1

Vulnerability Manager Jobs in Seattle, WA (NOW HIRING)

The role We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi's Vulnerability Management program. You will design and build scalable systems that ...

Senior Vulnerability Management Engineer

Seattle, WA ยท On-site

$130K - $178K/yr

About the role As a Senior Vulnerability Management Engineer you will independently identify, assess, prioritize, and drive the remediation of vulnerabilities across applications, infrastructure ...

Vulnerability Management Engineer

Seattle, WA ยท On-site +1

$140 - $155/hr

This position supports advancing the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate. Detect: - Maintain and expand scan and sensor ...

Senior Vulnerability Management Engineer

Seattle, WA ยท On-site

$118K - $163K/yr

About the role As a Senior Vulnerability Management Engineer you will independently identify, assess, prioritize, and drive the remediation of vulnerabilities across applications, infrastructure ...

The role We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi's Vulnerability Management program. You will design and build scalable systems that ...

next page

Showing results 1-20

Vulnerability Manager information

See Seattle, WA salary details

$10

$25

$61

How much do vulnerability manager jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for vulnerability manager in Seattle, WA is $25.01, according to ZipRecruiter salary data. Most workers in this role earn between $19.76 and $24.18 per hour, depending on experience, location, and employer.

What does a vulnerability manager do?

A Vulnerability Manager is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's systems, networks, and applications. They oversee vulnerability scanning, analyze the results, prioritize risks, and work with various teams to implement remediation strategies. Their goal is to reduce the organization's exposure to cyber threats by ensuring that security weaknesses are addressed promptly and effectively.

What are the key skills and qualifications needed to thrive as a vulnerability manager, and why are they important?

To thrive as a Vulnerability Manager, you need expertise in risk assessment, vulnerability scanning, and cybersecurity fundamentals, typically supported by a degree in information security or a related field. Familiarity with tools like Nessus, Qualys, and vulnerability management platforms, as well as certifications such as CISSP or CEH, is often required. Strong analytical skills, attention to detail, and clear communication are crucial soft skills for effectively identifying issues and coordinating remediation efforts. These abilities ensure that organizations can proactively manage security risks and maintain robust defense against cyber threats.

What are some common challenges faced by vulnerability managers when prioritizing remediation efforts?

Vulnerability Managers often encounter challenges in balancing limited resources with a high volume of identified vulnerabilities. Prioritizing remediation efforts requires close collaboration with IT, development, and business teams to assess the potential impact and exploitability of each vulnerability. Additionally, they must stay updated on emerging threats, ensure compliance with industry standards, and communicate risk effectively to both technical and non-technical stakeholders. Navigating these complexities is essential for maintaining a strong security posture while minimizing disruption to business operations.

What is the difference between Vulnerability Manager vs Security Analyst?

AspectVulnerability ManagerSecurity Analyst
CertificationsCertified Vulnerability Assessor (CVA), CISSP, CEHCISSP, Security+, CEH
Work EnvironmentOversees vulnerability assessments, manages teams, develops strategiesMonitors security systems, analyzes threats, responds to incidents
Employer & Industry UsageUsed in cybersecurity teams across industries to manage vulnerabilitiesCommonly employed in security operations centers (SOCs) to analyze threats

While both roles focus on cybersecurity, Vulnerability Managers primarily oversee vulnerability assessments and strategy, whereas Security Analysts focus on monitoring and incident response. Both roles require relevant certifications and work within cybersecurity teams, but their daily responsibilities and focus areas differ.

What cities near Seattle, WA are hiring for Vulnerability Manager jobs?

Cities near Seattle, WA with the most Vulnerability Manager job openings:

Infographic showing various Vulnerability Manager job openings in Seattle, WA as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 83% Physical, 2% Hybrid, and 15% Remote job distribution, with an average salary of $52,026 per year, or $25 per hour.

VULNERABILITY MANAGEMENT ENGINEER

Seattle, WA โ€ข On-site

Widenet Consulting
Marketingย โ€ขย 1 - 10 employees

$140 - $155/hr

Full-time, Contractor

Medical, Retirement

This job post hasย expired 3 days ago.ย Applications are no longer accepted.


Job description

Job Description:
Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.

Job Description:
This position supports advancing the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate.

Detect:
– Maintain and expand scan and sensor coverage across endpoints, servers, cloud workloads, containers, network devices, and SaaS
– Close asset visibility gaps, including shadow IT, unmanaged devices, and assets provisioned outside IT
– Tune authenticated scanning, credential health, agent health, and scan cadence to reduce false negatives
– Reconcile vulnerability data across multiple sources into a single authoritative inventory

Prioritize:
– Build and operate risk-based prioritization that blends CVSS severity, EPSS likelihood, CISA KEV exploitation status, and SSVC decision logic
– Enrich findings with business context: asset criticality, data classification, internet exposure, compensating controls, application owner, and business unit
– Replace severity-only queues with defensible, tiered remediation SLAs
– Operate the exception and risk acceptance workflow, including expiration and re-review

Report:
– Design and publish program metrics: coverage, mean time to remediate by tier, backlog aging, SLA compliance, and burndown
– Deliver executive and operational dashboards, including Power BI reporting fed by automated pipelines
– Produce audit and assurance evidence on request
– Translate technical findings into business risk language for non-technical stakeholders

