We are seeking an experienced
Vulnerability Management Engineer to design, build, and operationalize a mature vulnerability management program across a large, rapidly evolving enterprise environment. This is a hands-on engineering role responsible for developing sustainable processes, workflows, and operational procedures while driving enterprise-wide vulnerability remediation.
This engagement focuses on building a comprehensive vulnerability management program with ServiceNow Vulnerability Response workflow development serving as the primary deliverable. The ideal candidate has extensive experience with enterprise vulnerability management, ServiceNow Security Operations, and risk-based remediation across complex infrastructure environments.
What You'll Do
Vulnerability Management Program Development
- Build and operationalize a mature vulnerability management program across a large and continuously changing enterprise asset environment.
- Reconcile and maintain an authoritative asset inventory across multiple security and identity platforms.
- Identify asset visibility and scanner coverage gaps to improve overall security posture.
Asset Inventory & Vulnerability Assessment
- Reconcile asset data across:
- Tenable
- CrowdStrike
- Okta
- Active Directory
- Microsoft Intune
- ServiceNow CMDB
- Identify scanner, agent, and asset coverage gaps.
- Aggregate and de-duplicate vulnerability findings from multiple sources.
- Establish a baseline of the organization's current vulnerability posture.
Risk-Based Prioritization
- Enrich vulnerability data using:
- CVSS
- EPSS
- CISA Known Exploited Vulnerabilities (KEV)
- NodeZero validated-exploitable findings
- Produce and maintain a risk-ranked vulnerability register.
- Prioritize remediation efforts based on business risk and exploitability.
ServiceNow Vulnerability Response Engineering
- Design, build, and configure the ServiceNow Vulnerability Response workflow, including:
- Intake
- Prioritization
- Assignment
- Tracking
- Verification
- Re-scanning
- Closure
- Develop risk-based Service Level Agreements (SLAs).
- Establish exception handling and risk acceptance processes.
- Integrate workflows within ServiceNow SecOps.
Remediation & Program Operations
- Drive initial remediation efforts for the organization's highest-risk vulnerabilities in partnership with infrastructure and application owners.
- Coordinate remediation activities across multiple technical teams.
- Track remediation progress and report on key program metrics.
- Develop executive-ready reporting and dashboards.
Documentation & Operational Support
- Author operational runbooks and standard operating procedures.
- Transition the vulnerability management program into steady-state operations.
- Provide weekly project status updates and implementation progress.
AI-Driven Security Engineering
- Utilize frontier AI models such as ChatGPT Enterprise and Claude to accelerate:
- Vulnerability analysis
- Finding de-duplication
- Risk prioritization
- Reporting
- Workflow design
- Operational documentation
- Apply AI responsibly while following enterprise governance and security best practices.
Required Qualifications
Must-Have Skills
- Hands-on experience operating enterprise vulnerability management platforms, including:
- Tenable
- CrowdStrike Falcon Spotlight / Exposure Management
- Strong understanding of:
- Vulnerability lifecycle management
- Asset inventory reconciliation
- Risk-based remediation
- Enterprise security operations
- Experience prioritizing vulnerabilities using:
- CVSS
- EPSS
- CISA Known Exploited Vulnerabilities (KEV)
- Validated exploitability methodologies
- Hands-on experience building ServiceNow Vulnerability Response / SecOps workflows (required and non-negotiable).
- Experience coordinating remediation across infrastructure and application teams.
- Experience designing remediation SLAs and executive reporting.
- Proficiency using frontier AI models, including ChatGPT Enterprise and Claude, within security engineering workflows.
- Ability to work independently and drive initiatives from discovery through operational maturity.
Preferred Qualifications
Experience with the following technologies is highly desired:
- NodeZero
- CrowdStrike NG-SIEM
- ServiceNow CMDB
- Patch management platforms
- Change management processes
- CMDB reconciliation
Industry experience in:
- Insurance
- Financial Services
- Other regulated industries
Preferred certifications include:
- CISSP
- GIAC Security Certifications
- Tenable Certifications
- CrowdStrike Certifications
Equivalent hands-on experience will be considered in place of certifications.
Technology Environment
You will be supporting and working with:
- Tenable
- CrowdStrike Falcon Spotlight / Exposure Management
- CrowdStrike NG-SIEM
- NodeZero
- Okta
- Active Directory
- Microsoft Intune / MDM
- ServiceNow Vulnerability Response
- ServiceNow SecOps
- ServiceNow CMDB
- ChatGPT Enterprise
- Claude
Work Environment
- Fully remote position.
- Collaborative IT Security Engineering team operating within a SAFe Agile framework.
- ServiceNow is utilized for ITSM and Security Operations.
- Zoom is used for collaboration and team communication.
- AI-forward culture where frontier AI models are actively incorporated into engineering workflows.
- Fast-paced, acquisition-driven environment requiring flexibility, adaptability, and strong execution.
Initial Project Focus
Upon joining, you will lead the implementation of the organization's enterprise Vulnerability Management initiative, including:
- Building a comprehensive asset inventory and identifying coverage gaps.
- Conducting a current-state vulnerability assessment.
- Developing and implementing the ServiceNow Vulnerability Response workflow.
- Establishing remediation SLAs and driving initial remediation efforts.
- Creating operational runbooks and transitioning the program into steady-state operations.
What We're Looking For
We're looking for a self-directed Vulnerability Management Engineer who thrives on building security programs from the ground up. You'll be comfortable leading enterprise vulnerability initiatives, coordinating remediation across multiple teams, and developing scalable operational processes. Success in this role requires strong technical expertise, exceptional communication skills, and the ability to operate effectively in a fast-paced, acquisition-driven environment while leveraging AI to improve security operations.
U.S. Citizenship required