Cyber Vulnerability Management Engineer CVE

Remote • Posted 59 minutes ago • Updated 59 minutes ago
Contract Independent
Contract W2
4 Months
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Cyber Security Infrastructure Engineer and Architect
  • Cyber Vulnerability Management Engineer CVE

Summary

***We are unable to sponsor for this 4+ month contract role, possible CTH, no 3rd party candidates will be considered***

Prestigious Enterprise Company is currently seeking a Cyber Vulnerability Management Engineer with strong CVEs experience. Candidate will provide hands-on support for the Secure Technology Solutions Sustainability service by augmenting the existing vulnerability management team in executing core vulnerability management operations. This is a senior-level technical role requiring strong vulnerability analysis, infrastructure knowledge, sound technical judgment, and the ability to work effectively with both engineering teams and technology leadership. This role will primarily support vulnerabilities affecting enterprise infrastructure, middleware, platforms, and DevOps technologies.

Responsibilities:

Vulnerability Investigation & Validation

  • Investigate and validate vulnerabilities identified through enterprise vulnerability scanning and aggregation platforms, including Rapid7 InsightVM/Nexpose, Qualys, and Nucleus.
  • Perform technical analysis beyond scanner output to determine whether vulnerabilities are valid, applicable, exploitable, or otherwise relevant within the context of the affected environment.
  • Research CVEs, vendor advisories, security bulletins, affected versions, patches, mitigations, exploitability, and other technical information necessary to accurately assess vulnerability risk.
  • Analyze affected infrastructure, middleware, operating systems, network technologies, platforms, and DevOps technologies to understand vulnerability applicability and appropriate remediation.
  • Identify potential false positives, configuration issues, version discrepancies, or other conditions requiring additional investigation.
  • Work directly with technical teams to gather evidence, validate findings, troubleshoot discrepancies, and determine appropriate remediation or mitigation approaches.

Vulnerability Management Operations

  • Execute established vulnerability management processes and runbooks consistently and independently.
  • Provide backup support for day-to-day and on-call vulnerability management activities, including investigation and coordination of newly identified or time-sensitive vulnerabilities.
  • Triage vulnerability findings and determine appropriate actions based on severity, exposure, exploitability, affected technology, and established enterprise requirements.
  • Create and distribute vulnerability advisories that clearly communicate affected technologies, risk, required actions, remediation guidance, and timelines.
  • Create, route, track, and follow up on remediation tickets with responsible technology teams.
  • Monitor outstanding vulnerability work and proactively engage stakeholders to drive remediation to completion.
  • Support both newly identified vulnerabilities and existing vulnerability backlog as needed.
  • Maintain accurate records and documentation throughout the vulnerability lifecycle.

Risk Acceptance

  • Facilitate established vulnerability risk acceptance processes for findings that cannot be remediated within required timelines.
  • Work with technical teams to understand remediation constraints, compensating controls, exposure, and residual risk.
  • Review existing risk acceptances approaching expiration and coordinate remediation, renewal, or escalation as appropriate.
  • Ensure risk acceptance documentation is technically accurate, clearly written, and completed in accordance with established processes and approval requirements.
  • Communicate effectively with engineers, managers, and technology leadership regarding vulnerability risk and remediation decisions.

Qualifications:

  • Significant hands-on experience in vulnerability management, vulnerability analysis, infrastructure security, or a closely related security engineering discipline.
  • Senior-level understanding of vulnerabilities, including CVEs, CVSS, vulnerability applicability, exploitability, remediation, mitigation, and false-positive validation.
  • Demonstrated ability to independently investigate and validate vulnerability findings rather than relying solely on vulnerability scanner results or severity ratings.
  • Strong technical understanding of enterprise infrastructure, including operating systems, networking, middleware, servers, common enterprise platforms, and related technologies.
  • Experience with enterprise vulnerability scanning and/or vulnerability management platforms such as Rapid7 InsightVM/Nexpose, Qualys VM, Nucleus, or comparable technologies.
  • Ability to research and interpret vendor security advisories, CVE information, scanner evidence, software versions, patches, configurations, and other technical data when assessing vulnerability findings.
  • Experience coordinating vulnerability remediation with infrastructure, platform, middleware, DevOps, or other technical engineering teams.
  • Ability to learn and consistently execute established operational processes and runbooks with minimal oversight.
  • Strong organizational skills and ability to independently manage multiple concurrent vulnerability investigations, remediation efforts, and stakeholder interactions.
  • Excellent written and verbal communication skills.
  • Strong interpersonal and relationship-management skills, with demonstrated ability to work effectively with both highly technical engineers and technology leadership.

Preferred Skills:

  • Direct experience with Rapid7 InsightVM/Nexpose, Nucleus, and/or Qualys Vulnerability Management.
  • Experience supporting enterprise-scale vulnerability management programs and large, heterogeneous technology environments.
  • Experience managing vulnerability advisories, remediation ticketing workflows, vulnerability exceptions, and/or formal risk acceptance processes.
  • Experience investigating vulnerabilities affecting middleware, infrastructure platforms, network technologies, operating systems, containers, or DevOps tooling.
  • Familiarity with vulnerability intelligence sources, exploitability analysis, CISA KEV, EPSS, vendor advisories, and other risk-prioritization inputs.
  • Experience working within defined vulnerability remediation SLAs and escalation processes.
  • Familiarity with workflow/ticketing platforms such as Jira or Ivanti.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: napil006
  • Position Id: CJ-VulCA
  • Posted 59 minutes ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Easy Apply

Contract

Depends on Experience

Remote

Today

Easy Apply

Full-time

$110 - $125

Remote or Minnesota

Today

Full-time

USD 143,200.00 - 196,900.00 per year

Remote or Philadelphia, Pennsylvania

Today

Full-time

Search all similar jobs