Sr. Endpoint Vulnerability Remediation Engineer
Listed on 2026-07-18
-
IT/Tech
Cybersecurity
Position Overview
Early Warning, a leader in payment and risk solutions, is seeking an Endpoint Vulnerability Manager to drive the identification, prioritization, and remediation of endpoint vulnerabilities across the enterprise. The role involves designing and implementing processes for securing endpoint systems, including patch management, configuration hardening, and vulnerability mitigation, and providing strategic guidance to technical teams and business units.
LocationPositions located in Scottsdale, San Francisco, Chicago, or New York. The role follows a hybrid work model.
Responsibilities- Drive endpoint vulnerability remediation efforts, including identification, prioritization, and resolution of Windows and Mac vulnerabilities.
- Design, implement, and maintain patch management and vulnerability remediation strategies, ensuring timely deployment and compliance with organizational SLAs.
- Partner with Security, Infrastructure, and Application teams to assess risk, validate remediation actions, and reduce overall attack surface.
- Create and maintain policies, standards, and technical documentation related to endpoint security, patching, and vulnerability management.
- Develop and maintain dashboards and reporting to track vulnerability posture, remediation progress, and risk reduction metrics.
- Represent Workplace Technology in Technology Review Boards, ensuring security best practices and consistent methodologies are applied.
- Work closely with internal teams and external vendors to resolve vulnerabilities in a timely manner, including driving escalations and ensuring SLA adherence.
- Act as an escalation point for critical vulnerabilities, security incidents, and remediation blockers.
- Participate in incident, problem, and change management processes as they relate to endpoint vulnerabilities and security risks.
- Support automation of vulnerability detection and remediation using scripting and Dev Ops practices.
- Assist with audit, compliance, and regulatory activities, including evidence gathering and remediation tracking.
- Bachelor’s degree in computer science, cybersecurity, engineering, or an equivalent field.
- Minimum of 5+ years of experience in endpoint management, vulnerability management, or infrastructure/security engineering.
- Demonstrated experience in a medium-to-large‑scale enterprise environment.
- Proven experience with endpoint vulnerability management tools (e.g., Rapid7), EDR platforms (e.g., Crowd Strike, Defender for Endpoint), and patch management solutions (e.g., SCCM/MECM, Intune, WSUS).
- Hands‑on experience with Windows and macOS endpoint administration and hardening.
- Knowledge of security configuration standards (e.g., CIS benchmarks) and network fundamentals (TCP/IP, DNS, firewalls).
- Strong scripting/automation skills (Power Shell, Python, Bash).
- Risk‑based vulnerability prioritization and remediation strategies.
- Excellent interpersonal and communication skills.
- Experience with vulnerability reporting and analytics tools such as Splunk, Power BI, or similar platforms.
- Experience integrating vulnerability management with ticketing/workflow systems (e.g., Service Now).
- Relevant certifications such as CISSP, CEH, Security+, or other endpoint/security certifications.
- Experience with automation/orchestration tools for remediation workflows.
The role is primarily sedentary and requires extensive use of a computer. Occasional standing, walking, kneeling, and reaching may be needed. Ability to lift up to 10 pounds occasionally.
CompensationSan Francisco, CA: $128,000 – $156,000 per year. Phoenix, AZ / Chicago, IL: $106,000 – $130,000 per year.
Equal Employment OpportunityEarly Warning Services LLC is an equal opportunity employer. All qualified applicants are considered for employment without regard to race, color, religion, sex, national origin, disability, or any other protected characteristic.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).