1

Vulnerability Management Jobs in Seattle, WA (NOW HIRING)

next page

Showing results 1-20

Vulnerability Management information

See Seattle, WA salary details

$5

$66

$91

How much do vulnerability management jobs pay per hour?

As of Aug 10, 2026, the average hourly pay for vulnerability management in Seattle, WA is $66.46, according to ZipRecruiter salary data. Most workers in this role earn between $54.90 and $78.83 per hour, depending on experience, location, and employer.

What are the common challenges faced in a vulnerability management role?

Professionals in Vulnerability Management often encounter challenges such as rapidly evolving threat landscapes, prioritizing remediation efforts among numerous vulnerabilities, and ensuring continuous communication between technical and non-technical stakeholders. They may also need to adapt to changing regulatory requirements and work within tight deadlines to protect the organization from emerging risks. As part of this role, you'll collaborate regularly with IT, security, and business teams to ensure remediation steps are effectively implemented. Continuous learning and adaptability are important, as technologies and attack vectors change frequently in this field. Being proactive and detail-oriented will help you address these challenges and advance your career in cybersecurity.

What does a vulnerability management do?

A vulnerability management professional is responsible for identifying, assessing, and prioritizing security vulnerabilities in an organization's systems and networks. They use tools like vulnerability scanners and follow best practices to mitigate risks, often working closely with security teams and maintaining documentation for compliance. This role requires technical knowledge of cybersecurity principles and may involve certifications such as CISSP or CompTIA Security+.

What are the key skills and qualifications needed to thrive in a vulnerability management position?

To thrive in Vulnerability Management, you need a strong understanding of cybersecurity principles, network protocols, and risk assessment, typically supported by a relevant degree and experience in information security. Familiarity with vulnerability scanning tools (such as Nessus or Qualys), security frameworks, and industry certifications like CISSP or CompTIA Security+ is highly valued. Exceptional analytical thinking, communication skills, and an ability to work collaboratively across IT and business teams help professionals excel in this field. These competencies are crucial to effectively identifying, prioritizing, and mitigating security risks in dynamic organizational environments.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires knowledge of security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers strong job growth and demand for skilled professionals.

What is vulnerability management?

A Vulnerability Management job involves identifying, assessing, prioritizing, and mitigating security vulnerabilities in an organization's systems, networks, and applications. Professionals in this role use tools like vulnerability scanners and threat intelligence to detect weaknesses and coordinate remediation efforts with IT and security teams. They also establish policies, monitor security risks, and ensure compliance with industry standards. The goal is to reduce the organization's exposure to cyber threats and improve overall security posture.

What are the most commonly searched types of Vulnerability Management jobs in Seattle, WA? The most popular types of Vulnerability Management jobs in Seattle, WA are:
What are popular job titles related to Vulnerability Management jobs in Seattle, WA? For Vulnerability Management jobs in Seattle, WA, the most frequently searched job titles are:
What cities near Seattle, WA are hiring for Vulnerability Management jobs? Cities near Seattle, WA with the most Vulnerability Management job openings:
Infographic showing various Vulnerability Management job openings in Seattle, WA as of August 2026, with employment types broken down into 81% Full Time, and 19% Contract. Highlights an 81% In-person, 5% Hybrid, and 14% Remote job distribution, with an average salary of $138,243 per year, or $66.5 per hour.

Staff Vulnerability Management Engineer

SoFi

Seattle, WA • On-site

Full-time

Posted 10 days ago


Job description

The role


We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi's Vulnerability Management program. You will design and build scalable systems that identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud and infrastructure, containers, software supply chains, and specialized hardware or firmware surfaces. This is a hands-on engineering role with broad technical influence: you will write production code, make architecture decisions, establish vulnerability management standards, and improve how teams understand and reduce vulnerability risk.


You will partner with Engineering, Infrastructure, SRE, Compliance, Legal, and business stakeholders to accelerate remediation while protecting engineering velocity and customer trust. You will also serve as a senior technical responder for embargoed disclosures and zero-day events, lead root-cause analysis for high-impact vulnerability incidents, and mentor engineers. The ideal candidate combines deep vulnerability management expertise with strong software engineering judgment, systems thinking, and a bias for durable, measurable outcomes.


