Executing vulnerability and patch management tasks across infrastructure, middleware, and applications * Analyzing exposure data, asset criticality, exploitability, and attack paths to help ...
Executing vulnerability and patch management tasks across infrastructure, middleware, and applications * Analyzing exposure data, asset criticality, exploitability, and attack paths to help ...
Executing vulnerability and patch management tasks across infrastructure, middleware, and applications * Analyzing exposure data, asset criticality, exploitability, and attack paths to help ...
Executing vulnerability and patch management tasks across infrastructure, middleware, and applications * Analyzing exposure data, asset criticality, exploitability, and attack paths to help ...
Lead and continuously enhance vulnerability management programs, including security scanning, penetration testing, remediation tracking, and vendor coordination * Conduct proactive threat hunting and ...
New
Lead and continuously enhance vulnerability management programs, including security scanning, penetration testing, remediation tracking, and vendor coordination * Conduct proactive threat hunting and ...
New
Principal, Security Engineering & Vulnerability Management for WB Games
Burbank, CA · On-site
$177.17 - $329.03/hr
Principal, Security Engineering & Vulnerability Management for WB Games Must work a hybrid schedule (3 days onsite) out of NYC or Burbank office. Job Responsibilities * Act as the primary link ...
Principal, Security Engineering & Vulnerability Management for WB Games
Burbank, CA · On-site
$177.17 - $329.03/hr
Principal, Security Engineering & Vulnerability Management for WB Games Must work a hybrid schedule (3 days onsite) out of NYC or Burbank office. Job Responsibilities * Act as the primary link ...
GEICO is seeking a highly experienced Staff Security Engineer to lead the strategy, architecture, and execution of Vulnerability Management across a complex, hybrid technology ecosystem. This role ...
GEICO is seeking a highly experienced Staff Security Engineer to lead the strategy, architecture, and execution of Vulnerability Management across a complex, hybrid technology ecosystem. This role ...
Vulnerability Engineer
Irvine, CA · On-site
ClifyX is a company focused on cybersecurity solutions, and they are seeking a Vulnerability Engineer to enhance their vulnerability management processes. The role involves analyzing vulnerability ...
Vulnerability Engineer
Irvine, CA · On-site
ClifyX is a company focused on cybersecurity solutions, and they are seeking a Vulnerability Engineer to enhance their vulnerability management processes. The role involves analyzing vulnerability ...
Security Engineer, Vulnerability Management and Automation
San Jose, CA · On-site
$150K - $350K/yr
Build and manage automation for vulnerability management, and help Figure prioritize and address vulnerabilities across the infrastructure * Identify, triage, and remediate vulnerabilities and ...
Security Engineer, Vulnerability Management and Automation
San Jose, CA · On-site
$150K - $350K/yr
Build and manage automation for vulnerability management, and help Figure prioritize and address vulnerabilities across the infrastructure * Identify, triage, and remediate vulnerabilities and ...
They are looking for a Security Engineer to join the Security & Privacy team, focusing on designing, implementing, and managing vulnerability discovery and remediation across enterprise and Cloud ...
They are looking for a Security Engineer to join the Security & Privacy team, focusing on designing, implementing, and managing vulnerability discovery and remediation across enterprise and Cloud ...
They are seeking a Security Engineer to join the Security & Privacy team, focusing on designing, implementing, and managing vulnerability discovery and remediation across enterprise and Cloud ...
They are seeking a Security Engineer to join the Security & Privacy team, focusing on designing, implementing, and managing vulnerability discovery and remediation across enterprise and Cloud ...
Build and manage automation for vulnerability management, and help Figure prioritize and address vulnerabilities across the infrastructure * Identify, triage, and remediate vulnerabilities and ...
Build and manage automation for vulnerability management, and help Figure prioritize and address vulnerabilities across the infrastructure * Identify, triage, and remediate vulnerabilities and ...
The Job The Principal, Security Engineering & Vulnerability Management for WB Games is a key leader within the Global Information and Content Security (GICS) team, implementing WBD's security ...
