialist is a hands‑on individual contributor responsible for executing Core Specialty’s vulnerability management program across endpoints, servers, cloud resources, and applications. This role focuses on continuous vulnerability scanning, risk analysis, remediation coordination, and reporting, working closely with IT, Infrastructure, Endpoint, and Threat teams.

The ideal candidate is highly analytical, detail‑oriented, and comfortable operating in a metrics‑driven, SLA‑based environment, with the ability to translate technical findings into actionable remediation guidance.

The selected candidate will be required to work a hybrid schedule (3 days in office/2 remote) out of our Dallas, TX, or Cincinnati, OH office. No relocation assistance is being offered with this role.

Key Accountabilities/Deliverables
  • Conduct continuous vulnerability scanning across enterprise assets using Qualys and related tools.
  • Analyze scan results to validate findings, remove false positives, and assess exploitability.
  • Prioritize vulnerabilities using CVSS, Qualys Detection Score (QDS), asset criticality, and business impact.
  • Enforce remediation SLAs aligned to severity levels: Critical: 7 days, High: 30 days, Medium: 60 days, Low: 180 days.
  • Partner with Infrastructure, EUC, Cloud, and Application teams to drive timely remediation.
  • Support remediation activities using Qualys, Intune, JAMF, PolicyPak, and Microsoft Defender.
  • Ensure vulnerability management activities aligned with NIST, CIS Controls, ISO 27001, and insurance regulatory expectations.
  • Partner with Threat Intelligence and SOC teams to assess vulnerability exposure related to active threats.
  • Develop scripts (PowerShell) and workflows to support remediation, reporting, and validation.
Technical Knowledge and Understanding
  • Strong understanding of: CVSS scoring and risk prioritization, patch management and remediation workflows, endpoint, server, and cloud security fundamentals.
  • Ability to analyze technical findings and communicate risk clearly to non‑security teams.
  • Strong documentation and organizational skills.
Experience required
  • 4+ years of experience in vulnerability management, security engineering, or threat operations.
  • Hands‑on experience with vulnerability scanning platforms (Qualys preferred; Tenable/Rapid7 acceptable).
  • Experience working with Intune, JAMF, or similar endpoint management tools.
Certifications (Preferred)
  • CompTIA Security+
  • Qualys Vulnerability Management certifications
  • GIAC certifications (e.g., GSEC, GCIH)
  • CISSP (or progress toward certification)

Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa for this position.

At Core Specialty, you will receive a competitive salary and opportunities for professional development and advancement. We offer medical, dental, vision, and life insurances; short and long‑term disability; a Company‑match of 100% of a 6% contribution 401(k) plan; an Employee Assistance Plan; Health Savings Account, Flexible Spending Account, Health Reimbursement Account, and a wellness program

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Specialist
Vulnerability Management Specialist

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

Hybrid
USD 80,000 - 100,000
Medical, dental, vision, and life insurance
Short and long-term disability insurance
401(k) plan with company match
+1
Vulnerability Management Specialist
Vulnerability Management Specialist

Core Specialty Insurance Holdings, Inc. • Cincinnati (OH)

Hybrid
USD 85,000 - 110,000
Medical, dental, and vision insurance
401(k) plan with company match
Employee Assistance Plan
+1
Vulnerability Management Specialist
Vulnerability Management Specialist

Kalepa Insurance Services, LLC • Cincinnati (OH)

Hybrid
Medical insurance
Dental insurance
401(k) with company match
Hybrid Vulnerability Management Specialist
Hybrid Vulnerability Management Specialist

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

Hybrid
USD 80,000 - 100,000
Medical, dental, vision, and life insurance
Short and long-term disability insurance
401(k) plan with company match
+1
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000
Vulnerability Management Lead
Vulnerability Management Lead

K2Share LLC • Washington

On-site
USD 120,000 - 180,000
Vulnerability Management and Security Engineering
Vulnerability Management and Security Engineering

RennerBrown • New York (NY)

On-site
USD 140,000 - 190,000
Vulnerability Engineer
Vulnerability Engineer

CBTS • United States

On-site
USD 80,000 - 85,000
Vulnerability Management SME 4674
Vulnerability Management SME 4674

Tier4 Group • Atlanta (GA)

On-site
USD 90,000 - 120,000
Competitive compensation
Excellent benefits
Hybrid schedule
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Compunnel, Inc. • Irving (TX)

On-site
USD 100,000 - 130,000