Sr. Security Engineer, Vulnerability Management
Listed on 2026-08-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Systems Engineer, IT Consultant
Company :
enGen
Job Description :JOB SUMMARY
CANDIDATE MUST BE US Citizen (due to contractual/access requirements)
Highmark Health is seeking a highly experienced and technically adept Cybersecurity Engineer with a deep specialization in Vulnerability Management and Secure Configuration Management . This pivotal role is responsible for the strategic development, implementation, and continuous enhancement of enterprise-wide security controls and practices that proactively defend against evolving threats and meet critical business and regulatory obligations .
As a lead Security Engineer , you will leverage your 10+ years of expertise to design, develop, and implement robust ISRM Infrastructure solutions , ensuring optimal performance, resilience, and security across diverse environments, including cloud security and infrastructure security . You will champion security baselines and configuration management practices for on-premises, endpoint, network, application, and containerized systems.
A key aspect of this role involves researching, analyzing and recommending cutting-edge security technologies ,
threat detection capabilities , and attack surface management solutions . You will be instrumental in driving the adoption of automation, orchestration, and advanced analytics to improve vulnerability management effectiveness , enhance threat visibility , and streamline remediation efforts .
Strong scripting skills and experience with system integrations are essential to succeed in this role.
This position requires a U.S. Citizen due to contractual and access requirements. If you are a proactive and innovative cybersecurity
professional passionate about building and securing critical infrastructure,
- Lead teams in clearly defining requirements, deliverables and time frames. Escalate issues and make recommendations to resolve them to the appropriate audience.
- Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.
- Develop and/or deliver technical training in complex technical areas. Mentor less senior staff in the execution of their duties.
- Complete project tasks to enable the on time, within budget and scope delivery of ISRM Infrastructure projects.
- Implement, monitor, configure, and maintain security systems.
- Assure compliance to required standards, procedures, guidelines and processes.
- Other duties as assigned or requested.
- Bachelor's Degree in Computer Science, Information Systems, or closely related field
- None
- Master's Degree in Computer Science, Information Security or related field
Required
- 7 years with Information Security and Systems Analysis
- 7 years with Information Security and/or Information Risk Management and/or Information Technology
- 7 years with Operating Systems and Software Administration
- 7 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
- 7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
- 10 years of experience in Information Security
- 5+ years of experience in Vulnerability and Secure Configuration Management engineering, including design, architecture, complex deployments and configuration, API integrations, high availability concepts, vendor communication.
- 3+ years of experience in adjacent Security domains, such as Threat Intel, Application Security, Offensive Security (Penetration Testing, Red/Purple Teaming).
- Outstanding technical acumen across a broad range of cloud and on-premise technologies, architectures, applications and APIs
- Outstanding verbal, written, presentation, facilitation, and interaction skills, including ability to effectively communicate technical issues and engineering concepts to technical and non-technical people
- Demonstrated ability to initiate and guide enterprise technical products and services business cases to successful outcomes at scale
- Demonstrated ability to navigate technical details for enterprise security services, and guide through solution development
- Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3
- Familiarity with secure SDLC best practices
- Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.
- Strong teamwork and inter-personal skills
Required
- None
- Certified Information Security Professional (CISSP)
- Security LANGUAGE REQUIREMENT (other than English)?
None
TRAVEL REQUIREMENT:0% - 25%
PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONSPosition Type:
Office-Based
Office-Based Positions
Teaches/Trains others regularly
Occasionally
Travels regularly from the office to various work sites or from site-to-site
Occasionally
Works primarily out-of-the office selling…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).