1

Vulnerability Remediation Engineer Jobs (NOW HIRING)

next page

Showing results 1-20

Vulnerability Remediation Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do vulnerability remediation engineer jobs pay per year?

As of Sep 10, 2026, the average yearly pay for vulnerability remediation engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What is a vulnerability remediation engineer?

A Vulnerability Remediation Engineer is a cybersecurity professional responsible for identifying, assessing, and addressing security vulnerabilities in an organization's systems and networks. They work closely with IT and security teams to prioritize vulnerabilities, develop remediation plans, and ensure that security patches and fixes are properly implemented. Their goal is to minimize security risks and protect the organization's data and infrastructure from cyber threats.

How does a vulnerability remediation engineer typically collaborate with other IT and security teams to address identified vulnerabilities?

Vulnerability Remediation Engineers work closely with various teams, including system administrators, application developers, and incident response staff, to ensure that identified vulnerabilities are properly prioritized and addressed. They facilitate communication between vulnerability assessment teams and the stakeholders responsible for patching or mitigating risks, often coordinating remediation timelines and providing technical guidance. This collaborative process helps ensure that remediation efforts are efficient and align with the organization's security policies and risk tolerance. Regular meetings, status updates, and clear documentation are common practices to maintain alignment and track progress.

What are the key skills and qualifications needed to thrive as a vulnerability remediation engineer, and why are they important?

To thrive as a Vulnerability Remediation Engineer, you need expertise in cybersecurity principles, vulnerability assessment, and risk management, typically backed by a degree in computer science or a related field. Familiarity with tools such as Nessus, Qualys, Rapid7, and ticketing systems like Jira, along with certifications like CISSP or CEH, is highly valuable. Strong analytical thinking, problem-solving abilities, and effective communication skills set candidates apart in this role. These skills are vital for identifying, prioritizing, and remediating security vulnerabilities to protect organizational assets and maintain compliance.

What is the difference between Vulnerability Remediation Engineer vs Vulnerability Analyst?

AspectVulnerability Remediation EngineerVulnerability Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, GIAC certifications
Work EnvironmentHands-on technical role focusing on fixing vulnerabilitiesAnalyzing and assessing vulnerabilities, reporting findings
Employer & Industry UsageIT security teams in various industries, focusing on remediationSecurity teams, risk management, and compliance departments

While both roles focus on cybersecurity vulnerabilities, the Vulnerability Remediation Engineer primarily implements fixes and patches to resolve security issues, whereas the Vulnerability Analyst identifies, assesses, and reports vulnerabilities. The engineer's role is more technical and hands-on, while the analyst's role emphasizes analysis and documentation.

What cities are hiring for Vulnerability Remediation Engineer jobs?

Cities with the most Vulnerability Remediation Engineer job openings:

What states have the most Vulnerability Remediation Engineer jobs?

States with the most job openings for Vulnerability Remediation Engineer jobs include:

What are popular job titles related to Vulnerability Remediation Engineer jobs?

For Vulnerability Remediation Engineer jobs, the most frequently searched job titles are:

Infographic showing various Vulnerability Remediation Engineer job openings in the United States as of June 2026, with employment types broken down into 96% Full Time, 1% Part Time, and 3% Contract. Highlights an 84% Physical, 6% Hybrid, and 10% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

Vulnerability Remediation Engineer

Raritan, NJ • Remote

Noblesoft Technologies
Software Development • 51 - 200 employees

Contractor

Re-posted 3 days ago


Job description

Job Title: Vulnerability Remediation Engineer

Location:  Raritan, NJ 08869 / REMOTE

Job Description:

  • Implement capabilities for a global Vulnerability Management program: internal/external exposure, imminent threats, prioritization, remediation facilitation.
  • Serve as technical SME for vulnerability tools and processes (Tenable, Qualys, Rapid7, or equivalent).
  • Continuously improve VM processes for coverage, efficiency, and visibility.
  • Leverage automation, analytics, and threat intelligence to improve accuracy and reduce remediation timelines.
  • Operate/optimize scanning platforms, discovery tooling, and reporting pipelines for asset visibility.
  • Partner with Infrastructure, Engineering, Application, and Cloud teams to reduce risk across environments.
  • Lead critical vulnerability identification and response exercises, including zero-day/imminent threats.
  • Develop and maintain metrics, dashboards, and executive-level reporting on posture, remediation progress, and program maturity.
  • Track and communicate remediation SLAs, risk reduction, and program improvements.

Qualifications and Skills:

  • Technical proficiency across network, system, and application layers; scanning, asset discovery, and exploit analysis
  • Hands-on experience with VM tools (e.g., Tenable.io, Qualys VMDR/WAS, Rapid7 InsightVM/AppSec) and discovery utilities (Nmap, SSLScan, Shodan, BitSight, Security Scorecard, custom scripts).
  • Knowledge in threat intel and data-driven prioritization (CVSS/CISA/EPSS).
  • Strong cloud understanding (AWS, Azure, GCP) and modern app stacks.
  • Scripting/automation (Python, PowerShell, Bash) and data analysis (SQL, Excel).
  • Scale-ready processes, metrics, dashboards, and analytics (Tableau, PowerBI).
  • Cross-functional collaboration; clear risk communication to technical and business stakeholders.
  • Knowledge of IT processes, secure baselines, and control frameworks (CIS, NIST, ISO, Microsoft, etc.).

Preferred:

  • Relevant certifications such as OSCP, GWAPT, CEH, or CSSLP.
  • Experience working in Agile and DevSecOps environments.
  • Knowledge of containerized applications and security tools (e.g., Docker, Kubernetes, etc.).
  • Understanding of regulatory compliance requirements (e.g., PCI DSS, GDPR, HIPAA).
  • Experience with penetration testing and exploit development.