The Job The Principal, Security Engineering & Vulnerability Management for WB Games is a key leader within the Global Information and Content Security (GICS) team, implementing WBD's security ...
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
This is an Individual Contributor role in the Exposure Management Content team responsible for researching, developing and delivering our Host and Network Vulnerability Assessment detections for ...
This is an Individual Contributor role in the Exposure Management Content team responsible for researching, developing and delivering our Host and Network Vulnerability Assessment detections for ...
This is an Individual Contributor role in the Exposure Management Content team responsible for researching, developing and delivering our Host and Network Vulnerability Assessment detections for ...
This is an Individual Contributor role in the Exposure Management Content team responsible for researching, developing and delivering our Host and Network Vulnerability Assessment detections for ...
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Cyber Manager - ASM Vulnerability Management - Patching
San Diego, CA · On-site
$117K - $159K/yr
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Cyber Manager - ASM Vulnerability Management - Patching
San Diego, CA · On-site
$117K - $159K/yr
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Cyber Manager - ASM Vulnerability Management - Patching
San Francisco, CA · On-site
$130K - $176K/yr
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Cyber Manager - ASM Vulnerability Management - Patching
San Francisco, CA · On-site
$130K - $176K/yr
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Principal, Security Engineering & Vulnerability Leadership
Burbank, CA · On-site
$177.17 - $329.03/hr
WarnerMedia Services, LLC is seeking a Principal in Security Engineering & Vulnerability Management to lead the implementation of security strategies across WB Games operations. This role involves ...
New
Principal, Security Engineering & Vulnerability Leadership
Burbank, CA · On-site
$177.17 - $329.03/hr
WarnerMedia Services, LLC is seeking a Principal in Security Engineering & Vulnerability Management to lead the implementation of security strategies across WB Games operations. This role involves ...
New
Staff Technical Program Manager, Security Programs
San Francisco, CA · On-site
$152K - $196K/yr
The ideal candidate has owned vulnerability management or adjacent security programs at scale and understands how to turn complex security risk into clear priorities, measurable outcomes, and ...
Staff Technical Program Manager, Security Programs
San Francisco, CA · On-site
$152K - $196K/yr
The ideal candidate has owned vulnerability management or adjacent security programs at scale and understands how to turn complex security risk into clear priorities, measurable outcomes, and ...
Vulnerability Management information
See California salary details
$5.18 - $12.26
0% of jobs
$12.26 - $19.35
0% of jobs
$19.35 - $26.43
0% of jobs
$26.43 - $33.51
0% of jobs
$33.51 - $40.59
15% of jobs
$40.59 - $47.68
9% of jobs
$47.99 is the 25th percentile. Wages below this are outliers.
$47.68 - $54.76
24% of jobs
The median wage is $56.78 / hr.
$54.76 - $61.84
7% of jobs
$61.84 - $68.93
8% of jobs
$71.15 is the 75th percentile. Wages above this are outliers.
$68.93 - $76.01
36% of jobs
$76.01 - $83.09
0% of jobs
$5
$60
$83
How much do vulnerability management jobs pay per hour?
What are the common challenges faced in a vulnerability management role?
Professionals in Vulnerability Management often encounter challenges such as rapidly evolving threat landscapes, prioritizing remediation efforts among numerous vulnerabilities, and ensuring continuous communication between technical and non-technical stakeholders. They may also need to adapt to changing regulatory requirements and work within tight deadlines to protect the organization from emerging risks. As part of this role, you'll collaborate regularly with IT, security, and business teams to ensure remediation steps are effectively implemented. Continuous learning and adaptability are important, as technologies and attack vectors change frequently in this field. Being proactive and detail-oriented will help you address these challenges and advance your career in cybersecurity.
What does a vulnerability management do?
What are the key skills and qualifications needed to thrive in a vulnerability management position?
