2

Remote Qualys Vulnerability Management Jobs (NOW HIRING)

Experience using vulnerability assessment or vulnerability management platforms such as Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Wiz, Armis, or comparable tools.

$70K - $170K/yr

Location This is a remote role based in the US. About The Job You're Considering We are looking for ... Experience with vulnerability scanning tools such as Qualys, Tenable, Rapid7, Wiz, or similar ...

Experience using vulnerability assessment or vulnerability management platforms such as Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Wiz, Armis, or comparable tools.

Showing results 21-40

Remote Qualys Vulnerability Management information

See salary details

$23K

$139.6K

$174.5K

How much do remote qualys vulnerability management jobs pay per year?

As of Sep 14, 2026, the average yearly pay for remote qualys vulnerability management in the United States is $139,599.00, according to ZipRecruiter salary data. Most workers in this role earn between $116,000.00 and $160,000.00 per year, depending on experience, location, and employer.

What is a remote Qualys Vulnerability Management?

A Remote Qualys Vulnerability Management job involves using the Qualys platform to identify, assess, and prioritize security vulnerabilities in an organization's IT infrastructure, all while working remotely. Professionals in this role deploy and manage vulnerability scans, analyze scan results, and provide recommendations for remediation to minimize risk. They often collaborate with IT and security teams to ensure vulnerabilities are addressed promptly, helping to maintain the security posture of the organization. The remote aspect means all tasks are performed online, allowing for flexibility in work location.

What are the key skills and qualifications needed to thrive as a remote Qualys Vulnerability Management professional?

To excel in Remote Qualys Vulnerability Management, you need a strong background in cybersecurity principles, vulnerability assessment, and typically a degree in computer science or related field. Proficiency with Qualys Vulnerability Management tools, understanding of network security protocols, and often relevant certifications like CompTIA Security+ or CISSP are essential. Analytical thinking, attention to detail, and effective communication are standout soft skills for interpreting scan results and collaborating with distributed teams. These skills ensure accurate identification and remediation of security risks, safeguarding organizational assets in remote environments.

What are some common challenges remote Qualys Vulnerability Management professionals face, and how can these be addressed?

One common challenge for remote Qualys Vulnerability Management professionals is ensuring effective communication and collaboration with IT and security teams across different time zones and departments. Addressing this requires establishing clear processes for reporting vulnerabilities, prioritizing remediation, and using collaboration tools to stay aligned. Additionally, managing multiple clients or environments remotely can introduce complexity, so strong organizational skills and proactive scheduling of scans and follow-ups are essential. Regular virtual meetings and detailed documentation also help maintain transparency and accountability within the team.

What is the difference between Remote Qualys Vulnerability Management vs Remote Vulnerability Analyst?

AspectRemote Qualys Vulnerability ManagementRemote Vulnerability Analyst
CertificationsQualys Certified, Security+CompTIA Security+, CISSP (preferred)
Work EnvironmentSecurity teams, IT departments, using vulnerability management toolsSecurity teams, IT departments, analyzing vulnerabilities and reports
Industry UsageCybersecurity, IT, Managed Security Service ProvidersCybersecurity, IT, consulting firms
Primary FocusManaging and scanning vulnerabilities with Qualys platformAnalyzing vulnerabilities, assessing risks, and reporting

Remote Qualys Vulnerability Management roles focus on using Qualys tools to identify and manage security vulnerabilities, while Remote Vulnerability Analysts analyze vulnerability data, assess risks, and prepare reports. Both roles require cybersecurity knowledge but differ in technical focus and responsibilities.

More about Remote Qualys Vulnerability Management jobs

What cities are hiring for Remote Qualys Vulnerability Management jobs?

Cities with the most Remote Qualys Vulnerability Management job openings:

What are the most commonly searched types of Qualys Vulnerability Management jobs?

The most popular types of Qualys Vulnerability Management jobs are:

What states have the most Remote Qualys Vulnerability Management jobs?

States with the most job openings for Remote Qualys Vulnerability Management jobs include:

What job categories do people searching Remote Qualys Vulnerability Management jobs look for?

The top searched job categories for Remote Qualys Vulnerability Management jobs are:

Infographic showing various Remote Qualys Vulnerability Management job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, and 2% Contract. Highlights an 82% Physical, 2% Hybrid, and 16% Remote job distribution, with an average salary of $139,599 per year, or $67.1 per hour.

Engineer III, Vulnerability Management

Remote

Full-time

Medical, Dental, Vision

Posted 26 days ago


Job description

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!

Job Details

Job Summary

The Engineer III - Vulnerability Management is a senior technical contributor responsible for identifying, analyzing, prioritizing, reporting, and driving remediation of vulnerabilities and posture findings across enterprise environments. This role supports and helps mature a unified, risk-based Vulnerability and Posture Management capability spanning infrastructure, endpoints, cloud workloads, network devices, applications, SaaS platforms, external attack surface, and other critical assets. The Engineer III will help lead Continuous Threat Exposure Management (CTEM) activities, operate and optimize attack surface management and vulnerability management tools, and partner with technology, security, and business stakeholders to measurably reduce cyber risk.

