Vulnerability Management Specialist

Core Specialty Insurance Services, Inc.

Cincinnati (OH)

Hybrid

USD 80,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision, and life insurance
Short and long-term disability insurance
401(k) plan with company match
Wellness program

Job summary

Core Specialty Insurance Services, Inc. is seeking a Vulnerability Management Specialist based in Cincinnati, OH. This individual contributor will execute the company's vulnerability management program across endpoints, servers, and cloud resources.

The ideal candidate has 4+ years of experience in vulnerability management and strong knowledge of scanning platforms like Qualys. The role includes a mix of in-office and remote work with a focus on continuous vulnerability scanning and risk analysis.

Comprehensive benefits package includes various insurances and professional development opportunities.

Qualifications

  • 4+ years of experience in vulnerability management or related security fields.
  • Hands-on experience with vulnerability scanning platforms.
  • Strong understanding of CVSS scoring and patch management.

Responsibilities

  • Conduct continuous vulnerability scanning across enterprise assets.
  • Prioritize vulnerabilities using CVSS and assess exploitability.
  • Partner with teams to drive timely remediation.

Skills

Vulnerability management
Security engineering
Threat operations
Documentation skills
Risk analysis

Education

Preferred certifications: CompTIA Security+, GIAC (e.g., GSEC, GCIH), CISSP

Tools

Qualys
Intune
JAMF
PowerShell

Job description

Job Summary

The Vulnerability Management Specialist is a hands‑on individual contributor responsible for executing Core Specialty’s vulnerability management program across endpoints, servers, cloud resources, and applications. The role focuses on continuous vulnerability scanning, risk analysis, remediation coordination, and reporting, working closely with IT, Infrastructure, Endpoint, and Threat teams in a metrics‑driven, SLA‑based environment.

Key Responsibilities
  • Conduct continuous vulnerability scanning across enterprise assets using Qualys and related tools.
  • Analyze scan results to validate findings, remove false positives, and assess exploitability.
  • Prioritize vulnerabilities using CVSS, Qualys Detection Score (QDS), asset criticality, and business impact.
  • Enforce remediation SLAs aligned to severity levels: Critical: 7 days, High: 30 days, Medium: 60 days, Low: 180 days.
  • Partner with Infrastructure, EUC, Cloud, and Application teams to drive timely remediation.
  • Support remediation activities using Qualys, Intune, JAMF, PolicyPak, and Microsoft Defender.
  • Ensure vulnerability management activities align with NIST, CIS Controls, ISO 27001, and insurance regulatory expectations.
  • Partner with Threat Intelligence and SOC teams to assess vulnerability exposure related to active threats.
  • Develop scripts (PowerShell) and workflows to support remediation, reporting, and validation.
Qualifications
  • 4+ years of experience in vulnerability management, security engineering, or threat operations.
  • Hands‑on experience with vulnerability scanning platforms (Qualys preferred; Tenable/Rapid7 acceptable).
  • Experience working with Intune, JAMF, or similar endpoint management tools.
  • Strong understanding of CVSS scoring and risk prioritization, patch management and remediation workflows, endpoint, server, and cloud security fundamentals.
  • Ability to analyze technical findings and communicate risk clearly to non‑security teams.
  • Strong documentation and organizational skills.
  • Preferred certifications: CompTIA Security+, Qualys Vulnerability Management certifications, GIAC certifications (e.g., GSEC, GCIH), CISSP or progress toward certification.
Employment Details

Hybrid schedule: 3 days in office and 2 days remote, based out of Dallas, TX or Cincinnati, OH. No relocation assistance is offered.

Eligible candidates must be authorized to work in the United States; no visa sponsorship will be provided.

Benefits
  • Competitive salary and opportunities for professional development and advancement.
  • Medical, dental, vision, and life insurance.
  • Short and long‑term disability insurance.
  • Company‑match 100% of a 6% contribution 401(k) plan.
  • Employee Assistance Plan.
  • Health Savings Account, Flexible Spending Account, Health Reimbursement Account.
  • Wellness program.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Specialist
Vulnerability Management Specialist

Core Specialty Insurance Holdings, Inc. • Cincinnati (OH)

Hybrid
Medical insurance
Dental insurance
Life insurance
+2
Vulnerability Management Specialist
Vulnerability Management Specialist

Kalepa Insurance Services, LLC • Cincinnati (OH)

Hybrid
USD 90,000 - 125,000
Medical insurance
Dental insurance
401(k) with company match
+1
Vulnerability Management Specialist
Vulnerability Management Specialist

Core Specialty Insurance Holdings, Inc. • Cincinnati (OH)

Hybrid
USD 85,000 - 110,000
Medical, dental, and vision insurance
401(k) plan with company match
Employee Assistance Plan
+1
Vulnerability Management SME 4674
Vulnerability Management SME 4674

Tier4 Group • Atlanta (GA)

On-site
USD 90,000 - 120,000
Competitive compensation
Excellent benefits
Hybrid schedule
Hybrid Vulnerability Management Specialist
Hybrid Vulnerability Management Specialist

Core Specialty Insurance Services, Inc. • Cincinnati (OH)

Hybrid
USD 80,000 - 100,000
Medical, dental, vision, and life insurance
Short and long-term disability insurance
401(k) plan with company match
+1
Vulnerability Engineer
Vulnerability Engineer

CBTS • United States

On-site
USD 80,000 - 85,000
Vulnerability Management Lead
Vulnerability Management Lead

K2Share LLC • Washington

On-site
USD 120,000 - 180,000
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000
Vulnerability Management Manager
Vulnerability Management Manager

Considine Search • New York (NY)

On-site
USD 200,000 - 215,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

Compunnel, Inc. • Irving (TX)

On-site
USD 100,000 - 130,000