To thrive in Vulnerability Management, you need a strong understanding of cybersecurity principles, network protocols, and risk assessment, typically supported by a relevant degree and experience in information security. Familiarity with vulnerability scanning tools (such as Nessus or Qualys), security frameworks, and industry certifications like CISSP or CompTIA Security+ is highly valued. Exceptional analytical thinking, communication skills, and an ability to work collaboratively across IT and business teams help professionals excel in this field. These competencies are crucial to effectively identifying, prioritizing, and mitigating security risks in dynamic organizational environments.
Is vulnerability management a good career?
What is vulnerability management?
A Vulnerability Management job involves identifying, assessing, prioritizing, and mitigating security vulnerabilities in an organization's systems, networks, and applications. Professionals in this role use tools like vulnerability scanners and threat intelligence to detect weaknesses and coordinate remediation efforts with IT and security teams. They also establish policies, monitor security risks, and ensure compliance with industry standards. The goal is to reduce the organization's exposure to cyber threats and improve overall security posture.

Full-time
Re-posted 14 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
Help organizations reduce cyber risk and improve resilience as part of Deloitte's Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team. In this role, you'll support clients in identifying, prioritizing, and remediating security exposures across complex technology environments. You'll work with cross-functional stakeholders to strengthen vulnerability management and patching processes, improve visibility into risk, and support cyber transformation initiatives.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Security Engineer II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...
- Supporting vulnerability remediation and patching activities aligned to CTEM priorities
- Executing vulnerability and patch management tasks across infrastructure, middleware, and applications
- Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize remediation activities
- Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk
- Preparing client-facing analyses, dashboards, and status updates to track remediation progress and exposure reduction
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, the CTEM team helps clients identify exposures, prioritize remediation, and reduce risk across complex technology environments.
Qualifications
Required:
- 3+ years of experience in information technology, information security, vulnerability management, patch management, or a combination of these
- Experience supporting vulnerability remediation, patch management, or continuous threat exposure management activities
- Experience remediating vulnerabilities across Linux, Windows, middleware, and applications
- Experience using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
- Experience using PowerShell, Bash, Python, Ansible, Terraform, or JavaScript Object Notation for automation, scripting, or configuration activities
- Experience using ServiceNow or another Information Technology Service Management platform to coordinate remediation activities and track status
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, or a related field
- Experience in a consulting environment
- Experience preparing remediation metrics, dashboards, or status reporting
- Experience with security or risk frameworks such as the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix
- Experience supporting automation or orchestration of remediation workflows
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberCDR27
Qualifications:Help organizations reduce cyber risk and improve resilience as part of Deloitte's Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team. In this role, you'll support clients in identifying, prioritizing, and remediating security exposures across complex technology environments. You'll work with cross-functional stakeholders to strengthen vulnerability management and patching processes, improve visibility into risk, and support cyber transformation initiatives.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Security Engineer II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...
- Supporting vulnerability remediation and patching activities aligned to CTEM priorities
- Executing vulnerability and patch management tasks across infrastructure, middleware, and applications
- Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize remediation activities
- Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk
- Preparing client-facing analyses, dashboards, and status updates to track remediation progress and exposure reduction
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, the CTEM team helps clients identify exposures, prioritize remediation, and reduce risk across complex technology environments.
Qualifications
Required:
- 3+ years of experience in information technology, information security, vulnerability management, patch management, or a combination of these
- Experience supporting vulnerability remediation, patch management, or continuous threat exposure management activities
- Experience remediating vulnerabilities across Linux, Windows, middleware, and applications
- Experience using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
- Experience using PowerShell, Bash, Python, Ansible, Terraform, or JavaScript Object Notation for automation, scripting, or configuration activities
- Experience using ServiceNow or another Information Technology Service Management platform to coordinate remediation activities and track status
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, or a related field
- Experience in a consulting environment
- Experience preparing remediation metrics, dashboards, or status reporting
- Experience with security or risk frameworks such as the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix
- Experience supporting automation or orchestration of remediation workflows
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberCDR27
Education:Bachelor's DegreeEmployment Type: