1

Vulnerability Management Engineer Jobs (NOW HIRING)

Vulnerability Management Lead

Austin, TX ยท On-site

$101K - $133K/yr

They are seeking a hands-on Vulnerability Management Lead to own the VM program end-to-end, acting ... The role involves driving accountability across engineering teams and shaping the long-term VM ...

New

Vulnerability Management Process Define and implement a risk-based vulnerability management ... Work with IT, DevOps, and engineering teams to integrate security patching and vulnerability ...

Vulnerability Management Lead

Alexandria, VA ยท Hybrid

$109K - $144K/yr

RiVidium is seeking a Vulnerability Management Lead to support our planned MODES III team ... Partner with engineering and security teams to reduce risk and improve remediation velocity.

next page

Showing results 1-20

Vulnerability Management Engineer information

See salary details

$39K

$101.8K

$137.5K

How much do vulnerability management engineer jobs pay per year?

As of Jun 19, 2026, the average yearly pay for vulnerability management engineer in the United States is $101,752.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,000.00 and $116,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Vulnerability Management Engineer, and why are they important?

To thrive as a Vulnerability Management Engineer, you need a solid understanding of cybersecurity principles, vulnerability assessment methodologies, and experience with network and system security, often backed by a relevant degree and certifications like CISSP, CEH, or CompTIA Security+. Familiarity with vulnerability management tools such as Qualys, Nessus, or Rapid7, and knowledge of ticketing and SIEM systems, is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you collaborate with IT teams and convey security risks clearly. These skills and qualities are essential for proactively identifying, prioritizing, and remediating security vulnerabilities to protect organizational assets and maintain compliance.

What is the difference between Vulnerability Management Engineer vs Security Analyst?

AspectVulnerability Management EngineerSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Primary FocusIdentifying, assessing, and managing vulnerabilities in systemsMonitoring security events, analyzing threats, and incident response
Work EnvironmentIT/security teams, vulnerability scanning tools, security platformsSecurity operations centers, incident response teams, monitoring dashboards
Industry UsageIT security, cybersecurity firms, large enterprisesAll industries with cybersecurity needs, including finance, healthcare, and government

The Vulnerability Management Engineer primarily focuses on identifying and mitigating system vulnerabilities, while the Security Analyst monitors security events and responds to incidents. Both roles require similar certifications and often work within the same security teams, but their day-to-day tasks differ significantly.

What does a Vulnerability Management Engineer do?

A Vulnerability Management Engineer is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems and networks. They use specialized tools to scan for weaknesses, prioritize risks based on potential impact, and work with IT teams to implement remediation strategies. Additionally, they monitor emerging threats, ensure compliance with security policies, and help educate staff on best practices to protect against cyberattacks.

How does a Vulnerability Management Engineer typically collaborate with other IT and security teams within an organization?

As a Vulnerability Management Engineer, you will work closely with various teams, including IT operations, network administrators, and application developers, to identify, assess, and remediate security vulnerabilities. Collaboration often involves coordinating vulnerability scans, sharing prioritized risk assessments, and helping teams understand the technical and business impact of identified issues. You'll also facilitate remediation efforts by advising on best practices, tracking progress, and sometimes providing training or technical support to ensure vulnerabilities are addressed in a timely manner. Effective communication and relationship-building skills are essential for success in this collaborative, cross-functional role.
More about Vulnerability Management Engineer jobs
What cities are hiring for Vulnerability Management Engineer jobs? Cities with the most Vulnerability Management Engineer job openings:
What states have the most Vulnerability Management Engineer jobs? States with the most job openings for Vulnerability Management Engineer jobs include:

