Engineer - Vulnerability Management
Listed on 2026-08-22
-
IT/Tech
Cybersecurity
Overview
Live the experience. From professional empowerment to continual learning opportunities. From ongoing investment in new and emerging technologies to a career of self-determination. At Ulta Beauty, our tech team is critical to our scalability-and is recognized that way. We’ve been defined as a 'mature start-up.' A place where interdepartmental exposure, open doors, and genuine collaboration is ubiquitous. Where challenges come fast and furious, requiring agility, mental dexterity, and creativity.
Where our passion for better solutions drives us and is core to who we are. We’re engineering for the future of retail, and it’s no-holds-barred. But for those motivated by continual change and ambiguity, by superior leadership, by whip smart colleagues who will press you daily for your very best, you’ll find that virtually nothing’s impossible at Ulta Beauty.
The Engineer - Vulnerability Management is responsible for working with the VM Manager to design, implement, and maintain a robust vulnerability management program across hybrid environments, including on-premises, cloud, containers, and SaaS platforms. This role focuses on technical execution - deploying and tuning scanning tools (Tenable Security Center/Falcon Exposure Management), then using continuous, data driven communication to remediation teams via Service Now VR so that they are empowered to address the riskiest vulnerabilities within their environments.
The engineer will leverage risk-based prioritization, threat intelligence, and business context to reduce exposure and improve resilience. This position requires deep technical expertise in vulnerability scanning technologies, scripting and automation, and security practices across the traditional and cloud-native spectrum. The engineer will collaborate closely with infrastructure, cloud, application, and security teams to drive remediation according to organizational SLAs, and continuously improve program maturity through metrics, automation, and emerging technologies.
Accomplish These Goals By
- Vulnerability Identification & Scanning
- Design, schedule, and optimize authenticated/credentialed scans for on-prem, cloud, and remote endpoints; ensure minimal disruption and scan hygiene
- Validate scanner configuration and coverage (e.g., Qualys/Tenable/Rapid7/Falcon Exposure Management) and continuously tune for false-positive reduction
- Risk-Based Prioritization
- Prioritize findings using context: exploit likelihood (EPSS), Known Exploited Vulnerabilities (CISA KEV), network exposure, business impact, compensating controls, and asset criticality
- Correlate with threat intel and active detections (EDR/XDR/SIEM), elevating actively exploited vulnerabilities to emergency treatment
- Define severity thresholds and SLAs per asset class; manage exceptions with time-bound risk acceptance and compensating controls.
- Remediation & Ticketing
- Drive remediation by regularly partnering with Infra/Platform, Cloud, and App teams to empower them to make informed decisions when weighing the priority of patches and configuration changes versus compensating controls and operational realities
- Integrate with ticketing systems (Service Now VR) to ensure that proper assignment logic is in place, and that automated validation scans determine the status of fix actions.
- Assist the Security Operations team as they execute zero-day/rapid-response playbooks (e.g. scans/queries, exploitability assessments, validations, enrich post-mortems)
- Asset & Exposure Discovery
- Contribute to and help maintain an accurate, continuously updated asset inventory across a primary scope of endpoints, servers, and network devices, as well as containers, mobile, OT/IoT, and cloud resources (IaaS, PaaS, SaaS)
- Integrate data from CMDB, cloud provider APIs, EDR/XDR, MDM, and attack surface management to reduce blind spots
- Assist CMDB owner with categorization of assets for business criticality, data sensitivity, internet-exposure, and ownership to enable risk-based prioritization
- Validation & Continuous Improvement
- Perform targeted rescans and exploit-simulation where safe to confirm remediation
- Tune detection rules to reduce…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).