1

Threat Vulnerability Management Engineer Jobs (NOW HIRING)

Vulnerability Management Engineer

Seattle, WA ยท On-site +1

$140 - $155/hr

Top 5: * 5+ years hands-on vulnerability management or security engineering * Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender ...

Sr Vulnerability Management Engineer

$107K - $146K/yr

The Impact You'll Make in this Role The Senior Vulnerability Management Engineer is a senior technical contributor responsible for operating, scaling, and maturing the enterprise vulnerability ...

Sr Vulnerability Management Engineer

OR ยท On-site +1

$104K - $143K/yr

The Impact You'll Make in this Role The Senior Vulnerability Management Engineer is a senior technical contributor responsible for operating, scaling, and maturing the enterprise vulnerability ...

Sr Vulnerability Management Engineer

New York, NY ยท Remote

$114K - $157K/yr

The Impact You'll Make in this Role The Senior Vulnerability Management Engineer is a senior technical contributor responsible for operating, scaling, and maturing the enterprise vulnerability ...

Senior Vulnerability Management Engineer

Raleigh, NC ยท On-site

$111K - $152K/yr

Celonis, a leader in Process Mining technology, is looking for an experienced Senior Vulnerability Management Engineer to join our elite Security Engineering Team. This crucial role involves ...

As a Senior Vulnerability Management Engineer at Group 1001, you are equal parts security practitioner and infrastructure engineer. You will combine your deep vulnerability expertise with systems ...

Endpoint Security & Vulnerability Management Engineer Please note: As per current corporate policy, this position may require you to be in the office up to four (4) days per week and/or as ...

The Engineer III will help lead Continuous Threat Exposure Management (CTEM) activities, operate and optimize attack surface management and vulnerability management tools, and partner with technology ...

Endpoint Security & Vulnerability Management Engineer Please note: As per current corporate policy, this position may require you to be in the office up to four (4) days per week and/or as ...

Endpoint Security & Vulnerability Management Engineer Please note: As per current corporate policy, this position may require you to be in the office up to four (4) days per week and/or as ...

Showing results 41-60

Threat Vulnerability Management Engineer information

See salary details

$42K

$96K

$149K

How much do threat vulnerability management engineer jobs pay per year?

As of Sep 9, 2026, the average yearly pay for threat vulnerability management engineer in the United States is $96,000.00, according to ZipRecruiter salary data. Most workers in this role earn between $77,000.00 and $117,500.00 per year, depending on experience, location, and employer.

What is a threat vulnerability management engineer?

A Threat Vulnerability Management Engineer is a cybersecurity professional responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT systems. They use specialized tools and methodologies to scan networks, applications, and devices for potential threats, analyze risks, and recommend or implement remediation strategies. Their work helps protect sensitive data and ensure compliance with security standards. They often collaborate with IT, security teams, and business units to respond rapidly to new vulnerabilities and reduce the risk of cyberattacks.

What are the key skills and qualifications needed to thrive as a threat vulnerability management engineer, and why are they important?

To thrive as a Threat Vulnerability Management Engineer, you need a strong understanding of cybersecurity principles, risk assessment, and vulnerability scanning, often supported by a degree in computer science or information security. Familiarity with security tools like Nessus, Qualys, Rapid7, and certifications such as CISSP or CEH are typically required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and collaborating with cross-functional teams. These skills ensure proactive identification, evaluation, and mitigation of security vulnerabilities, protecting organizations from potential cyber threats.

What are some common challenges faced by threat vulnerability management engineers, and how can they be addressed?

Threat Vulnerability Management Engineers often face the challenge of prioritizing vulnerabilities across a vast and constantly changing IT landscape. Balancing the need for quick remediation with resource limitations requires strong analytical skills and effective communication with stakeholders. Staying updated on the latest threats and integrating automated tools for scanning and reporting can help streamline the process. Building collaborative relationships with IT and development teams is also crucial to ensure timely resolution and minimize risk to the organization.

What cities are hiring for Threat Vulnerability Management Engineer jobs?

Cities with the most Threat Vulnerability Management Engineer job openings:

What states have the most Threat Vulnerability Management Engineer jobs?

States with the most job openings for Threat Vulnerability Management Engineer jobs include:

What are popular job titles related to Threat Vulnerability Management Engineer jobs?

