Vulnerability Management / CTEM Specialist

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in GBR
Remote
Senior level
Artificial Intelligence • Machine Learning • Analytics
The Role
Lead implementation of a Continuous Threat Exposure Management platform, migrating from legacy vulnerability tools. Design risk-scoring, SLA, exception, escalation, integration, reconciliation, reporting, and operating-model processes. Validate scanner data, build ServiceNow and API integrations, automate analysis with Python, create dashboards and KPIs, and document configurations, workflows, runbooks, and policies for technical and executive stakeholders.
Summary Generated by Built In
Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Vulnerability Management / CTEM Specialist to join an embedded security team supporting a large commercial enterprise's transition to a modern Continuous Threat Exposure Management (CTEM) program. This role will lead the implementation of a new CTEM platform, replacing a legacy vulnerability management tool, and will design the surrounding operational processes — from exploitability-based risk scoring and SLA frameworks to exception handling and escalation procedures. The ideal candidate brings 5+ years of experience in vulnerability management or CTEM platform delivery, hands-on integration work with ITSM tools, and the ability to translate technical processes into clear documentation for both technical and executive audiences.

This is a contract position involving a large commercial enterprise in the Financial Services industry. Candidates with previous consulting or contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

Responsibilities:

  • Lead the implementation of a CTEM platform, migrating from a legacy vulnerability management tool
  • Design and configure connectors, scoring/exploitability models, and consolidation logic across scanners and source systems
  • Validate data ingestion fidelity across vulnerability scanners and source systems
  • Design SLA and exploitability/risk-scoring frameworks
  • Build exception and risk-acceptance workflows
  • Perform asset/vulnerability de-duplication and inventory reconciliation
  • Stand up critical/high-priority vulnerability escalation processes
  • Build and validate API-based integrations between the CTEM platform and downstream systems (e.g., ServiceNow)
  • Write Python scripts/automation for data tagging, gap analysis, and reporting
  • Build role-based dashboards and reporting for analysts, remediation owners, and CISO-level stakeholders
  • Develop KPI/metrics frameworks for security operations
  • Author platform configuration documentation, runbooks, and policy/SLA documentation
  • Support business process mapping and current-state/future-state workflow design
  • Develop Target Operating Model (TOM) documentation
Requirements

Must-Have:

  • Experience with Risk-Based Vulnerability Management (RBVM) / CTEM tools and platforms (e.g., Kenna, Zafran, Rapid7, Tenable, Qualys)
  • Experience with vulnerability management platforms: connectors, scoring/exploitability models, consolidation logic, ticketing integration
  • Experience validating data ingestion fidelity across scanners and source systems
  • Experience designing SLA and exploitability/risk-scoring frameworks
  • Experience with exception and risk-acceptance process design
  • Experience with asset/vulnerability de-duplication and asset inventory reconciliation
  • Experience standing up critical/high-priority vulnerability escalation processes
  • 5+ years of relevant vulnerability management / cybersecurity consulting experience
  • U.S. Citizenship or Permanent Residency; ability to work within the continental U.S.

Preferred / Nice-to-Have:

  • API-based system integration and validation testing experience
  • Scripting/automation experience (e.g., Python) for data tagging, gap analysis, reporting automation
  • Experience with IT Service Management (ITSM) platforms (e.g., ServiceNow) — workflow design and ticket lifecycle automation
  • Experience building role-based dashboards/reporting for technical and executive audiences
  • Experience developing KPI/metrics frameworks for security operations
  • Technical writing experience (platform configuration documentation, runbooks, policy/SLA documentation)
  • Business process mapping and current-state/future-state workflow design
  • Experience developing Target Operating Model (TOM) documentation
Skill(s)

Technical Skills:

  • RBVM/CTEM platforms (Zafran, Kenna, Rapid7, Tenable, Qualys)
  • Vulnerability scanner integration and API-based connectors
  • Exploitability/risk-scoring models
  • ITSM platforms (ServiceNow)
  • Python scripting/automation
  • Dashboarding and reporting tools

Soft Skills:

  • Cross-functional stakeholder communication (analysts through executives)
  • Technical writing and documentation
  • Process design and facilitation
  • Ability to work independently within an embedded client team
Benefits
  • Medical — Multiple POS health plan options including an HSA-compatible plan
  • Dental — PPO coverage for preventive, basic, and major services
  • Vision — Annual exam, frames, lenses, and contact lens allowance
  • 401(k) — Employer match up to 5% of eligible compensation
  • Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each
  • PTO — 15–25 days annually based on tenure
  • Paid Federal Holidays — All 11 federal holidays observed

Skills Required

  • Experience with Risk-Based Vulnerability Management or Continuous Threat Exposure Management tools and platforms, such as Kenna, Zafran, Rapid7, Tenable, or Qualys
  • Experience with vulnerability management platform connectors, scoring and exploitability models, consolidation logic, and ticketing integration
  • Experience validating data ingestion fidelity across vulnerability scanners and source systems
  • Experience designing SLA and exploitability or risk-scoring frameworks
  • Experience designing exception and risk-acceptance processes
  • Experience with asset and vulnerability de-duplication and asset inventory reconciliation
  • Experience standing up critical and high-priority vulnerability escalation processes
  • At least 5 years of relevant vulnerability management or cybersecurity consulting experience
  • U.S. Citizenship or Permanent Residency
  • Ability to perform all work within the continental United States
  • API-based system integration and validation testing experience
  • Python scripting or automation experience for data tagging, gap analysis, or reporting automation
  • Experience with IT Service Management platforms such as ServiceNow, including workflow design and ticket lifecycle automation
  • Experience building role-based dashboards and reporting for technical and executive audiences
  • Experience developing KPI and metrics frameworks for security operations
  • Technical writing experience involving configuration documentation, runbooks, or policy and SLA documentation
  • Experience with business process mapping and current-state or future-state workflow design
  • Experience developing Target Operating Model documentation
  • Cross-functional stakeholder communication from analysts through executives
  • Ability to work independently within an embedded client team
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
35 Employees
Year Founded: 2018

What We Do

Dragonfly AI uses a biologically driven AI to predict attention on visual assets. Across all channels and environments, the platform can be integrated with workflows to validate decision-making with data for creative that has a higher impact and performs better. Particularly relevant for CPG and FMCG brands but can be integrated with any creative process for a new layer of data insights to support teams in optimizing creative specifically for attention

Similar Jobs

NBCUniversal Logo NBCUniversal

Director, Business & Legal Affairs, Carnival

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
London, Greater London, England, GBR

Rubrik Logo Rubrik

Senior Talent Partner EMEA

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
In-Office or Remote
London, Greater London, England, GBR
3000 Employees

Samsara Logo Samsara

Senior Software Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
UK
4000 Employees
Remote or Hybrid
2 Locations
289097 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account