Security Engineer, Vulnerability Management
The Security Engineer III is a role designed for individuals with experience in cybersecurity and IT systems. They support vulnerability management program processes and procedures, using enterprise security tools to facilitate vulnerability identification and reporting. As a Security Engineer, you will frequently interact with members of all our brand's Security and IT teams, as well as third-party platform providers. In this dynamic, global environment, you will be responsible for facilitating vulnerability scanning and penetration testing, communicating vulnerability findings, and tracking vulnerability remediation efforts.
Key Responsibilities
- Configure and maintain vulnerability management and penetration testing platforms
- Plan, execute, and assess vulnerability scanning and penetration testing services
- Manage the output from vulnerability scanning and penetration testing to provide comprehensive reporting details of the vulnerabilities, their potential impact, and suggested remediations as needed
- Act as a technical specialist, providing technical support for vulnerability management initiatives and penetration testing engagements
- Collaborate across functions to ensure vulnerability management, security programs, and technical controls comply with policies, laws, and regulations.
- Drive remediation efforts by partnering with system owners and developers to automate, prioritize and assist in resolving high-risk vulnerabilities
- Facilitate penetration testing engagements between external vendors and internal teams to uncover and address security weaknesses
- Create and update processes and procedures, along with supporting documentation, for the vulnerability management program
- Provide training, guidance, and mentorship to team members on vulnerability management practices and tools
- Facilitate vulnerability management reviews and audits with teams
- Stay current with emerging threats and vulnerabilities and proactively assess their potential impact on the organization
Qualifications
- Bachelor’s degree in computer science, information security, or a related field
- 3+ years of experience in vulnerability management or related field
- Strong knowledge of vulnerability management tools and methodologies (e.g., Nessus, Qualys, Rapid7).
- Excellent analytical and problem-solving skills with the ability to tackle complex technical challenges.
- Ability to solve problems in a dynamic team environment and handle multiple assignments in a timely manner.
- Strong communication skills and the ability to work collaboratively with cross-functional teams.
- Demonstrated initiative in improving processes, mentoring others, and expanding technical capabilities.
Salary Range: $117,800 to $162,200 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate’s location, experience, and other job-related factors.