What you'll do

  •  Lead high-complexity vulnerability management initiatives and make architecture decisions for assigned program areas, from detection and assessment through ticket routing, remediation, exception handling, and closure validation.
  • Design, build, and productionize scalable triage and prioritization automation, including scanner and asset integrations, enrichment pipelines, decision logic, deduplication, ownership resolution, service-level tracking, observability, and failure recovery.
  • Develop risk-based prioritization models that combine CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations.
  • Engineer and improve vulnerability workflows across application security, cloud and infrastructure, containers and Kubernetes, open-source dependencies, secrets, software supply chain, and hardware-adjacent surfaces such as GPU, DPU/BlueField, BMC, and firmware.
  • Own or materially advance software supply chain capabilities, including SBOM inventory, dependency visibility, SLSA-aligned controls, and integration of SAST, SCA, secret scanning, and container scanning into CI/CD.
  • Act as a senior technical responder for critical vulnerabilities, embargoed disclosures, and zero-day events; coordinate technical assessment, containment, mitigation, patch deployment, validation, and executive communication with service owners and incident response teams.
  • Partner directly with development and platform teams to define practical remediation paths and, when appropriate, review or contribute secure changes in Python, Go, JavaScript/TypeScript, or infrastructure code.
  • Define technical standards for vulnerability severity, remediation service levels, exceptions, evidence, and closure criteria; ensure workflows support audit-ready reporting for applicable regulatory and compliance frameworks.
  • Produce actionable metrics, dashboards, and risk insights for technical and executive audiences, with clear accountability, trend analysis, compliance posture, and execution risks.
  • Lead root-cause analysis for high-impact vulnerability incidents and convert lessons learned into durable improvements to tooling, architecture, controls, and operating practices.
  • Evaluate and responsibly apply AI/ML and LLM-assisted techniques to security triage and decision support, with human-in-the-loop validation, measurable quality controls, and safe failure modes.
  • Build AI-assisted remediation workflows that partner with engineering teams to proactively identify, validate, and apply security patches, with appropriate testing, human oversight, rollback mechanisms, and measurable risk reduction.
  • Communicate complex security tradeoffs and program risks clearly to stakeholders across Engineering, Product, Operations, Legal, Compliance, and executive leadership.


What you'll need

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
  • Deep expertise in vulnerability management, security engineering, and modern infrastructure, including cloud, containers, and distributed systems.
  • Strong programming or scripting skills in Python, Go, Java, or similar languages, with experience building automation at scale.
  • Deep knowledge of vulnerability management methods and standards, including CVSS, EPSS, CISA KEV, threat intelligence integration, asset and exposure context, remediation SLAs, exception governance, and risk-based prioritization.
  • Hands-on experience with modern vulnerability and application security tooling such as Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, Checkmarx, or equivalent platforms, plus experience tuning SAST, SCA, secret scanning, container, or cloud findings.
  • Experience designing end-to-end workflows that integrate scanners, asset inventories or CMDBs, ticketing systems, CI/CD platforms, data stores, dashboards, and alerting systems.
  • Working knowledge of cloud-native and software supply chain environments, including AWS, GCP, or Azure; Kubernetes and containers; build systems and package managers; SBOMs; and Infrastructure as Code.
  • Demonstrated ability to lead cross-functional technical initiatives, influence without direct authority, make sound decisions amid ambiguity, and drive work from concept through production operation and measurable outcomes.
  • Experience mentoring senior and developing engineers and raising engineering quality through design reviews, code reviews, standards, and incident leadership.
  • Strong written and verbal communication, business judgment, and the ability to explain how security choices affect engineering velocity, regulatory obligations, customer trust, and business risk.


Nice to have

  • Experience managing security partnerships with hardware or software vendors, including embargoed disclosures, coordinated vulnerability disclosure, and pre-release remediation collaboration.
  • Production experience with security orchestration platforms such as Tines and serverless frameworks such as AWS Lambda or Google Cloud Functions.
  • Experience scaling vulnerability management in a high-growth, cloud-native environment or operating within FedRAMP, PCI DSS, SOC 2, ISO 27001, NIST, or comparable regulated environments.