Vulnerability Management Engineer

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Workstreet

Workstreet

11 - 50 employees

Founded 2023

🔒 Cybersecurity

📋 Compliance

🤝 B2B

Cybersecurity • Compliance • B2B

Workstreet is a managed security and compliance services provider that helps businesses automate and modernize their security programs. With expertise in compliance frameworks including SOC 2, ISO 27001, HIPAA, and GDPR, Workstreet supports companies in achieving their security and compliance outcomes efficiently. Their services include acting as a virtual Chief Information Security Officer (vCISO), full-scale penetration testing, and vendor risk management, aiming to streamline security processes while allowing businesses to focus on growth.

📋 Description

• Orchestrate Vulnerability Scanning Infrastructure: Configure, schedule, and maintain authenticated credentials, scan policies, and asset groups across client networks and cloud-native environments using enterprise platforms (Tenable/Nessus, Qualys, Rapid7 InsightVM, and Vanta). • Execute Threat Analysis and Risk Prioritization: Evaluate raw scan outputs and filter false positives; apply advanced risk-based prioritization data utilizing CVSS base scores, EPSS real-time exploit indices, global threat intelligence feeds, and critical client asset contexts. • Drive Collaborative Remediation and Governance: Translate technical vulnerabilities into clear, actionable architectural guidance and patch-management workflows; partner directly inside the trenches with client software engineers and IT teams to multi-thread remediation efforts and accelerate their sub-30-day time-to-remediate velocity. • Manage Exceptions and Audit Compliance: Document, verify, and track formal client requests for temporary vulnerability exceptions or long-term risk acceptances; map operational patching data directly to control evidence required for regulatory audits (SOC 2, ISO 27001, HIPAA, CMMC, and NIST). • Own the Advisory Client Experience: Act as the strategic primary point of contact and trusted security advisor for an assigned portfolio of fast-growth startups; deliver regular project milestones, handle high-priority technical escalations with calm professionalism, and generate regular status reports and executive summaries that communicate technical risk as clear business value.

🎯 Requirements

• Proven enterprise vulnerability engineer - Command direct operational execution configuring, deploying, and maintaining industry-leading vulnerability discovery platforms, explicitly leveraging Tenable/Nessus, Qualys, Rapid7 InsightVM, or Vanta. • Surgical risk prioritizer - Mastered advanced risk scoring architectures including CVSS base scores and EPSS real-time exploit probability indices to isolate, rank, and target high-consequence threats. • Precision threat analyst - Deconstructed massive raw scanning datasets, systematically validated results to eliminate false positives, and converted intricate technical threat data into clear business risk metrics. • Advanced infrastructure posture auditor - Diagnosed, categorized, and cataloged diverse vulnerability classes, cloud/container exposure vectors, active exploit mechanisms, and configuration weaknesses across distributed system architectures. • GRC architecture strategist - Aligned automated infrastructure scanning protocols directly against regulatory compliance frameworks, specifically matching continuous monitoring records to strict audit evidence controls for SOC 2, ISO 27001, HIPAA, and CMMC. • High-velocity technical consultant - Engineered clear technical blueprints, structured project milestones, and progress matrices while simultaneously orchestrating deliverables across an active portfolio of client accounts. • Elite stakeholder diplomat - Built immediate trust and drove technical risk calibrations directly with US-based tech founders, engineering executives, and corporate leaders using clear, business-friendly communication. • Orchestration of patch management pipelines - Proven history managing full-lifecycle patch deployments, technical change management workflows, and remediation sequences alongside distributed IT, DevOps, and software engineering teams within a managed service provider (MSP/MSSP) or consulting environment. • Credentialed cybersecurity specialist - Hold active, validated professional industry markers such as CompTIA Security+, CEH, Tenable Certified Security Associate, or GIAC GEVA. • Cloud-native security engineering - Direct exposure mapping, configuring, and defending cloud-native vulnerability surfaces across public multi-cloud public hosting platforms, explicitly AWS, GCP, and Azure environments. • Command of threat intelligence syndication - Advanced navigation of the CVE lifecycle, National Vulnerability Database (NVD) registries, and active threat feed integrations to intercept and anticipate real-world exploits.

🏖️ Benefits

• Career Development: Clear path with mentorship and training opportunities • Technical Training: Comprehensive onboarding on security and compliance frameworks • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities. • Growth Opportunity: Early-stage company with significant room for career advancement. • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.

Apply Now

Similar Jobs

🔥 13 hours ago

Weekday (YC W21)

11 - 50

☁️ SaaS

🎯 Recruiter

Data Engineer responsible for designing, developing, and optimizing scalable cloud-based data platforms. Collaborate with cross-functional teams to ensure high-performance data solutions.

Apache

Azure

Cloud

ETL

Python

Spark

SQL

🔥 14 hours ago

Weekday

501 - 1000

👗 Fashion

🛒 Retail

🛍️ eCommerce

Microsoft Fabric Engineer for EazyML responsible for designing, developing, and maintaining scalable data platforms. This role focuses on building reliable data pipelines and leveraging AI for productivity.

Apache

Azure

Cloud

ETL

Python

Spark

SQL

🕒 3 days ago

Evnek

51 - 200

🤖 Artificial Intelligence

🏢 Enterprise

🤝 B2B

Ontology Engineer designing and maintaining semantic knowledge models. Collaborating with AI engineers to improve data integration and interoperability for enterprise applications.

Python

🕒 3 days ago

Sutherland

10,000+ employees

🤝 B2B

🤖 Artificial Intelligence

☁️ SaaS

Disaster Recovery Engineer at Sutherland implementing and supporting Disaster Recovery solutions across various environments. Collaborating with multiple teams to maintain cloud and data center operations.

🇮🇳 India – Remote

💰 $300M Secondary Market on 2014-10

⏰ Full Time

🟡 Mid-level

🟠 Senior

👷🏻‍♀️ Engineer

Cloud

Linux

🕒 5 days ago

Elfonze Technologies

201 - 500

🏢 Enterprise

☁️ SaaS

🤝 B2B

SailPoint ISC Engineer responsible for identity governance setup. Onboarding applications and configuring identity profiles for enterprise needs.

Cloud

ITSM