Contract Vulnerability Management
BILL RATE: $110.00 - $125.00/hour
LOCATION: remote
possible contract to hire, 3-4 month if hired, CANNOT be in these states: Washington DC, AK, ND, NE, HI, OK, VT, ME, WY, NH, Puerto Rico
SELLING POINTS: vulnerability management, vulnerability analysis - CVEs CVSS. management operating systems linux windows cloud azure networking middleware servers rapid7 insight vm nexpose qualys vm
This is a senior-level technical role requiring strong vulnerability analysis, infrastructure knowledge, sound technical judgment, and the ability to work effectively with both engineering teams and technology leadership.
The role will primarily support vulnerabilities affecting enterprise infrastructure, middleware, platforms, and DevOps technologies.
Key Responsibilities
Vulnerability Investigation & Validation
- Investigate and validate vulnerabilities identified through enterprise vulnerability scanning and aggregation platforms, including Rapid7 InsightVM/Nexpose, Qualys, and Nucleus.
- Perform technical analysis beyond scanner output to determine whether vulnerabilities are valid, applicable, exploitable, or otherwise relevant within the context of the affected environment.
- Research CVEs, vendor advisories, security bulletins, affected versions, patches, mitigations, exploitability, and other technical information necessary to accurately assess vulnerability risk.
- Analyze affected infrastructure, middleware, operating systems, network technologies, platforms, and DevOps technologies to understand vulnerability applicability and appropriate remediation.
- Identify potential false positives, configuration issues, version discrepancies, or other conditions requiring additional investigation.
- Work directly with technical teams to gather evidence, validate findings, troubleshoot discrepancies, and determine appropriate remediation or mitigation approaches.
Vulnerability Management Operations
Qualifications
- Significant hands-on experience in vulnerability management, vulnerability analysis, infrastructure security, or a closely related security engineering discipline.
- Senior-level understanding of vulnerabilities, including CVEs, CVSS, vulnerability applicability, exploitability, remediation, mitigation, and false-positive validation.
- Strong technical understanding of enterprise infrastructure, including operating systems, networking, middleware, servers
- Experience with enterprise vulnerability scanning and/or vulnerability management platforms such as Rapid7 InsightVM/Nexpose, Qualys
- Ability to research and interpret vendor security advisories, CVE information, scanner evidence, software versions, patches, configurations, and other technical data when assessing vulnerability findings.
- Experience coordinating vulnerability remediation with infrastructure, platform, middleware, DevOps, or other technical engineering teams.
- Ability to learn and consistently execute established operational processes and runbooks with minimal oversight.
Preferred
- Direct experience with Rapid7 InsightVM/Nexpose, Nucleus, and/or Qualys Vulnerability Management.
- Experience supporting enterprise-scale vulnerability management programs and large, heterogeneous technology environments.
- Experience managing vulnerability advisories, remediation ticketing workflows, vulnerability exceptions, and/or formal risk acceptance processes.
- Experience investigating vulnerabilities affecting middleware, infrastructure platforms, network technologies, operating systems, containers, or DevOps
- Familiarity with vulnerability intelligence sources, exploitability analysis, CISA KEV, EPSS, vendor advisories, and other risk-prioritization inputs.
- Experience working within defined vulnerability remediation SLAs and escalation processes.
- Familiarity with workflow/ticketing platforms such as Jira or Ivanti.