1

Vulnerability Management Engineer Jobs in Phoenix, AZ

... DevOps teams. You'll help design, operationalize, and continually improve our vulnerability ... Own the vulnerability management lifecycle: Drive end-to-end vulnerability management across ...

Track and enforce remediation timelines in coordination with SOC, IR, and engineering teams ... Minimum of 2 years of experience in security operations, vulnerability management, or risk analysis.

Track and enforce remediation timelines in coordination with SOC, IR, and engineering teams ... Minimum of 2 years of experience in security operations, vulnerability management, or risk analysis.

Track and enforce remediation timelines in coordination with SOC, IR, and engineering teams ... Minimum of 2 years of experience in security operations, vulnerability management, or risk analysis.

Track and enforce remediation timelines in coordination with SOC, IR, and engineering teams ... Minimum of 8 years of experience in security operations, vulnerability management, or risk analysis ...

Track and enforce remediation timelines in coordination with SOC, IR, and engineering teams ... Minimum of 8 years of experience in security operations, vulnerability management, or risk analysis ...

Track and enforce remediation timelines in coordination with SOC, IR, and engineering teams ... Minimum of 8 years of experience in security operations, vulnerability management, or risk analysis ...

ServiceNow SecOps Sr. Developer

Phoenix, AZ · On-site

$53.50 - $73.75/hr

Hiring Alert | ServiceNow SecOps Sr. Developer - Security Operations & Vulnerability Response ... Security Incident Response & Vulnerability Management * Workflows, Business Rules & Client Scripts

The Cyber Defense team manages security controls spanning vulnerability scanning, security patching ... You will join a DevOps team of Information Security professionals responsible for developing ...

Senior Cloud Engineer

Phoenix, AZ · On-site

$55.25 - $74/hr

Senior Cloud Engineer Reporting To: Chief Technology Officer Summary Invessio is building an ... evidence, vulnerability management, and applicable fintech security standards. * Implement ...

... engineering teams. * Demonstrated experience leading audit, compliance, or regulatory engagements within a financial institution. * Strong understanding of vulnerability management processes, tools ...

next page

Showing results 1-20

Vulnerability Management Engineer information

See Phoenix, AZ salary details

$38.7K

$101K

$136.5K

How much do vulnerability management engineer jobs pay per year?

As of Sep 2, 2026, the average yearly pay for vulnerability management engineer in Phoenix, AZ is $101,031.00, according to ZipRecruiter salary data. Most workers in this role earn between $83,400.00 and $115,700.00 per year, depending on experience, location, and employer.

What does a vulnerability management engineer do?

A Vulnerability Management Engineer is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems and networks. They use specialized tools to scan for weaknesses, prioritize risks based on potential impact, and work with IT teams to implement remediation strategies. Additionally, they monitor emerging threats, ensure compliance with security policies, and help educate staff on best practices to protect against cyberattacks.

What are the key skills and qualifications needed to thrive as a vulnerability management engineer, and why are they important?

To thrive as a Vulnerability Management Engineer, you need a solid understanding of cybersecurity principles, vulnerability assessment methodologies, and experience with network and system security, often backed by a relevant degree and certifications like CISSP, CEH, or CompTIA Security+. Familiarity with vulnerability management tools such as Qualys, Nessus, or Rapid7, and knowledge of ticketing and SIEM systems, is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you collaborate with IT teams and convey security risks clearly. These skills and qualities are essential for proactively identifying, prioritizing, and remediating security vulnerabilities to protect organizational assets and maintain compliance.

How does a vulnerability management engineer typically collaborate with other IT and security teams within an organization?

As a Vulnerability Management Engineer, you will work closely with various teams, including IT operations, network administrators, and application developers, to identify, assess, and remediate security vulnerabilities. Collaboration often involves coordinating vulnerability scans, sharing prioritized risk assessments, and helping teams understand the technical and business impact of identified issues. You'll also facilitate remediation efforts by advising on best practices, tracking progress, and sometimes providing training or technical support to ensure vulnerabilities are addressed in a timely manner. Effective communication and relationship-building skills are essential for success in this collaborative, cross-functional role.

What is the difference between Vulnerability Management Engineer vs Security Analyst?

AspectVulnerability Management EngineerSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Primary FocusIdentifying, assessing, and managing vulnerabilities in systemsMonitoring security events, analyzing threats, and incident response
Work EnvironmentIT/security teams, vulnerability scanning tools, security platformsSecurity operations centers, incident response teams, monitoring dashboards
Industry UsageIT security, cybersecurity firms, large enterprisesAll industries with cybersecurity needs, including finance, healthcare, and government

The Vulnerability Management Engineer primarily focuses on identifying and mitigating system vulnerabilities, while the Security Analyst monitors security events and responds to incidents. Both roles require similar certifications and often work within the same security teams, but their day-to-day tasks differ significantly.

What are popular job titles related to Vulnerability Management Engineer jobs in Phoenix, AZ?