Vulnerability Management Lead

Saronic Technologies

Austin, TX โ€ข On-site

$101K - $133K/yr

Full-time

Posted 2 days ago


Job description

Job Summary:
Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms. They are seeking a hands-on Vulnerability Management Lead to own the VM program end-to-end, acting as the technical authority for vulnerability discovery, triage, prioritization, remediation, and reporting across various environments. The role involves driving accountability across engineering teams and shaping the long-term VM posture as the company scales.
Responsibilities:
โ€ข Own end-to-end vulnerability lifecycle: discovery, validation, prioritization, remediation tracking, exception management, and verification across cloud, on-prem, container, and embedded Linux environments
โ€ข Operate and optimize enterprise vulnerability scanning platforms for continuous credentialed scanning across servers, endpoints, network devices, containers, and cloud assets; maintain coverage, schedules, and configuration audit policies
โ€ข Integrate vulnerability scanning into CI/CD pipelines to harden build workflows, enforce least-privilege controls, and surface supply chain risks before they reach production
โ€ข Leverage AI-assisted scanning and graph-based enrichment pipelines to accelerate triage, map lateral exposure paths, and prioritize findings by exploitability and mission impact
โ€ข Correlate findings across tools to eliminate noise, reduce false positives, and surface the vulnerabilities that actually matter
โ€ข Apply CVSS, CISA KEV, exploit maturity, and asset exposure context โ€” including internet-facing systems, privileged access paths, and classified adjacency โ€” to drive risk-based SLAs and remediation sequencing
โ€ข Partner with software and platform engineering teams to drive timely remediation; own escalation paths for aging critical and high findings
โ€ข Lead critical CVE response: rapid triage, impact assessment, containment guidance, and stakeholder communication for zero-days and actively exploited vulnerabilities
โ€ข Govern exception management: risk acceptance with compensating controls, time-bound approvals, and periodic review cycles
โ€ข Coordinate patching windows and change management across Windows, Linux, network devices, and cloud services
โ€ข Align the VM program to CMMC Level 2/3 requirements; produce audit-ready evidence, POA&Ms, and control effectiveness documentation
โ€ข Deliver executive and operational reporting: exposure trends, SLA performance, mean time to remediate, patch coverage, and remediation velocity
โ€ข Support CMMC assessments and audits with clean, well-documented vulnerability data and remediation history
โ€ข Maintain asset inventory hygiene and scan coverage metrics; ensure classified and sensitive system boundaries are respected in tooling and data handling
โ€ข Build and mature automation for scan scheduling, finding enrichment, ticket creation, SLA tracking, and reporting โ€” reducing manual overhead as the program scales
โ€ข Define and refine VM policies, procedures, and playbooks including critical CVE response runbooks and patch cadence standards
โ€ข Evaluate and recommend tooling improvements; drive integration across the vulnerability management and broader security stack
โ€ข Mentor and support analysts as the team grows; run tabletop exercises for vulnerability and patching scenarios
Qualifications:
Required:
โ€ข 5+ years in cybersecurity with 3+ years of hands-on vulnerability management ownership in hybrid on-prem/cloud environments
โ€ข Deep operational expertise with enterprise vulnerability scanning platforms โ€” credentialed scanning, policy tuning, coverage management, and integration with downstream workflows
โ€ข Strong command of CVE/CVSS scoring, CISA KEV, exploit maturity indicators, and the ability to translate technical risk into business impact for non-technical stakeholders
โ€ข Experience with CI/CD security tooling and supply chain risk management, including build pipeline security principles
โ€ข Proven track record driving remediation accountability across engineering teams โ€” you know how to get vulnerabilities closed, not just reported
โ€ข Experience aligning VM programs to federal or defense compliance frameworks; CMMC, NIST SP 800-171, or NIST RMF experience strongly preferred
โ€ข Metrics-driven: comfortable owning exposure reduction KPIs, SLA adherence, MTTR, and patch coverage dashboards
โ€ข Clear, direct communicator โ€” equally effective in a technical deep-dive and an executive briefing
โ€ข Security clearance eligibility
Preferred:
โ€ข Active Secret or TS clearance, or prior clearance history
โ€ข Experience with AI-assisted vulnerability tooling, graph-based asset and exposure analysis, or automated enrichment pipelines
โ€ข Experience with CI/CD pipeline security hardening platforms
โ€ข Experience operating in classified or air-gapped environments
โ€ข Scripting or automation experience (Python, PowerShell, or Bash) for scan orchestration, data normalization, API integrations, and reporting pipelines
โ€ข Experience with container and cloud-native vulnerability management using CSP-native security tooling
โ€ข Familiarity with NIST SP 800-218 (Secure Software Development Framework) and software supply chain security frameworks
โ€ข Relevant certifications: CISSP, CySA+, GCSA, GCPN, Security+, or equivalent
Company:
Saronic is building cutting-edge unmanned surface vehicles that enable maritime security and domain awareness by combining best-in-class hardware, software and artificial intelligence into one scalable, fully integrated platform. Founded in 2022, the company is headquartered in Austin, USA, with a team of 1001-5000 employees. The company is currently Late Stage.