1

Vulnerability Management Jobs in Michigan (NOW HIRING)

Roush is looking for a Cyber Security Architect to design, implement, and manage enterprise security controls across Microsoft 365, EDR tools, Vulnerability Management, and Data Loss Prevention (DLP ...

Roush is looking for a Cyber Security Architect to design, implement, and manage enterprise security controls across Microsoft 365, EDR tools, Vulnerability Management, and Data Loss Prevention (DLP ...

As part of our cybersecurity practice, you'll help clients strengthen their cyber resilience across areas such as threat detection, security monitoring, vulnerability management, incident response ...

New

Contribute to security monitoring, vulnerability management, incident response, identity and access management, and threat detection activities. * Analyze security events, operational data, and cyber ...

New

W2 only, no Subs allowed. 5+ years of experience implementing and supporting enterprise security tools (SIEM, CRIBL, XDR, Vulnerability Management, DLP, Endpoint Security) 5+ years of experience in ...

W2 only, no Subs allowed. 5+ years of experience implementing and supporting enterprise security tools (SIEM, CRIBL, XDR, Vulnerability Management, DLP, Endpoint Security) 5+ years of experience in ...

Showing results 21-40

Vulnerability Management information

See Michigan salary details

$4

$53

$74

How much do vulnerability management jobs pay per hour?

As of Aug 17, 2026, the average hourly pay for vulnerability management in Michigan is $53.93, according to ZipRecruiter salary data. Most workers in this role earn between $44.54 and $63.96 per hour, depending on experience, location, and employer.

What is vulnerability management?

A Vulnerability Management job involves identifying, assessing, prioritizing, and mitigating security vulnerabilities in an organization's systems, networks, and applications. Professionals in this role use tools like vulnerability scanners and threat intelligence to detect weaknesses and coordinate remediation efforts with IT and security teams. They also establish policies, monitor security risks, and ensure compliance with industry standards. The goal is to reduce the organization's exposure to cyber threats and improve overall security posture.

What are the common challenges faced in a vulnerability management role?

Professionals in Vulnerability Management often encounter challenges such as rapidly evolving threat landscapes, prioritizing remediation efforts among numerous vulnerabilities, and ensuring continuous communication between technical and non-technical stakeholders. They may also need to adapt to changing regulatory requirements and work within tight deadlines to protect the organization from emerging risks. As part of this role, you'll collaborate regularly with IT, security, and business teams to ensure remediation steps are effectively implemented. Continuous learning and adaptability are important, as technologies and attack vectors change frequently in this field. Being proactive and detail-oriented will help you address these challenges and advance your career in cybersecurity.

What are the key skills and qualifications needed to thrive in a vulnerability management position?

To thrive in Vulnerability Management, you need a strong understanding of cybersecurity principles, network protocols, and risk assessment, typically supported by a relevant degree and experience in information security. Familiarity with vulnerability scanning tools (such as Nessus or Qualys), security frameworks, and industry certifications like CISSP or CompTIA Security+ is highly valued. Exceptional analytical thinking, communication skills, and an ability to work collaboratively across IT and business teams help professionals excel in this field. These competencies are crucial to effectively identifying, prioritizing, and mitigating security risks in dynamic organizational environments.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires knowledge of security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers strong job growth and competitive salaries. It is suitable for individuals interested in technical problem-solving and continuous learning in cybersecurity.

What does a vulnerability management do?

A vulnerability management professional is responsible for identifying, assessing, and prioritizing security vulnerabilities in an organization’s systems and networks. They use tools like vulnerability scanners and follow best practices to mitigate risks, often working closely with security teams and maintaining documentation for compliance. This role requires technical knowledge of cybersecurity principles and may involve certifications such as CISSP or CompTIA Security+.

What are the most commonly searched types of Vulnerability Management jobs in Michigan?

The most popular types of Vulnerability Management jobs in Michigan are:

What cities in Michigan are hiring for Vulnerability Management jobs?

Cities in Michigan with the most Vulnerability Management job openings:

Infographic showing various Vulnerability Management job openings in Michigan as of August 2026, with employment types broken down into 77% Full Time, and 23% Contract. Highlights an 96% In-person, and 4% Remote job distribution, with an average salary of $112,168 per year, or $53.9 per hour.

