Principal Cyber Vulnerability Engineer Dallas or Detroit metro
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Principal Cyber Vulnerability Engineer
The Cyber Vulnerability Operations Team consists of the Application Security (App Sec) teams and the Vulnerability Management Operations (VM Ops) teams. Together, the Vulnerability Operations team collaborates with peers across Comerica to provide visibility into vulnerabilities within applications and infrastructure and ensures they are remediated, as well as facilitates and enforces the use of secure development practices across the bank.
The Principal Cyber Vulnerability Operations Engineer is responsible for vulnerability scanning, prioritizing vulnerabilities, and driving remediations while partnering with the application and infrastructure teams. The ideal candidate will have hands‑on expertise in vulnerability management and operations, knowledge of tools such as Qualys and PowerBI, experience with Windows/Linux/Unix server administration, and coding in one programming language. Experience with cross‑functional teams and automation is required.
A background in Qualys Policy management, PCI Compliance, and VMDR modules is also critical.
- Perform vulnerability assessments and baseline control scans across the Comerica environment; report on Key Risks Indicators (KRIs).
- Lead security vulnerability and risk management activities, identifying vulnerabilities and supporting application/system owners to manage risks and remediate vulnerabilities.
- Establish and mature processes around vulnerability management, remediation, and reporting.
- Lead key projects such as vulnerability prioritization to remediate critical vulnerabilities.
- Participate in vendor evaluations and selection for vulnerability management products, including external attack surface management solutions; implement and support those products on an ongoing basis.
- Stay current on vulnerability management best practices across the industry.
- Develop a comprehensive set of metrics to track enterprise risks and remediation trends; keep management informed through accurate, timely reporting.
- Support monthly KRI reporting by collecting data and working with application and infrastructure teams to remediate vulnerabilities.
- Create presentations based on KRI materials and keep management informed.
- Drive technical excellence and implementation of vulnerability management best practices in collaboration with technology teams across the enterprise.
- Provide consultation and close collaboration with other infrastructure departments and vendors to meet organizational and business goals.
- Automate existing manual processes to improve delivery speed.
- Coach and mentor junior team members and application teams on vulnerability remediation efforts.
- Identify and communicate gaps in vulnerability management practices.
- Participate in Red Team exercises to proactively identify potential vulnerabilities.
- Partner with application and infrastructure owners to provide consulting on remediation of large, complex vulnerabilities within SLAs, reducing risk for the bank.
- Develop cyber vulnerability analysis and related metrics and reporting deliverables.
- Bachelor’s Degree in Computer Science, Engineering, Information Systems, Cybersecurity, or Business Administration, or equivalent experience.
- 12 years of relevant experience or higher education and work experience equivalent.
- 6+ years of experience in Cyber or Information Security, preferably in Vulnerability Management and Security within the financial services industry.
- 5+ years of experience collaborating across Enterprise IT and Security to remediate vulnerabilities identified.
- 3+ years of experience with programming concepts and fundamentals (e.g., Python, .NET, Java, JavaScript, Power Shell) and ability to automate with those tools.
- 3+ years of experience in Qualys Policy management, PCI Compliance, and VMDR modules.
- 3+ years of experience or working knowledge in server administration.
- 2+ years of experience coaching/mentoring contractors.
- 2+ years of experience in vulnerability assessments, including creation, maintenance, and troubleshooting of scan configurations across the enterprise.
- 2+ years of experience with Vulnerability Management across cloud platforms and EVM management/prioritization.
- 2+ years of experience with endpoint protection technologies.
Location:
Auburn Hills Operations Center
Hours:
8:00am – 5:00pm Monday–Friday
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).