×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Engineer III, Vulnerability Management

Job in Philadelphia, Philadelphia County, Pennsylvania, 19102, USA
Listing for: Cencora
Full Time position
Listed on 2026-08-21
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below

Engineer III
- Vulnerability Management

The Engineer III
- Vulnerability Management is a senior technical contributor responsible for identifying, analyzing, prioritizing, reporting, and driving remediation of vulnerabilities and posture findings across enterprise environments. This role supports and helps mature a unified, risk-based Vulnerability and Posture Management capability spanning infrastructure, endpoints, cloud workloads, network devices, applications, SaaS platforms, external attack surface, and other critical assets. The Engineer III will help lead Continuous Threat Exposure Management (CTEM) activities, operate and optimize attack surface management and vulnerability management tools, and partner with technology, security, and business stakeholders to measurably reduce cyber risk.

Primary Responsibilities

  • Perform advanced vulnerability analysis across infrastructure, cloud, endpoint, network, application, SaaS, and externally facing assets.
  • Lead and support Continuous Threat Exposure Management (CTEM) processes, including scoping, discovery, prioritization, validation, mobilization, and ongoing risk reduction activities.
  • Operate and improve vulnerability management, attack surface management, external posture management, cloud posture and SaaS posture capabilities.
  • Analyze vulnerability and posture data from multiple sources, normalize findings, and develop actionable risk-based remediation priorities.
  • Assess vulnerabilities using business context, asset criticality, exploitability, threat intelligence, exposure, compensating controls, and regulatory or compliance impact.
  • Drive remediation and risk treatment efforts with infrastructure, cloud, network, application, endpoint, Dev Ops, and business technology teams.
  • Lead emerging vulnerability and critical exposure response activities, including impact analysis, stakeholder coordination, mitigation tracking, and executive-level status reporting.
  • Create and maintain dashboards, metrics, and reporting for vulnerability trends, remediation progress, SLA performance, exposure reduction, attack surface changes, and program maturity.
  • Support implementation and optimization of unified vulnerability management workflows, including ticketing, ownership assignment, exception handling, rescan validation, remediation automation, and governance routines.
  • Evaluate and recommend improvements to scanning coverage, asset inventory quality, vulnerability data integrity, risk scoring, and stakeholder reporting.
  • Translate complex technical findings into clear remediation guidance for technical teams and concise risk summaries for leadership.
  • Contribute to security standards, procedures, playbooks, process documentation, and continuous improvement initiatives for the Vulnerability and Posture Management program.
  • Mentor junior engineers and analysts by providing technical guidance, quality review, and support for vulnerability triage and remediation governance.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Engineering, or a related field, or equivalent practical experience.
  • 7-10 years of combined experience in information technology, cybersecurity, systems administration, cloud operations, network security, application security, security engineering, or related disciplines.
  • At least 4 years of hands-on experience in vulnerability management, exposure management, attack surface management, configuration assurance, or a closely related cybersecurity function.
  • At least one active cybersecurity certification, such as CISSP, CISM, Security+, CySA+, GSEC, CCSK, CCSP, OSCP, GIAC certification, or another recognized security certification.
  • Strong understanding of vulnerability lifecycle management, including discovery, validation, prioritization, remediation, exception handling, rescan validation, and reporting.
  • Experience using vulnerability assessment or vulnerability management platforms such as Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Wiz, Armis, or comparable tools.
  • Experience with attack surface, posture, or exposure management capabilities such as CAASM,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary