Engineer III, Vulnerability Management

🕒 Agosto 18

🤠 Texas – Remoto

infoinfo

⏰ Tempo Integral

🟠 Sênior

🔴 Especialista

👷🏻‍♀️ Engenheiro

👻 Score fantasma 10%

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Cencora

Cencora

10.000+ funcionários

💼 Consultoria

📦 Logística

🏥 Saúde

Consulting • Logistics • Healthcare

A Cencora é uma empresa dedicada a melhorar a saúde e o bem-estar de pessoas e animais em escala global. Com base no legado da AmerisourceBergen, a Cencora oferece uma ampla gama de soluções líderes do setor que abrangem logística especializada, armazenagem, pesquisa de medicamentos, suporte ao desenvolvimento clínico e muito mais. Ela fornece suporte à comercialização e acesso de pacientes e oferece serviços de distribuição atacadista e especializada. A Cencora atende um público diversificado, incluindo empresas farmacêuticas, consultórios médicos, farmácias e sistemas de saúde. A empresa também estende seus serviços para a saúde animal, gerenciando operações e entregando produtos para o cuidado farmacêutico animal. Com uma forte presença global, a Cencora tem como objetivo reformular a prestação de serviços de saúde por meio de produtos e soluções inovadoras, esforçando-se para criar futuros mais saudáveis para todos.

Descrição

• Perform advanced vulnerability analysis across infrastructure, cloud, endpoint, network, application, SaaS, and externally facing assets • Lead and support Continuous Threat Exposure Management (CTEM) processes, including scoping, discovery, prioritization, validation, mobilization, and ongoing risk reduction • Operate and improve vulnerability management, attack surface management, external posture management, cloud posture, and SaaS posture capabilities • Analyze and normalize vulnerability and posture data and develop risk-based remediation priorities • Assess vulnerabilities using business context, asset criticality, exploitability, threat intelligence, exposure, compensating controls, and regulatory or compliance impact • Drive remediation and risk treatment with infrastructure, cloud, network, application, endpoint, DevOps, and business technology teams • Lead emerging vulnerability and critical exposure response, including impact analysis, stakeholder coordination, mitigation tracking, and executive-level reporting • Create and maintain dashboards, metrics, and reporting for vulnerability trends, remediation progress, SLA performance, exposure reduction, attack surface changes, and program maturity • Support unified vulnerability management workflows, including ticketing, ownership assignment, exception handling, rescan validation, remediation automation, and governance • Evaluate and recommend improvements to scanning coverage, asset inventory quality, vulnerability data integrity, risk scoring, and stakeholder reporting • Translate technical findings into remediation guidance and concise risk summaries for leadership • Contribute to security standards, procedures, playbooks, documentation, and continuous improvement initiatives • Mentor junior engineers and analysts on vulnerability triage and remediation governance

🎯 Requisitos

• Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Engineering, or a related field, or equivalent practical experience • 7–10 years of combined experience in information technology, cybersecurity, systems administration, cloud operations, network security, application security, security engineering, or related disciplines • At least 4 years of hands-on experience in vulnerability management, exposure management, attack surface management, configuration assurance, or a closely related cybersecurity function • At least one active cybersecurity certification, such as CISSP, CISM, Security+, CySA+, GSEC, CCSK, CCSP, OSCP, GIAC certification, or another recognized security certification • Strong understanding of vulnerability lifecycle management, including discovery, validation, prioritization, remediation, exception handling, rescan validation, and reporting • Experience with vulnerability assessment or vulnerability management platforms such as Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Wiz, Armis, or comparable tools • Experience with attack surface, posture, or exposure management capabilities such as CAASM, EASM, RBVM, CSPM, SSPM, external posture management, or security ratings platforms • Ability to interpret CVEs, CVSS, EPSS, threat intelligence, exploitability indicators, asset context, and compensating controls to prioritize risk • Experience with enterprise asset data, CMDB data, ownership models, assignment groups, and business criticality attributes • Experience using Excel, Power BI, SQL, data lakes, reporting platforms, or other data analysis and visualization tools • Working knowledge of NIST CSF, NIST 800-53, ISO 27001, CIS Critical Security Controls, PCI DSS, HIPAA, GDPR, OWASP Top 10, SANS Top 25, and MITRE ATT&CK • Excellent written and verbal communication skills • Demonstrated ability to coordinate cross-functional remediation activities in a complex enterprise environment • Preferred: experience building or maturing CTEM, exposure management, or unified risk-based vulnerability management programs • Preferred: experience with vulnerability workflow automation, ServiceNow SecOps, Jira, SOAR, or similar platforms • Preferred: experience consolidating and normalizing vulnerability data across multiple source tools • Preferred: cloud security and cloud posture management across AWS, Azure, Google Cloud, or hybrid environments • Preferred: external attack surface management, SaaS security posture management, configuration assurance, or third-party exposure management • Preferred: regulatory, audit, customer assurance, or compliance reporting experience • Preferred: scripting or automation using Python, PowerShell, APIs, or query languages • Ability to influence without direct authority and lead cross-functional initiatives

🏖️ Benefícios

• Medical, dental, and vision care • Backup dependent care • Adoption assistance • Infertility coverage • Family building support • Behavioral health solutions • Paid parental leave • Paid caregiver leave • Training programs • Professional development resources • Mentorship programs • Employee resource groups • Volunteer activities

Candidatar-se

Vagas Similares

🕒 Agosto 18

Anduril Industries

501 - 1000

🏭 Manufatura

💼 Consultoria

📦 Logística

Airworthiness Engineer certifying developmental and production military aircraft for Anduril, a defense technology company. Supporting flight releases, FAA integration, airworthiness boards, and digital certification planning.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $146.000 - $194.000 / ano

⏰ Tempo Integral

🟠 Sênior

👷🏻‍♀️ Engenheiro

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Agosto 18

Fieldguide

11 - 50

💼 Consultoria

🏥 Saúde

🤖 Inteligência Artificial

Audit Methodology Engineer translating AICPA and PCAOB standards into AI-powered audit workflows for Fieldguide’s trust automation software. Partnering with product, engineering, and AI teams to maintain accurate, explainable methodology content.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $170.000 - $205.000 / ano

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🦅 Patrocina Visto H1B

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Agosto 18

Boyd Gaming

10.000+ funcionários

🍽️ Alimentos e Bebidas

✈️ Turismo

🎲 Jogos de Azar

Facilities Engineer II maintaining HVAC, plumbing, electrical, and building systems for Boyd Gaming’s United States casino operations. Responding to emergencies, performing preventive maintenance, and overseeing renovations.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $18 / hora

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Agosto 18

Whatnot

201 - 500

💼 Consultoria

📦 Logística

📣 Marketing

Threat Detection and Response Engineer protecting Whatnot’s live commerce marketplace. Investigating cyber incidents across endpoints and cloud environments while improving detection and response playbooks.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $175.000 - $260.000 / ano

💰 $260.000.000 Series D em 2022-07

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🦅 Patrocina Visto H1B

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Agosto 18

Pax8

1001 - 5000

🏪 Marketplace

🤝 B2B

☁️ SaaS

Technology Services Engineer securing identity, access, and automation for Pax8’s global cloud marketplace. Supporting Entra, Azure, IAM governance, scripting, and infrastructure-as-code initiatives.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $65.000 - $95.000 / ano

💰 $50.000.000 Debt Financing - Pax8 em 2023-09

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🦅 Patrocina Visto H1B

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório