OPCyberTalent is seeking a Security Engineer - Vulnerability Management to lead and enhance our vulnerability detection, assessment, and remediation efforts. This role will be responsible for managing enterprise-wide vulnerability management programs, ensuring security best practices, and working cross-functionally with IT and security teams to mitigate risks. This role requires a proactive problem-solver who can adapt to evolving threats while delivering security solutions.
Key Responsibilities:
-
Design, implement, and manage a comprehensive vulnerability management program.
-
Perform vulnerability scanning, assessment, and prioritization.
-
Collaborate with IT, DevOps, and security teams to remediate identified vulnerabilities.
-
Conduct root cause analysis of security vulnerabilities and recommend mitigation strategies.
-
Develop automation scripts for scanning, reporting, and remediation workflows.
-
Ensure compliance with industry standards, regulations, and frameworks (e.g., NIST, CIS, ISO 27001, PCI-DSS).
-
Provide security recommendations to enhance network, endpoint, cloud, and application security.
-
Maintain up-to-date knowledge of emerging security threats, vulnerabilities, and industry trends.
-
Generate reports and communicate vulnerability risk levels to key stakeholders, including executive leadership.
-
Develop and maintain security documentation, policies, and best practices for vulnerability management.
Required Qualifications:
-
5+ years of experience in cybersecurity with a focus on vulnerability management.
-
Hands-on experience with vulnerability assessment tools.
-
Strong understanding of common vulnerabilities, CVSS scoring, and remediation techniques.
-
Proficiency in scripting languages (Python, PowerShell, Bash) for automation.
-
Experience working in hybrid cloud environments (AWS, Azure, GCP) and securing cloud infrastructure.
-
Knowledge of endpoint security, network security, and application security principles.
-
Familiarity with SIEM, IDS/IPS, and EDR solutions.
-
Experience with compliance frameworks (NIST, CIS, ISO 27001, PCI-DSS, HIPAA, SOC 2).
-
Excellent communication and collaboration skills with the ability to work across departments.
Preferred Qualifications:
-
Security certifications such as CISSP, OSCP, CEH, GSEC, or equivalent.
-
Experience with DevSecOps practices and CI/CD security integration.
-
Hands-on experience with container security tools
-
Prior experience in penetration testing or threat modeling.
#LI-JC2