Primary Responsibilities

  • Perform advanced vulnerability analysis across infrastructure, cloud, endpoint, network, application, SaaS, and externally facing assets.
  • Lead and support Continuous Threat Exposure Management (CTEM) processes, including scoping, discovery, prioritization, validation, mobilization, and ongoing risk reduction activities.
  • Operate and improve vulnerability management, attack surface management, external posture management, cloud posture and SaaS posture capabilities.
  • Analyze vulnerability and posture data from multiple sources, normalize findings, and develop actionable risk-based remediation priorities.
  • Assess vulnerabilities using business context, asset criticality, exploitability, threat intelligence, exposure, compensating controls, and regulatory or compliance impact.
  • Drive remediation and risk treatment efforts with infrastructure, cloud, network, application, endpoint, DevOps, and business technology teams.
  • Lead emerging vulnerability and critical exposure response activities, including impact analysis, stakeholder coordination, mitigation tracking, and executive-level status reporting.
  • Create and maintain dashboards, metrics, and reporting for vulnerability trends, remediation progress, SLA performance, exposure reduction, attack surface changes, and program maturity.
  • Support implementation and optimization of unified vulnerability management workflows, including ticketing, ownership assignment, exception handling, rescan validation, remediation automation, and governance routines.
  • Evaluate and recommend improvements to scanning coverage, asset inventory quality, vulnerability data integrity, risk scoring, and stakeholder reporting.
  • Translate complex technical findings into clear remediation guidance for technical teams and concise risk summaries for leadership.
  • Contribute to security standards, procedures, playbooks, process documentation, and continuous improvement initiatives for the Vulnerability and Posture Management program.
  • Mentor junior engineers and analysts by providing technical guidance, quality review, and support for vulnerability triage and remediation governance.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Engineering, or a related field, or equivalent practical experience.
  • 7-10 years of combined experience in information technology, cybersecurity, systems administration, cloud operations, network security, application security, security engineering, or related disciplines.
  • At least 4 years of hands-on experience in vulnerability management, exposure management, attack surface management, configuration assurance, or a closely related cybersecurity function.
  • At least one active cybersecurity certification, such as CISSP, CISM, Security+, CySA+, GSEC, CCSK, CCSP, OSCP, GIAC certification, or another recognized security certification.
  • Strong understanding of vulnerability lifecycle management, including discovery, validation, prioritization, remediation, exception handling, rescan validation, and reporting.
  • Experience using vulnerability assessment or vulnerability management platforms such as Qualys, Tenable, Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Wiz, Armis, or comparable tools.
  • Experience with attack surface, posture, or exposure management capabilities such as CAASM, EASM, RBVM, CSPM, SSPM, external posture management, or security ratings platforms.
  • Ability to interpret vulnerability findings, CVEs, CVSS, EPSS, threat intelligence, exploitability indicators, asset context, and compensating controls to prioritize risk.
  • Experience working with enterprise asset data, CMDB data, ownership models, assignment groups, and business criticality attributes.
  • Strong analytical skills with experience using Excel, Power BI, SQL, data lakes, reporting platforms, or other data analysis and visualization tools.
  • Working knowledge of common security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Critical Security Controls, PCI DSS, HIPAA, GDPR, OWASP Top 10, SANS Top 25, and MITRE ATT&CK.
  • Excellent written and verbal communication skills, with the ability to explain technical risk to both technical and non-technical audiences.
  • Demonstrated ability to coordinate cross-functional remediation activities in a complex enterprise environment.

Preferred Qualifications

  • Experience helping build or mature a CTEM, exposure management, or unified risk-based vulnerability management program.
  • Experience with vulnerability workflow automation, ServiceNow SecOps, Jira, SOAR, or similar remediation workflow platforms.
  • Experience consolidating and normalizing vulnerability data across multiple source tools and integrating results into dashboards, remediation queues, or governance workflows.
  • Experience with cloud security and cloud posture management across AWS, Azure, Google Cloud, or hybrid environments.
  • Experience with external attack surface management, SaaS security posture management, configuration assurance, or third-party exposure management.
  • Experience supporting regulatory, audit, customer assurance, or compliance reporting related to vulnerability and exposure management.
  • Familiarity with scripting or automation using Python, PowerShell, APIs, or query languages to improve reporting, remediation tracking, and data quality.
  • Ability to influence without direct authority and lead cross-functional initiatives across technical teams, business stakeholders, and security leadership.

Tools and Technologies

The successful candidate should be comfortable working with a broad ecosystem of vulnerability, posture, exposure, and reporting technologies. Relevant tools may include vulnerability scanners, endpoint vulnerability platforms, cloud security posture tools, external attack surface management tools, SaaS posture tools, risk-based vulnerability management platforms, workflow automation solutions, SIEM or threat intelligence platforms, ServiceNow, Power BI, Excel, SQL, and data integration technologies.

Key Competencies

  • Risk-based decision making and prioritization
  • Strong technical analysis and investigative discipline
  • Enterprise stakeholder management and cross-functional coordination
  • Clear communication of technical risk and business impact
  • Operational excellence, process improvement, and automation mindset
  • Data quality awareness and ability to reconcile conflicting tool outputs
  • Ownership, accountability, and ability to lead initiatives with limited direction
  • Ability to balance tactical remediation urgency with strategic program maturity

Success Measures

  • Improved visibility and coverage across enterprise assets, including cloud, endpoint, network, application, SaaS, and externally exposed environments.
  • Reduced critical and high-risk vulnerability exposure through effective prioritization, remediation governance, and stakeholder engagement.
  • Improved mean time to remediate, vulnerability closure rate, and SLA adherence.
  • Increased adoption of risk-based vulnerability management and CTEM practices across security and technology teams.
  • Improved quality, consistency, and usability of vulnerability reporting, dashboards, ownership mapping, and remediation workflows.
  • Demonstrated progress in reducing attack surface risk and improving overall security posture.
What Cencora offers

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members' ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencora

Full timeEqual Employment Opportunity

Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.

The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.

Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email hrsc@cencora.com. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned

Affiliated CompaniesAffiliated Companies: AmerisourceBergen Services Corporation