For Threat Vulnerability Management Engineer jobs, the most frequently searched job titles are:

Vulnerability Management Engineer

Seattle, WA โ€ข On-site

WideNet Consulting Group
Recruiting and Staffing Servicesย โ€ขย 51 - 200 employees

$140 - $155/hr

Other

Medical, Retirement

Posted 14 days ago


Key responsibilities

  • Maintain and expand scan and sensor coverage across endpoints, servers, cloud workloads, containers, network devices, and SaaS.

  • Build and operate risk-based prioritization models, enrich findings with business context, and manage remediation SLAs.

  • Drive remediation campaigns, automate ticket creation and closure, and verify that remediation reduces exposure.


Job description

Job Description:

Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.

Job Description:

This position supports advancing the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate.

Detect
  • Maintain and expand scan and sensor coverage across endpoints, servers, cloud workloads, containers, network devices, and SaaS
  • Close asset visibility gaps, including shadow IT, unmanaged devices, and assets provisioned outside IT
  • Tune authenticated scanning, credential health, agent health, and scan cadence to reduce false negatives
  • Reconcile vulnerability data across multiple sources into a single authoritative inventory
Prioritize
  • Build and operate risk-based prioritization that blends CVSS severity, EPSS likelihood, CISA KEV exploitation status, and SSVC decision logic
  • Enrich findings with business context: asset criticality, data classification, internet exposure, compensating controls, application owner, and business unit
  • Replace severity-only queues with defensible, tiered remediation SLAs
  • Operate the exception and risk acceptance workflow, including expiration and re-review
Report
  • Design and publish program metrics: coverage, mean time to remediate by tier, backlog aging, SLA compliance, and burndown
  • Deliver executive and operational dashboards, including Power BI reporting fed by automated pipelines
  • Produce audit and assurance evidence on request
  • Translate technical findings into business risk language for non-technical stakeholders
Remediate
  • Drive remediation campaigns in partnership with IT operations, endpoint, cloud, and application teams
  • Automate ticket creation, routing, and closure into the ITSM platform
  • Perform closed-loop verification that remediation actually reduced exposure
  • Support emergency response for actively exploited vulnerabilities
Platform and program
  • Direct, hands-on experience implementing or migrating to a new enterprise vulnerability management platform, including requirements definition, proof of concept, integration, data migration, and rollout
  • Direct experience driving continuous improvement to an established VM program, including maturity assessment, process redesign, and runbook development
Required Qualifications
  • 5+ years hands-on vulnerability management or security engineering
  • Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium)
  • Demonstrated experience building prioritization models that incorporate business context, not severity alone
  • Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration
  • Working fluency with KQL or an equivalent query language for security data
  • Experience integrating VM data with CMDB, ITSM, and BI platforms
  • Cloud vulnerability management experience across Azure and at least one other provider
  • Ability to work independently and produce written deliverables without heavy oversight
Preferred
  • Experience with Tanium and Microsoft Defender for Endpoint as data sources
  • Container and image scanning experience
  • Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns
  • Exposure to CTEM or exposure management program models
  • Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500

Pay Range: $75.00 โ€“ $85.00 per hour, depending upon experience.

Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.

SLA Describe hiring preference(C/CTH/FTE)

12 month contract

Bill rate or FTE Salary range and target

Target rate: We need to make our best offer, so let's discuss rates, keeping in mind they can go a bit higher than for our other clients.

Potential target: $140 to $155/hr

Work Authorization Requirements

No C2C without approval 1099 ok

Budget Confirmed?

Yes

Why is the position open?

New role

How long has the position been open?

Just opened

Is there HR/vendor competition? Exclusive?

Competition โ€“ this is an RFP process

Interview Process
  • 2 interviews โ€“ likely team fit/leadership + technical
Work location
  • Local and onsite 2-3 days a week is ideal and will be prioritized over remote
  • Open to remote but must be in PST. This is not preferred.
Project overview

Advance the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate.

Top 5
  • 5+ years hands-on vulnerability management or security engineering
  • Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium)
  • Demonstrated experience building prioritization models that incorporate business context, not severity alone
  • Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration
  • Working fluency with KQL or an equivalent query language for security data
Nice to Have
  • Experience with Tanium and Microsoft Defender for Endpoint as data sources
  • Container and image scanning experience
  • Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns
  • Exposure to CTEM or exposure management program models
  • Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500
#J-18808-Ljbffr