1

Vulnerability Management Automation Engineer Jobs

Cloud Automation Engineer

Fort Worth, TX

$53.50 - $71.50/hr

They focus on automating CI/CD pipelines, implementing security practices, and managing DTAP environments while ensuring compliance and vulnerability management. The Cloud Automation Engineer ...

next page

Showing results 1-20

Vulnerability Management Automation Engineer information

See salary details

$37K

$107.1K

$163K

How much do vulnerability management automation engineer jobs pay per year?

As of May 31, 2026, the average yearly pay for vulnerability management automation engineer in the United States is $107,126.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,500.00 and $123,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Vulnerability Management Automation Engineer, and why are they important?

To thrive as a Vulnerability Management Automation Engineer, you need expertise in cybersecurity, scripting languages (such as Python or PowerShell), and a strong understanding of vulnerability assessment methodologies, often supported by a degree in computer science or information security. Familiarity with vulnerability scanning tools (like Nessus or Qualys), security information and event management (SIEM) systems, and certifications such as CISSP or CEH are typically required. Strong problem-solving skills, attention to detail, and effective communication help you identify risks and collaborate with cross-functional teams. These skills are crucial for proactively identifying, automating the remediation of security weaknesses, and protecting organizational assets from cyber threats.

What are some common challenges faced by Vulnerability Management Automation Engineers when integrating automated tools into existing security workflows?

A common challenge for Vulnerability Management Automation Engineers is ensuring that automated tools seamlessly integrate with legacy systems and current security processes without causing disruptions. Balancing automation efficiency with accuracy is crucial, as automated scans can sometimes generate false positives or miss context-specific vulnerabilities. Additionally, coordinating with cross-functional teams, such as IT and DevOps, is essential to align remediation efforts and establish clear communication channels. Staying updated with the latest threat landscapes while continuously refining automation scripts also presents an ongoing challenge.

What does a Vulnerability Management Automation Engineer do?

A Vulnerability Management Automation Engineer designs, develops, and maintains automated solutions to identify, assess, and remediate security vulnerabilities within an organization's systems and networks. They work closely with security and IT teams to streamline vulnerability scanning, reporting, and patch management processes. Their goal is to reduce manual work, improve efficiency, and ensure timely mitigation of security risks by leveraging automation tools and scripting. This role requires strong technical skills in cybersecurity, automation technologies, and familiarity with vulnerability management platforms.

What is the difference between Vulnerability Management Automation Engineer vs Vulnerability Analyst?

AspectVulnerability Management Automation EngineerVulnerability Analyst
CertificationsCompTIA Security+, CISSP, or similarCompTIA Security+, GIAC, or similar
Work EnvironmentFocus on automation tools, scripting, and security systemsFocus on vulnerability assessment, analysis, and reporting
Industry UsageIT security teams, cybersecurity firms, large enterprisesSecurity operations centers, IT departments, consulting firms

The Vulnerability Management Automation Engineer primarily develops and maintains automation tools to streamline vulnerability detection and remediation, utilizing scripting and security platforms. In contrast, the Vulnerability Analyst conducts manual assessments, analyzes vulnerabilities, and reports findings. Both roles are essential in cybersecurity but differ in technical focus and daily tasks.

More about Vulnerability Management Automation Engineer jobs
What job categories do people searching Vulnerability Management Automation Engineer jobs look for? The top searched job categories for Vulnerability Management Automation Engineer jobs are:
Infographic showing various Vulnerability Management Automation Engineer job openings in the United States as of May 2026, with employment types broken down into 100% Full Time. Highlights an 25% Physical, and 75% Remote job distribution, with an average salary of $107,126 per year, or $51.5 per hour.
Cybersecurity Engineer - Threat & Vulnerability Management

Cybersecurity Engineer - Threat & Vulnerability Management

GM Financial

Irving, TX • Hybrid

Full-time

Retirement

Posted 7 days ago


GM Financial rating

7.7

Company rating: 7.7 out of 10

Based on 38 frontline employees who took The Breakroom Quiz

72nd of 139 rated vehicle equipment hire


Job description

Why GM Financial Cybersecurity?

Innovation isn't just a talking point at GM Financial, it's how we operate. By joining our team, you'll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.

Cybersecurity is central to our strategic vision, so you'll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.

Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive.

This position will be posted until filled.

Opportunity to work in a hybrid model: Potential to work 4 days onsite and 1 day remote

What makes you an ideal candidate?

  • Deep understanding of vulnerability management processes, CVSS scoring, and remediation strategies.
  • Hands-on experience with application security tools (e.g., Veracode, Checkmarx, Burp Suite, OWASP ZAP).
  • Strong knowledge of secure software development lifecycle (SDLC) and DevSecOps principles.
  • Familiarity with container security, Kubernetes, and cloud-native application security.
  • Experience securing cloud environments (AWS, Azure, GCP) and implementing IaC security controls (Terraform, CloudFormation).
  • Proficiency in scripting and automation (Python, Bash, or similar) for vulnerability scanning and remediation workflows.
  • Solid understanding of networking fundamentals, TCP/IP, OSI model, and application layer protocols (HTTP, SSL/TLS, DNS).
  • Knowledge of security frameworks and standards (NIST CSF, ISO 27001, OWASP Top 10).
  • Strong analytical skills for interpreting vulnerability data and assessing business impact.
  • Excellent communication skills for collaborating with developers, operations teams, and leadership.
  • Ability to think strategically, innovate, and implement scalable security solutions.

Experience and Education

  • Minimum of 1 to 5 years of experience in large and complex business environments with a successful track record working directly with senior level management preferred
  • Minimum of 1 year experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering, or Network Operations, Information Technology, Application Development preferred
  • Bachelor's Degree in related field or equivalent work experience strongly preferred
  • Cybersecurity related certifications strongly preferred
  • Experience with CI/CD security integration and automated vulnerability scanning.
  • Familiarity with microservices architecture and securing APIs.
  • Advanced technical writing and documentation skills.
  • Knowledge of threat modeling and risk assessment methodologies.

What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.

Our Culture: Our team members define and shape our culture - an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work - we thrive.

Compensation: Competitive pay and bonus eligibility

Work Life Balance: Flexible hybrid work environment, 4-days a week in office

This position is not open to agency submissions

#GMFJobs

#LI-SC1

About the role:

As a Cybersecurity Engineer specializing in Vulnerability Management and Application Security, you will play a critical role in safeguarding enterprise systems and applications against evolving threats. Your primary focus will be on identifying, assessing, and mitigating vulnerabilities across infrastructure and application layers, while ensuring compliance with security standards and best practices.

In this role you will:

  • Develop and maintain technical security requirements, standards, and documentation for vulnerability management and application security.
    • Design and implement security solutions with emphasis on:
    • Vulnerability Management (VM) platforms and processes
    • Application Security tools (SAST, DAST, IAST)
    • Secure coding practices and CI/CD pipeline integration
  • Perform vulnerability assessments and penetration testing for applications and systems; analyze findings and drive remediation efforts.
  • Collaborate with development and operations teams to integrate security controls into DevOps workflows and Infrastructure as Code (IaC).
  • Monitor and analyze system logs and security alerts to detect unauthorized access or anomalies.
  • Create and present security metrics, vulnerability trends, and risk reports to leadership.
  • Participate in incident response activities, providing technical expertise for application-related security incidents.
  • Conduct periodic risk assessments for applications and supporting infrastructure.
  • Evaluate and recommend security tools and technologies to enhance vulnerability detection and remediation capabilities.
  • Stay current on emerging threats, vulnerabilities, and regulatory requirements impacting application security.

What GM Financial employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom