×
Register Here to Apply for Jobs or Post Jobs. X

Senior Vulnerability Management Engineer

Job in Irvine, Orange County, California, 92616, USA
Listing for: Tekfortune
Full Time position
Listed on 2026-07-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below

Senior Vulnerability Management Engineer

Onsite-Irvine / Remote

Experience:

8–12+ years in Cybersecurity, with strong hands on Vulnerability Management experience

Role Overview

We are seeking a Senior Vulnerability Management Engineer to lead and mature the organization's vulnerability management program. This role requires deep hands on expertise with Rapid7 InsightVM, risk based prioritization, remediation governance, and collaboration with infrastructure, cloud, and application teams. The ideal candidate will drive vulnerability reduction through automation, intelligent prioritization, and strong stakeholder engagement.

Key Responsibilities

Vulnerability Management & Risk Prioritization

  • Own and manage the end to end vulnerability management lifecycle using Rapid7 InsightVM.
  • Conduct authenticated vulnerability scanning across on prem, cloud (AWS/Azure), External, and DMZ assets.
  • Analyze vulnerabilities using CVSS v3, Rapid7 Real Risk Score, exploitability, and asset criticality.
  • Identify and escalate Critical vulnerabilities, including Zero Day and KEV listed exposures.
  • Define and enforce Vulnerability Prioritization & SLA models (Critical, High, Medium, Low).

Remediation & Stakeholder Collaboration

  • Partner with Infrastructure, Cloud, Dev Ops, and Application teams to drive timely remediation.
  • Create and manage remediation projects within Rapid
    7.
  • Validate fixes through rescans and evidence collection.
  • Support risk acceptance workflows, ensuring business justification and governance approvals.

Dashboards, Reporting & Metrics

  • Build executive level dashboards and reports showing:
    • Total vulnerabilities
    • Critical/High trends
    • MTTR and SLA compliance
    • Risk score reduction
  • Provide audit ready reporting for PCI DSS, SOX, HIPAA, ISO 27001, and NIST.
  • Track KPIs such as vulnerability aging, repeat findings, and remediation velocity.

Automation & Integration

  • Integrate Rapid7 with Service Now for automated ticket creation and SLA tracking.
  • Use Python, Power Shell, or APIs to automate vulnerability workflows and reporting.
  • Embed vulnerability scanning into CI/CD pipelines to support Dev Sec Ops  practices.

Cloud & Infrastructure Security

  • Assess vulnerabilities in AWS/Azure workloads including compute, networking, IAM, and storage.
  • Review cloud misconfigurations and coordinate remediation with cloud teams.
  • Ensure proper tagging and asset classification for accurate risk scoring.

Governance & Continuous Improvement

  • Maintain vulnerability management policies, standards, and procedures.
  • Lead continuous improvement initiatives to reduce false positives and scanning gaps.
  • Provide mentoring and technical guidance to junior analysts and engineers.
  • Support internal and external security audits.
Required

Skills & Qualifications

Technical Skills

  • Strong hands on experience with Rapid7 InsightVM / Nexpose
  • Deep understanding of CVSS v3, exploit intelligence, and risk based prioritization
  • Experience with Zero Day, KEV, and threat intelligence integration
  • Cloud security experience in AWS and/or Azure
  • Familiarity with SIEM tools (Splunk, QRadar) for correlation and validation
  • Automation and scripting skills (Python, Power Shell, APIs)
  • Ticketing and workflow integration with Service Now / JIRA

Frameworks & Compliance

  • NIST CSF / NIST 800 53 / ISO 27001
  • PCI DSS, SOX, HIPAA (as applicable)
  • Secure SDLC and Dev Sec Ops  principles

Soft Skills

  • Strong communication and stakeholder management
  • Ability to translate vulnerability risk into business impact
  • Leadership and mentoring capabilities
  • Detail oriented with strong analytical skills
Preferred Certifications
  • CISSP / CISM
  • CCSK / AWS or Azure Security certifications
  • Rapid7 InsightVM experience preferred
Success Measures
  • Reduction in Critical and High vulnerabilities
  • Improved MTTR and SLA compliance
  • Accurate risk prioritization with fewer false positives
  • Measurable reduction in organizational risk score
  • Positive audit and compliance outcomes
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary