Security Specialist, Vulnerability Management

🔥 19 hours ago

🏄 California – Remote

infoinfo

💵 $120k - $175k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 12%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of AXON Networks

AXON Networks

201 - 500 employees

Founded 2021

💼 Consulting

📦 Logistics

📣 Marketing

Consulting • Logistics • Marketing

AXON Networks is a technology company focused on developing innovative networking solutions. They specialize in providing advanced connectivity options and data management systems tailored for various industries, enhancing communication and operational efficiency.

📋 Description

• Establish and operate a risk-based vulnerability management capability across cloud platforms, applications, Kubernetes and container environments, network infrastructure, software supply chains and cloud-managed customer-premises equipment • Establish authoritative vulnerability visibility across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware and CPE asset classes • Inventory the attack surface and define coverage for internet-facing and internal assets, cloud services, hosts, network devices, containers, Kubernetes clusters, applications, APIs, source code, dependencies, images, infrastructure as code and CPE/firmware • Design, configure and maintain authenticated and unauthenticated scans, agent-based assessments, cloud-native configuration checks, container and dependency scans, external attack-surface discovery and targeted validation tests • Establish safe scan windows, credentials, rate limits, exclusions and testing procedures to avoid destabilizing production, customer environments or CPE fleets • Evaluate, select and administer vulnerability-management and scanning tools such as Tenable Nessus, Qualys, Rapid7, Wiz, Orca, Prisma Cloud, Snyk, Veracode, Checkmarx, Trivy, Grype and Nuclei • Measure coverage, scan health, credential success, stale assets and blind spots; improve asset-to-owner mapping and data quality • Review findings and determine whether they are true positives, false positives, duplicates, accepted risks, mitigated conditions or actionable vulnerabilities • Analyze CVE applicability using affected components and versions, package provenance, CPE or firmware SBOMs, runtime reachability, configuration, network exposure, privileges, exploit prerequisites and existing controls • Reproduce or safely validate material findings using advisories, proof-of-concept analysis, logs, configuration evidence, package inspection and non-production testing • Monitor vulnerability intelligence and vendor advisories for cloud, Kubernetes, Linux, networking, broadband/CPE, open-source and commercial technologies • Prioritize remediation using CVSS, CISA KEV, EPSS, exploit availability, exposure, reachability, asset criticality, tenant/customer impact and compensating controls • Define remediation and mitigation targets by risk tier and escalate actively exploited or internet-reachable vulnerabilities • Create remediation records with affected assets, evidence, owners, due dates, recommended actions, validation criteria and customer or operational considerations • Partner with Engineering and DevOps on patches, upgrades, configuration changes, image rebuilds, dependency updates, firmware releases and compensating controls; verify closure through rescans or equivalent evidence • Manage risk exceptions with documented rationale, accountable approval, compensating controls, expiration dates and scheduled reassessment • Assess end-to-end security across cloud control planes, APIs, device-management protocols, access networks, gateways, routers, ONTs and connected-home devices • Work with Engineering to identify affected device models, hardware revisions, firmware branches, software components and deployed cohorts; support safe remediation and rollout validation • Build automation and integrations for asset enrichment, deduplication, risk scoring, ticket creation, ownership routing, SLA tracking, notifications, rescans, exception expiry and evidence collection • Maintain dashboards for coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, asset ownership and risk trends • Develop playbooks, standards and procedures for routine vulnerability handling, critical CVEs, zero-day response, scanner administration and tool outages • Report to technical owners and leaders, separating raw finding volume from material risk and identifying decisions or overdue actions • Support audits and customer security inquiries with traceable evidence while protecting sensitive vulnerability and customer information • Coordinate with Engineering, DevOps, NOC, Support, Product and Compliance to reduce measurable exposure without disrupting customer service

🎯 Requirements

• 5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security or a closely related discipline • Enterprise scanning and vulnerability-management workflow experience, including scanner configuration, authenticated scanning, coverage analysis, finding validation, false-positive handling, remediation tracking and rescanning • Strong CVE analysis skills, including determining applicability and exploitability using versions, configurations, exposure, reachability, privileges, controls and business context • Experience with enterprise vulnerability platforms and complementary cloud, container, dependency, application and open-source scanning tools • Working knowledge of CVE/CWE, NVD, CVSS, CISA KEV, EPSS, vendor advisories, software bills of materials and risk-based prioritization • Hands-on knowledge of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers and Kubernetes • Ability to read code, package manifests, container images, configurations, logs and network evidence • Scripting or programming ability in Python, Go, PowerShell, Bash or a comparable language • Experience integrating security platforms with APIs, ticketing and dashboards • Strong written and verbal communication skills for explaining technical risk, uncertainty, tradeoffs and decisions • Bachelor’s degree in cybersecurity, computer science, engineering or equivalent practical experience • Ability to work primarily during normal business hours with escalation availability for critical, actively exploited or zero-day vulnerabilities • Ability to handle sensitive vulnerability, exploit and customer information with strict need-to-know access and evidence controls • Ability to coordinate intrusive scans, validation tests and production-impacting work through approved change and maintenance processes • Willingness and ability to participate in an on-call rotation • Must be eligible to work without visa sponsorship; AXON Networks is unable to offer visa sponsorship

🏖️ Benefits

• Fully remote within North America • On-call escalation availability for critical, actively exploited or zero-day vulnerabilities • Equal-opportunity and inclusive working environment

Apply Now

Similar Jobs

🔥 20 hours ago

Catalyst Acoustics Group

201 - 500

🏗️ Construction

🏭 Manufacturing

🔧 Hardware

Information Security Manager owning cybersecurity governance and hands-on operations for Catalyst Acoustics Group's multi-brand manufacturing business. Managing Microsoft 365, Azure, EDR, incident response, and security vendors.

🔥 21 hours ago

LG Energy Solution Vertech, Inc.

51 - 200

🏭 Manufacturing

💼 Consulting

📦 Logistics

Cybersecurity Specialist III securing LGES Vertech’s energy storage systems through incident response, SIEM, vulnerability management, AWS, EDR, and IAM operations. Supporting audits, risk governance, and cross-functional security engineering.

🕒 Yesterday

Koniag Government Services

1001 - 5000

🏛️ Government

🎖️ Defense

💼 Consulting

Remote front desk security specialist providing virtual access control, visitor credentialing, and security monitoring. Supporting Koniag’s federal government customers and facility security operations.

🕒 Yesterday

Chinook Systems Inc.

11 - 50

🏗️ Construction

📦 Logistics

⚡ Energy

Cybersecurity OT Specialist designing and hardening industrial control systems for Chinook Systems’ energy-secure facilities. Conducting ICS risk assessments, compliance engineering, and client-site cybersecurity implementations.

🕒 Yesterday

Palo Alto Networks

10,000+ employees

🔒 Cybersecurity

🏢 Enterprise

AI Security Domain Consulting Manager leading Prisma AIRS pre-sales teams at Palo Alto Networks. Securing customers’ AI agents, applications, data, and enterprise adoption.