Cyber Manager - ASM Patching Engineer

Deloitte

Detroit, MI

Full-time

Re-posted 22 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 92 frontline employees who took The Breakroom Quiz

44th of 150 rated financial services


Job description

Help clients reduce cyber risk by leading forward deployed engineering work focused on patching, remediation, and continuous exposure reduction. As part of Deloitte's Cyber Defense & Resilience team, you'll work closely with client stakeholders to drive patch governance, remediation execution, and operational improvement across enterprise environments. In this role, you'll lead teams, manage delivery, and help clients translate vulnerability data into sustained risk-reduction outcomes.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As an Engineering Manager II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...

  • Leading forward deployed engineering workstreams that support large-scale patching and vulnerability remediation across client environments
  • Directing remediation prioritization using vulnerability findings, exploitability, asset criticality, attack path data, and threat intelligence
  • Overseeing patch execution governance, exception management, reporting, and validation across infrastructure, middleware, endpoints, and applications
  • Driving automation and process improvements that increase remediation speed, consistency, and visibility
  • Managing client relationships, delivery quality, team mentoring, and day-to-day coordination across technical and business stakeholders

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, forward deployed engineers and managers work side by side with client teams to strengthen patching operations, improve remediation governance, and reduce exposure across complex enterprise ecosystems.

Qualifications

Required:

  • 10+ years of experience in information technology, information security, vulnerability management, patch management, or a combination of these
  • 7+ years of experience leading client-facing patching, remediation, vulnerability management, or forward deployed engineering workstreams in enterprise environments
  • 7+ years of experience overseeing or remediation across Windows, Linux, middleware, endpoints, or applications using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
  • 3+ years of experience using PowerShell, Bash, Python, Ansible, Terraform, or JavaScript Object Notation to support automation, orchestration, or operational improvement
  • 3+ years of experience using ServiceNow or another Information Technology Service Management platform to manage remediation governance, reporting, exceptions, and status tracking
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, Mathematics, or Physics
  • Experience in a consulting environment
  • Experience leading teams that support patch execution, remediation operations, or exposure management programs
  • Experience presenting remediation strategy, delivery status, or exposure reduction metrics to leadership stakeholders
  • Experience with the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $155,600 to $306,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.


#CyberCDR27

Qualifications:

Help clients reduce cyber risk by leading forward deployed engineering work focused on patching, remediation, and continuous exposure reduction. As part of Deloitte's Cyber Defense & Resilience team, you'll work closely with client stakeholders to drive patch governance, remediation execution, and operational improvement across enterprise environments. In this role, you'll lead teams, manage delivery, and help clients translate vulnerability data into sustained risk-reduction outcomes.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As an Engineering Manager II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...

  • Leading forward deployed engineering workstreams that support large-scale patching and vulnerability remediation across client environments
  • Directing remediation prioritization using vulnerability findings, exploitability, asset criticality, attack path data, and threat intelligence
  • Overseeing patch execution governance, exception management, reporting, and validation across infrastructure, middleware, endpoints, and applications
  • Driving automation and process improvements that increase remediation speed, consistency, and visibility
  • Managing client relationships, delivery quality, team mentoring, and day-to-day coordination across technical and business stakeholders

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, forward deployed engineers and managers work side by side with client teams to strengthen patching operations, improve remediation governance, and reduce exposure across complex enterprise ecosystems.

Qualifications

Required:

  • 10+ years of experience in information technology, information security, vulnerability management, patch management, or a combination of these
  • 7+ years of experience leading client-facing patching, remediation, vulnerability management, or forward deployed engineering workstreams in enterprise environments
  • 7+ years of experience overseeing or remediation across Windows, Linux, middleware, endpoints, or applications using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
  • 3+ years of experience using PowerShell, Bash, Python, Ansible, Terraform, or JavaScript Object Notation to support automation, orchestration, or operational improvement
  • 3+ years of experience using ServiceNow or another Information Technology Service Management platform to manage remediation governance, reporting, exceptions, and status tracking
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, Mathematics, or Physics
  • Experience in a consulting environment
  • Experience leading teams that support patch execution, remediation operations, or exposure management programs
  • Experience presenting remediation strategy, delivery status, or exposure reduction metrics to leadership stakeholders
  • Experience with the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $155,600 to $306,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.


#CyberCDR27

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom