Logo for SoluStaff

Tenable Vulnerability Management Engineer

Role overview

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field, preferred but not required with acceptable experience
  • 3-5 years of recent, hands-on experience administering and engineering Tenable solutions in a large enterprise environment
  • Demonstrated recent experience with the Tenable platform
  • Advanced scripting and automation skills, particularly PowerShell

Responsibilities

  • Conduct vulnerability assessments using Tenable to identify potential security vulnerabilities within systems, networks, and applications
  • Collaborate with cross-functional teams to analyze and prioritize vulnerabilities based on risk levels and potential impact
  • Develop and implement vulnerability management processes, procedures, and best practices
  • Monitor and track the remediation of identified vulnerabilities, ensuring they are addressed within defined timelines

Key facts

  • Remote from: Pennsylvania (USA)
  • Fixed term
  • Mid-level (2-5 years)
  • Vulnerability Management Analyst
  • English

Hard skills

Other skills

  • Communication
  • Problem Solving
  • Analytical Thinking
  • Troubleshooting (Problem Solving)

About the company

SoluStaff logo

SoluStaff

Staffing & Recruiting

SoluStaff is a full-service IT consulting and staffing solutions provider that delivers experienced consulting services and proven staff augmentation resources to public and private sector organizations. Founded by an executive management team with a wealth of experience in the IT, government and healthcare sectors, our culture is forged in collaboration and continual communication, amongst our employees and with our customers. The cornerstone of our company is focused on our belief that success can be achieved by providing qualified and experienced IT personnel at a fair price. We hold IT Consulting Service contracts with healthcare, government and commercial sector organizations across the country. SoluStaff focuses on the delivery of IT services in these industry verticals: • Healthcare • IT Services • Financial Services • Legal • Department of Defense • Manufacturing • State and Local Governments • Insurance Whether you’re looking for professional service offerings, or are interested in joining a passionate and impactful team, we encourage you to reach out to our consulting and staffing specialists to see how SoluStaff can help you achieve your goals.

Company details

Company typeSME
IndustryStaffing & Recruiting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Symmetrio is recruiting a Remote Tenable Vulnerability Management Engineer Consultant for our customer, a large government organization in Philadelphia, PA. This role is intended for an experienced, hands-on Tenable practitioner who can elevate and mature a large enterprise vulnerability management program.

The successful candidate will bring recent, deep experience across the Tenable platform and will be expected to optimize how Tenable is configured, operated, automated, and used to drive risk-based vulnerability identification, prioritization, remediation, and executive reporting. This individual should be excited to expand the program beyond traditional infrastructure scanning by leveraging Tenable Vulnerability Management, Tenable Web App Scanning, APIs, automation, and other applicable Tenable capabilities. The candidate will also help advance the use of AI-enabled tools and techniques to analyze vulnerability data, identify patterns and exposures, improve prioritization, accelerate investigation, and support remediation decisions across a complex enterprise environment.

Strong PowerShell and/or Python scripting skills are essential to automate repetitive activities, integrate data sources, enrich findings, and improve the efficiency and scale of the vulnerability management lifecycle. The ideal candidate is not simply a scanner operator; they are a vulnerability management engineer and program builder who can identify opportunities to improve coverage, data quality, risk prioritization, automation, metrics, and overall program maturity.

This is a remote position, with occasional visits to the Philadelphia office as needed for team meetings, strategic planning, and stakeholder discussions. The position offers a salary range of $115,000–$130,000, along with competitive health benefits, PTO, and a 401(k) plan.

Responsibilities

  • Conduct vulnerability assessments using Tenable to identify potential security vulnerabilities within our systems, networks, and applications.
  • Collaborate with cross-functional teams to analyze and prioritize vulnerabilities based on risk levels and potential impact.
  • Develop and implement vulnerability management processes, procedures, and best practices to ensure timely identification, remediation, and reporting of vulnerabilities.
  • Monitor and track the remediation of identified vulnerabilities, ensuring that they are addressed within defined timelines.
  • Stay updated with the latest security vulnerabilities, threats, and industry best practices to continuously improve the vulnerability management program.
  • Perform regular vulnerability scanning and penetration testing to proactively identify and address potential security weaknesses.
  • Work closely with IT teams to provide guidance and support in remediating vulnerabilities, including suggesting configuration changes, patches, and other remediation actions.
  • Provide technical expertise and guidance to internal stakeholders on vulnerability management issues and best practices.
  • Collaborate with the Incident Response team to investigate and respond to security incidents related to vulnerabilities.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field, preferred but not required with acceptable experience. 3-5 years of recent, hands-on experience administering and engineering Tenable solutions in a large enterprise environment is acceptable in replacement of education. Relevant certifications (e.g., CISSP, CEH, GIAC), including Tenable or other vendor certifications, are highly desirable.
  • Demonstrated recent experience with the Tenable platform, with strong hands-on expertise in Tenable Vulnerability Management (Tenable.io) and Nessus, including scanner deployment and management, scan configuration, asset discovery, tagging, credentialed scanning, plugin management, troubleshooting, dashboards, reporting, and platform optimization.
  • Experience using Tenable Web App Scanning to identify and assess vulnerabilities in web applications and APIs; experience with additional Tenable services and capabilities is strongly preferred.
  • Proven experience designing, operating, and maturing an enterprise vulnerability management program, including vulnerability discovery, validation, risk-based prioritization, remediation tracking, exception management, metrics, reporting, and continuous improvement.
  • Advanced scripting and automation skills, particularly PowerShell; Python or similar scripting experience is highly desirable. Must be able to create and maintain scripts that automate Tenable administration, data collection, enrichment, reporting, integrations, remediation workflows, and other vulnerability management activities.
  • Experience working with Tenable APIs and integrating Tenable vulnerability and asset data with enterprise technologies such as ticketing systems, SIEM/SOAR platforms, CMDBs, asset inventories, dashboards, or other security tools.
  • Demonstrated ability and interest in leveraging AI tools to assist with vulnerability analysis, data correlation, pattern identification, prioritization, remediation research, scripting, reporting, and other vulnerability management use cases while applying appropriate validation and security controls to AI-generated outputs.
  • Strong understanding of vulnerability intelligence and risk-based prioritization, including CVE, CVSS, CISA Known Exploited Vulnerabilities (KEV), exploitability, threat intelligence, asset criticality, exposure, compensating controls, and business impact.
  • Solid understanding of common vulnerabilities, attack vectors, mitigation techniques, network and application security concepts, and the ability to distinguish actionable risk from scanner noise or false positives.
  • Experience with network scanning, authenticated/credentialed scanning, web application scanning, vulnerability validation, and penetration testing or vulnerability exploitation techniques.
  • Knowledge of industry standards and frameworks such as CVSS, CVE, OWASP, NIST, and vulnerability management best practices.
  • Strong analytical, troubleshooting, communication, and problem-solving skills, with the ability to translate technical vulnerability data into clear remediation guidance and risk information for infrastructure teams, application owners, leadership, and other stakeholders.
  • Demonstrated ability to independently identify gaps in vulnerability coverage, tooling, processes, automation, reporting, and governance and recommend and implement improvements that measurably increase vulnerability management program maturity.

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k)
  • Paid Time Off (Vacation, Sick & Public Holidays)

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Vulnerability Management Analyst Related jobs

Other jobs at SoluStaff

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.