Vulnerability Management Consultant Remote Location

Remote • Posted 2 days ago • Updated 2 days ago
Contract Corp To Corp
Contract W2
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🎯 Assessing qualifications...

Job Details

Skills

  • Vulnerability

Summary

Job Title: Vulnerability management Analyst

Location: Remote

Job Description:

We are seeking a technically strong Vulnerability Management Analyst Engineer to lead vulnerability identification, prioritization, and remediation across infrastructure, web applications, and cloud environments. This role combines handson scanning, threatinformed prioritization, crossfunctional remediation coordination to reduce risk and improve timetoremediation.

Experience

5+ years of vulnerability management, application security, or penetration testing experience preferred.

Key Responsibilities

Lead the endtoend vulnerability management lifecycle: discovery, validation, riskbased prioritization, remediation coordination, and remediation verification.

Execute vulnerability assessments across onpremises, cloud (AWS, Azure, Google Cloud Platform), containerized, infrastructure, and web application environments to maintain comprehensive asset coverage and risk visibility.

Perform and validate infrastructure, application, and dynamic web testing (DAST), including manual verification of OWASP Top 10 and SANS Top 25 vulnerabilities (e.g., SQLi, XSS, CSRF, SSRF, IDOR, auth bypass) using industrystandard tools (Tenable, Wiz, Qualys, Rapid7, Burp Suite, OWASP ZAP).

Apply threatinformed prioritization using CVSS, EPSS, CISA advisories, exploit intelligence, and business impact to reduce critical risk and mean time to remediation (MTTR).

Operate, tune, and optimize vulnerability scanning platforms, asset discovery, and reporting pipelines to ensure accurate coverage and actionable findings.

Partner with Infrastructure, Engineering, DevOps, Application, Cloud, Threat Intelligence, and Automation teams to drive remediation, establish secure baselines, and respond to zeroday or imminent threats.

Produce and present technical and executivelevel reports, dashboards, and metrics highlighting remediation SLAs, risk reduction, and program maturity.

Contribute to security best practices, secure coding standards, threat modeling, and risk assessments for application and infrastructure initiatives.

Stay current on emerging vulnerabilities, attack techniques, and vulnerability management tooling to continuously improve program effectiveness.

Required Qualifications & Skills

Proven experience identifying, validating, and remediating vulnerabilities across web applications, networks, systems, and cloud environments.

Handson proficiency with VM assessment and application security tools like: Tenable (NessusVMDR), Wiz, Qualys, Rapid7, Burp Suite, OWASP ZAP, Checkmarx, Veracode, Insight AppSec.

Familiarity with vulnerability prioritization frameworks and metrics (OWASP Top 10, SANS Top 25, CVSS, EPSSCISA).

Strong analytical, problemsolving, and writtenverbal communication skills with ability to translate technical findings to business stakeholders.

Preferred

Relevant certifications: OSCP, GWAPT, CEH, CSSLP, or equivalent.

Experience with penetration testing, exploit development, or application security architecture reviews.

Knowledge of regulatory and compliance frameworks (PCI DSS, GDPR, HIPAA, CIS, NIST, ISO).

Experience with external exposure monitoring and thirdparty risk tools (Shodan, SSLScan, Security Scorecard, BitSight).

Demonstrated success driving scaleready VM processes, SLAs, and executive reporting.

Conduct cloudnative and container vulnerability scanning and embed security controls and testing into CICD pipelines.

Strong manual testing skills for web application vulnerabilities and exploit validation.

Basic to intermediate programmingscripting skills (Python requiredpreferred also PowerShell, Bash familiarity with JavaScript, Java, or C# a plus).

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90911958
  • Position Id: 8919189
  • Posted 2 days ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

4d ago

Easy Apply

Contract, Third Party

Depends on Experience

Remote

4d ago

Easy Apply

Contract

Depends on Experience

Remote or Kent, Washington

Yesterday

Full-time

USD 115,600.00 - 167,900.00 per year

Remote or Kent, Washington

Yesterday

Full-time

USD 93,500.00 - 135,700.00 per year

Search all similar jobs