Vulnerability Management Engineer

 Posted 8 days ago
     
⭐ 5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

You will build and manage a sustainable vulnerability management program by reconciling asset data and configuring remediation workflows in ServiceNow. Additionally, you will drive risk-based remediation efforts, report program metrics to leadership, and utilize AI tools to enhance analysis and reporting.

This is a remote position.

About This Opportunity

CTI Staffing is partnering with a well-established organization in the insurance industry to find a Vulnerability Management Engineer for their IT Security team. This is a fully remote contract engagement with right-to-hire potential.

This team is standing up a mature, sustainable vulnerability management program across a large and continuously evolving asset environment. You'll own the build: from reconciling the asset inventory to standing up the remediation workflow that the program runs on. If you like building programs rather than inheriting them, this is that role.

What You'll Do

  • Reconcile asset data across vulnerability scanners, endpoint security platforms, identity sources, and the CMDB to identify coverage gaps
  • Aggregate and de-duplicate vulnerability findings and baseline the current-state posture
  • Enrich findings with exploit intelligence (CVSS, EPSS, CISA KEV, validated-exploitable status) and produce a risk-ranked register
  • Build and configure the ServiceNow Vulnerability Response remediation workflow, including SLAs and an exception/risk-acceptance process
  • Drive initial remediation waves on highest-risk exposures in partnership with asset owners
  • Report program metrics and provide weekly status to security leadership
  • Author operational runbooks and operate the program in steady state
  • Apply AI tools to accelerate de-duplication, analysis, prioritization, and reporting


Requirements

What You Bring

Must-Have:

  • Hands-on experience operating enterprise vulnerability tooling, including Tenable and CrowdStrike (Falcon Spotlight / Exposure Management)
  • ServiceNow Vulnerability Response / SecOps workflow build experience (this is the engagement's core deliverable)
  • Risk-based prioritization using CVSS, EPSS, and CISA KEV
  • Remediation orchestration across infrastructure and application owners, including SLA design
  • Metrics and executive-ready reporting
  • Proficiency applying frontier AI models (e.g., ChatGPT Enterprise, Claude) to security engineering work
  • US Citizenship required (client cannot provide sponsorship)

Nice-to-Have:

  • NodeZero or other autonomous pentest familiarity
  • Patch and change-management integration
  • CMDB reconciliation experience
  • Insurance, financial services, or regulated-industry background
  • CISSP, GIAC, or Tenable/CrowdStrike vendor certifications

Technical Environment:

  • Tenable, CrowdStrike (Falcon Spotlight / Exposure Management, NG-SIEM), NodeZero
  • ServiceNow (Vulnerability Response, SecOps, CMDB)
  • Okta, Active Directory, Intune/MDM
  • ChatGPT Enterprise and Claude

What Success Looks Like:

  • An authoritative, reconciled asset inventory with known coverage gaps closed
  • A live ServiceNow Vulnerability Response workflow with SLAs, driving measurable remediation on the highest-risk exposures
  • Runbooks and a steady-state program the internal team can operate


Similar Jobs

See all Remote Software Development jobs β†’

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified