Summary
We are looking for an experienced, Staff Vulnerability Management Engineer who can navigate complex threat scenarios and remain committed to decreasing the overall attack surface of the company. Enterprise Vulnerability Management remains a top priority at Guidewire, and you will be responsible for implementing and managing enterprise vulnerability tools and processes in a cloud environment, to reduce technical risks due to vulnerabilities and misconfigurations. This includes identifying and evaluating vulnerabilities and supporting remediation activities by actively collaborating with stakeholders.Job Description
Develop and execute a strategic vision for Vulnerability Management (VM) that ensures the right balance of safety and agility.
Partner with development teams to design and implement security controls in vulnerability detection, prevention, and remediation.
Brief and engage with engineering leaders in operational reviews and written updates.
Drive continuous improvement in the vulnerability management process.
Review all applicable threats, discover vulnerabilities/cloud misconfigurations and collaborate with remediation treatment owners to prioritize, provide context and remediate identified vulnerabilities.
Ensure knowledge creation around vulnerability management process, common vulnerabilities within the landscape and corresponding remediation practices.
Research the latest security best practices and technologies, staying on top of new threats and vulnerabilities to create threat briefs and provide timely assessment reports to key stakeholders.
Supporting compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks.
Actively use Guidewire tools, automation, and responsible AI capabilities to increase your productivity and improve the quality and consistency of project outcomes.
Requirements
Prior experience with managing and configuring any vulnerability management tool and risk based vulnerability such as Rapid 7, Tenable, Qualys, Brinqa, etc
Ability to automate solutions to repetitive problems/tasks using scripting languages such as Perl, Python, PowerShell or Bash.
Hands on experience handling vulnerability management operations for cloud workloads at scale in AWS/Azure
Mentor and provide technical guidance to the team on strategies for vulnerability analysis and remediation.
Persuasive mindset with strong relationship management skills to work with various stakeholders proactively on vulnerability assessment and remediation
Exceptional written communication skills to create clear, accurate documentation (process records, instructional guides) and effectively tailor communication for technical teams, business stakeholders, and engineering leadership.
Thorough understanding of enterprise security controls, network protocols and operating system (Windows/Linux environments)
An execution-focused mindset, capable of navigating through ambiguity and delivering results.
Demonstrated ability to embrace AI and data-driven insights to drive innovation, productivity, and continuous improvement in your current role.
Good to have:
Certifications from SANS, Offensive Security, ISC2, AWS is a plus.
About Guidewire
Guidewire is the platform P&C insurers trust to engage, innovate, and grow efficiently. We combine digital, core, analytics, and AI to deliver our platform as a cloud service. More than 540+ insurers in 40 countries, from new ventures to the largest and most complex in the world, run on Guidewire.
As a partner to our customers, we continually evolve to enable their success. We are proud of our unparalleled implementation track record with 1600+ successful projects, supported by the largest R&D team and partner ecosystem in the industry. Our Marketplace provides hundreds of applications that accelerate integration, localization, and innovation.
For more information, please visit www.guidewire.com and follow us on Twitter: @Guidewire_PandC.
Guidewire Software, Inc. is proud to be an equal opportunity and affirmative action employer. We are committed to an inclusive workplace, and believe that a diversity of perspectives, abilities, and cultures is a key to our success. Qualified applicants will receive consideration without regard to race, color, ancestry, religion, sex, national origin, citizenship, marital status, age, sexual orientation, gender identity, gender expression, veteran status, or disability. All offers are contingent upon passing a criminal history and other background checks where it's applicable to the position.
Skills Required
- Experience managing and configuring vulnerability management tools (e.g., Rapid7, Tenable, Qualys, Brinqa)
- Ability to automate repetitive tasks using scripting languages (Perl, Python, PowerShell, Bash)
- Hands-on experience handling vulnerability management operations for cloud workloads at scale in AWS or Azure
- Mentor and provide technical guidance on vulnerability analysis and remediation strategies
- Strong relationship management and persuasive stakeholder engagement skills
- Exceptional written communication skills for documentation and executive-level updates
- Thorough understanding of enterprise security controls, network protocols, and Windows/Linux operating systems
- Execution-focused mindset capable of delivering results in ambiguous situations
- Demonstrated ability to embrace AI and data-driven insights to improve vulnerability management
- Certifications from SANS, Offensive Security, ISC2, or AWS
Guidewire Software Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Guidewire Software and has not been reviewed or approved by Guidewire Software.
-
Flexible Benefits — Flexible work options and distinctive global mobility programs enable remote/hybrid arrangements and short-term or longer-term cross-border work opportunities. Feedback suggests these options are a meaningful differentiator for those valuing location flexibility.
-
Leave & Time Off Breadth — Unlimited PTO in the U.S., dedicated volunteer time, and a personal 'My Day' accompany generous parental leave. These elements indicate a broad time-off offering that supports rest, community engagement, and family needs.
-
Equity Value & Accessibility — Equity grants (RSUs) and an employee stock purchase plan are positioned as significant parts of total compensation. Stock-based components can enhance overall pay, with value influenced by market conditions.
Guidewire Software Insights
What We Do
Guidewire is the platform P&C insurers trust to engage, innovate, and grow efficiently. We combine digital, core, analytics, and AI to deliver our platform as a cloud service. More than 540 insurers, from new ventures to the largest and most complex in the world, run on Guidewire. As a partner to our customers, we continually evolve to enable their success. We are proud of our unparalleled implementation track record, with 1,000+ successful projects, supported by the largest R&D team and partner ecosystem in the industry. Our marketplace provides hundreds of applications that accelerate integration, localization, and innovation.
Why Work With Us
We're focused on each and every employees' personal and professional development, and offer internal career mobility programs and growth opportunities that make Guidewire unique. Other perks like generous PTO, flexible working, our Guidewire Gives Back charitabeland our "Work From Almost Anywhere" program support our employees' work-life balance
Gallery
.png)






