Security Engineer (Vulnerability Management)
Job Reference: 161884
Industry: Information and Communications Technology
Overview
We are seeking an exceptional Security Engineer to support and enhance our organization's vulnerability management program. This is a highly technical, operations-focused, hands-on role within a dynamic and fast-paced environment.
You will work across a broad range of applications and platforms, including traditional infrastructure, containers, and cloud environments, to identify and manage security vulnerabilities, coordinate remediation efforts, collaborate with stakeholders, and continuously improve processes through automation and AI-assisted tooling.
Key Qualifications
Core Security & Vulnerability Management
- Self-starter with the flexibility to work remotely and support global teams.
- Ability to manage and drive multiple initiatives simultaneously.
- Passionate about protecting customer and business data.
- Good understanding of vulnerability scanning tools such as Tenable, Qualys, or similar platforms.
- Familiarity with common security vulnerabilities and the ability to assess their severity and business impact.
- Ability to analyze vulnerabilities and provide practical remediation guidance.
- Experience independently coordinating and driving vulnerability remediation efforts.
- Passion for automation and continuous process improvement.
- Ability to perform proof-of-concept validation for known vulnerabilities.
- Solid understanding of IPv4 and IPv6 networking.
- Good analytical thinking and problem-solving skills.
- Experience working with SQL and Linux environments.
- Familiarity with penetration testing methodologies.
- Understanding of the broader security research landscape.
- Good verbal and written communication skills.
Technical Skills
- Proficiency in one or more programming or scripting languages such as Python, Go, Rust, and/or Bash.
- Hands-on experience with container technologies including Docker and Kubernetes.
- Knowledge of container image and registry vulnerability scanning tools such as Prisma Cloud, Trivy, or equivalent solutions.
- Working knowledge of major cloud platforms such as AWS, GCP, and/or Azure.
- Understanding of cloud security principles, including Identity and Access Management (IAM), Network Security, Workload Security, and Cloud Security Posture Management.
- Experience or exposure to DevSecOps practices, including security controls within CI/CD pipelines, Infrastructure as Code (IaC) security reviews such as Terraform, and shift-left security and remediation methodologies.
AI & Automation
- Awareness of emerging trends in AI-driven security operations.
- Hands-on experience with LLM-based tools is highly desirable.
- Familiarity with the Model Context Protocol (MCP) and experience building or integrating MCP servers/tools.
- Experience designing or developing AI agents and agentic workflows for vulnerability triage, security data enrichment, and remediation tracking is a plus.
Responsibilities
As part of the security engineering team, you will help identify, assess, and respond to emerging security vulnerabilities and threats while continuously improving the organization's security posture.
Key responsibilities include:
- Partner with cross-functional teams to identify and assess vulnerabilities across on-premises, containerized, and cloud environments.
- Drive vulnerabilities through the complete remediation lifecycle, ensuring timely resolution and effective stakeholder communication.
- Utilize programming and scripting skills to analyze large-scale security, system, and application data sets for impact assessment and decision-making.
- Design, evaluate, and implement automation solutions to improve vulnerability management processes.
- Explore and apply AI-driven approaches, including MCP-based tooling and AI agent workflows, to automate vulnerability triage, enrichment, and remediation tracking.
- Stay current on emerging threats, vulnerabilities, and industry best practices in cybersecurity.
Education & Experience
- Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field.
- Minimum 3 years of experience in Information Security or a related technical security discipline.
- Experience with container security, cloud security, and DevSecOps practices is a plus.
- Exposure to AI agents, MCP tooling, or AI-assisted security operations is a plus.