Remediate:
– Drive remediation campaigns in partnership with IT operations, endpoint, cloud, and application teams
– Automate ticket creation, routing, and closure into the ITSM platform
– Perform closed-loop verification that remediation actually reduced exposure
– Support emergency response for actively exploited vulnerabilities

Platform and program:
– Direct, hands-on experience implementing or migrating to a new enterprise vulnerability management platform, including requirements definition, proof of concept, integration, data migration, and rollout
– Direct experience driving continuous improvement to an established VM program, including maturity assessment, process redesign, and runbook development

Required Qualifications
– 5+ years hands-on vulnerability management or security engineering
– Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium)
– Demonstrated experience building prioritization models that incorporate business context, not severity alone
– Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration
– Working fluency with KQL or an equivalent query language for security data
– Experience integrating VM data with CMDB, ITSM, and BI platforms
– Cloud vulnerability management experience across Azure and at least one other provider
– Ability to work independently and produce written deliverables without heavy oversight

Preferred
– Experience with Tanium and Microsoft Defender for Endpoint as data sources
– Container and image scanning experience
– Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns
– Exposure to CTEM or exposure management program models
– Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500

Pay Range: $75.00 – $85.00 per hour, depending upon experience.
Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.

SLA
Describe hiring preference (C/CTH/FTE)
12 month contract
Bill rate or FTE Salary range and target:
Target rate: We need to make our best offer, so let’s discuss rates, keeping in mind they can go a bit higher than for our other clients.
Potential target: $140 to $155/hr
Work Authorization Requirements:
No C2C without approval
1099 ok

Budget Confirmed?
Yes
Why is the position open?
New role
How long has the position been open?
Just opened
Is there HR/vendor competition? Exclusive?
Competition – this is an RFP process
Interview Process:

  • 2 interviews – likely team fit/leadership + technical

Work location:

  • Local and onsite 2-3 days a week is ideal and will be prioritized over remote
  • Open to remote but must be in PST. This is not preferred.

Team size
Enterprise wide

Project overview:

Advance the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate.
Top 5:

  1. 5+ years hands-on vulnerability management or security engineering
  2. Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium)
  3. Demonstrated experience building prioritization models that incorporate business context, not severity alone
  4. Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration
  5. Working fluency with KQL or an equivalent query language for security data
  6. Experience integrating VM data with CMDB, ITSM, and BI platforms
  7. Cloud vulnerability management experience across Azure and at least one other provider

Nice to Have:

  • Experience with Tanium and Microsoft Defender for Endpoint as data sources
  • Container and image scanning experience
  • Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns
  • Exposure to CTEM or exposure management program models
  • Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500

Job Description:
Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.

Job Description:
This position supports advancing the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate.

Detect:
– Maintain and expand scan and sensor coverage across endpoints, servers, cloud workloads, containers, network devices, and SaaS
– Close asset visibility gaps, including shadow IT, unmanaged devices, and assets provisioned outside IT
– Tune authenticated scanning, credential health, agent health, and scan cadence to reduce false negatives
– Reconcile vulnerability data across multiple sources into a single authoritative inventory

Prioritize:
– Build and operate risk-based prioritization that blends CVSS severity, EPSS likelihood, CISA KEV exploitation status, and SSVC decision logic
– Enrich findings with business context: asset criticality, data classification, internet exposure, compensating controls, application owner, and business unit
– Replace severity-only queues with defensible, tiered remediation SLAs
– Operate the exception and risk acceptance workflow, including expiration and re-review

Report:
– Design and publish program metrics: coverage, mean time to remediate by tier, backlog aging, SLA compliance, and burndown
– Deliver executive and operational dashboards, including Power BI reporting fed by automated pipelines
– Produce audit and assurance evidence on request
– Translate technical findings into business risk language for non-technical stakeholders

Remediate:
– Drive remediation campaigns in partnership with IT operations, endpoint, cloud, and application teams
– Automate ticket creation, routing, and closure into the ITSM platform
– Perform closed-loop verification that remediation actually reduced exposure
– Support emergency response for actively exploited vulnerabilities

Platform and program:
– Direct, hands-on experience implementing or migrating to a new enterprise vulnerability management platform, including requirements definition, proof of concept, integration, data migration, and rollout
– Direct experience driving continuous improvement to an established VM program, including maturity assessment, process redesign, and runbook development

Required Qualifications
– 5+ years hands-on vulnerability management or security engineering
– Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium)
– Demonstrated experience building prioritization models that incorporate business context, not severity alone
– Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration
– Working fluency with KQL or an equivalent query language for security data
– Experience integrating VM data with CMDB, ITSM, and BI platforms
– Cloud vulnerability management experience across Azure and at least one other provider
– Ability to work independently and produce written deliverables without heavy oversight

Preferred
– Experience with Tanium and Microsoft Defender for Endpoint as data sources
– Container and image scanning experience
– Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns
– Exposure to CTEM or exposure management program models
– Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500

Pay Range: $75.00 – $85.00 per hour, depending upon experience.
Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.