For Vulnerability Management Engineer jobs in Phoenix, AZ, the most frequently searched job titles are:

What job categories do people searching Vulnerability Management Engineer jobs in Phoenix, AZ look for?

The top searched job categories for Vulnerability Management Engineer jobs in Phoenix, AZ are:

Infographic showing various Vulnerability Management Engineer job openings in Phoenix, AZ as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, and 3% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $101,031 per year, or $48.6 per hour.

Senior Vulnerability Management Analyst

Osaic

Scottsdale, AZ • Hybrid

$105K - $120K/yr

Full-time

Medical, Dental, Vision, Retirement

Re-posted 29 days ago


Osaic rating

8.1

Company rating: 8.1 out of 10

Based on 12 frontline employees who took The Breakroom Quiz


Job description

Current Employees and Contractors Apply HereOsaic Careers

IT Vulnerability Opportunity in Financial Services

Senior Vulnerability Management Analyst

Location(s):

Atlanta: 2300 Windy Ridge Pkwy SE, Suite750, Atlanta, GA 30339

La Vista:12325 Port Grace Blvd, La Vista, NE 68128

Oakdale: 7755 3rd St. N, Oakdale, MN 55128

Scottsdale: 18700 N Hayden Rd, Suite 255, Scottsdale, AZ 85255

St. Petersburg: 877 Executive Center Dr. W, Suite 300, St. Petersburg, FL 33702

Osaic has returned to the office on a hybrid schedule requiring a minimum of 4 days weekly in the office. Applicants should be located at one of our hubs listed above and must be willing to work this schedule.

Role Type: Full-time, Non-Exempt

Salary: $105,000 - $120,000 per year + annual performance-based bonus

Actual compensation offered will be determined individually, based on a number of job-related factors, including location, skills, licensure, experience, and education.

Our competitive compensation is just one component of Osaic's total compensation package. Additional benefits include health, vision, dental insurance, 401k, paid time away, volunteer days and much more. To view more details of what you can look forward to, visit our careers page:Osaic Benefits.

Summary:

We're seeking a Senior Vulnerability Analyst to lead and mature our enterprise vulnerability programs across SDLC (secure development lifecycle), external attack surface, and internal infrastructure/applications. This role drives endtoend vulnerability lifecycle management, from discovery and risk triage to remediation validation and program metrics, while partnering closely with Engineering, Product, Cloud/SRE, and IT. You'll also coordinate penetration testing readiness, evidence collection, and remediation plans, and help embed security into the development workflow. The ideal candidate has strong application development experience, practical threat modeling skills, and a pragmatic approach to risk.

Education Requirements:

Bachelor's degree preferred, high school diploma (or equivalent) in combination with significant experience will be considered in lieu of degree. Minimum of high school diploma or equivalent is required.

Responsibilities:

  • Lead vulnerability prioritization using CVSS, KEV, exploit intel, and asset criticality.
  • Partner with engineering and application teams to remove remediation blockers.
  • Own complex vulnerability investigations and coordinate cross-team resolution.
  • Mentor junior analysts and help improve internal processes.
  • Provide remediation guidance and secure configuration recommendations.
  • Help with pen test prework: scope definition, rules of engagement, asset inventories, credential/test data coordination, and stakeholder comms.
  • Manage findings intake, severity validation, and remediation plans with accountable owners; track to closure and report to leadership.
  • Lead lessons learned and control improvements to reduce recurring issues and improve test efficiency.
  • Lead continuous reduction of external attack surface: internetexposed services, DNS, certificates, cloud perimeters, API endpoints, and thirdparty exposures.
  • Partner with Cloud, SRE, and Networking to harden configurations, minimize unknown/legacy exposures, and validate fixes.
  • Partner with engineering to mature SAST/DAST/IAST/OSS/SBOM practices, secure build pipelines, and implement "shiftleft" controls (precommit, PR gates, CI quality bars).
  • Guide threat modeling, security requirements, and secure coding practices; advise on remediation patterns and safer libraries/frameworks.
  • Review architecture and code for highrisk components (authN/Z, crypto, secrets handling, supply chain, multitenant boundaries).
  • All other duties as assigned.

Basic Requirements:

  • Deep technical/domain expertise and ability to lead initiatives.
  • Strong understanding of OS, cloud environments, and vulnerability lifecycles.
  • Partner with Detection & Response to ensure logging, alerting, and containment strategies account for known weaknesses.
  • Target certifications: CISSP, GIAC (GSEC/GCIA/GCIH), CCSP.

Preferred Requirements:

  • Experience with KEV catalog operationalization and threat-intel integrations.
  • Knowledge of automation platforms
Current Employees and Contractors Apply Here

What Osaic employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Osaic logo

About Osaic

Sourced by ZipRecruiter

Industry

Finance and insurance

Company size

1,001 - 5,000 Employees

Headquarters location

Phoenix, AZ, US

Year founded

2016