Vulnerability Management Engineer

Posted 2 Days Ago
Be an Early Applicant
Bangalore, Bengaluru, Karnataka
Senior level
Hardware • Internet of Things • Logistics • Software
The Role
The Vulnerability Management Security Engineer manages vulnerability identification and remediation across the organization. Responsibilities include deploying assessment tools, analyzing vulnerabilities, coordinating with teams for remediation, generating reports, and ensuring compliance with standards like NIST and PCI-DSS. The role also involves continuous improvement through automation and collaboration with threat intelligence teams.
Summary Generated by Built In

Job Summary:

The Vulnerability Management Security Engineer is responsible to assist the Security Operations team in the comprehensive execution and management of vulnerability identification, assessment, and remediation processes across the organization. This role includes deploying and operating vulnerability assessment tools, refining scan results, providing technical assistance in coordinating with internal teams for remediation, and providing actionable insights to enhance the organization's security posture. The individual in this role must have a solid understanding of information security, risk assessment methodologies, and remediation best practices to address vulnerabilities effectively. The engineer will work closely with IT, development, and compliance teams to ensure that risks are managed within acceptable thresholds and regulatory requirements.


Principal Responsibilities:

  • Vulnerability Scanning and Assessment: Deploy and maintain vulnerability scanning tools to identify weaknesses across the organization's IT infrastructure, including servers, endpoints, networks, and applications. Conduct scheduled and ad-hoc vulnerability scans, ensuring comprehensive coverage and accuracy of scanning results. Assist in analyzing scan data to identify trends, patterns, and high-risk vulnerabilities, prioritizing issues based on potential impact and exploitability.
  • Remediation Coordination and Tracking: Work closely with IT and Security operations, application development, and other internal teams to track and support remediation efforts for identified vulnerabilities. Develop and document remediation plans and timelines based on vulnerability criticality and business impact. Facilitate the communication of remediation guidance and oversee the execution of risk mitigation actions.
  • Reporting and Documentation: Prepare detailed vulnerability assessment reports, including metrics on scan results, remediation status, and risk mitigation progress. Develop executive-level dashboards and summaries to provide a high-level overview of vulnerability management activities. Maintain documentation of processes, procedures, and vulnerability management playbooks, ensuring consistency and repeatability.
  • Continuous Improvement and Automation: Identify opportunities to improve the efficiency and effectiveness of the vulnerability management toolset, including process automation. Develop and implement scripts, automation workflows, and tools to enhance vulnerability scanning, reporting, and remediation tracking. Collaborate with other security teams to integrate vulnerability data with security incident response and threat intelligence workflows.
  • Compliance and Security Standards Adherence: Ensure vulnerability management activities align with industry standards, such as NIST, ISO 27001, and regulatory requirements like PCI-DSS and SOX. Maintain up-to-date knowledge of compliance requirements and emerging vulnerability management frameworks, incorporating relevant changes into existing processes.
  • Threat Intelligence Integration: Work with threat intelligence teams to contextualize vulnerabilities within the broader threat landscape. Adjust scanning priorities and remediation efforts based on emerging threats, zero-day vulnerabilities, and relevant exploit activity in the industry.
  • Other Duties as Assigned

Distinguishing Characteristics:

  • Technical Expertise in Vulnerability Management: The engineer should have deep expertise in vulnerability management tools and technologies, such as Qualys, Tenable, Rapid7, or similar platforms, and be skilled in configuring, tuning, and optimizing these tools.
  • Experience in Network Engineering: Demonstrated proficiency in managing and troubleshooting layer 2 and layer 3 devices.
  • Proficiency in Scripting Languages: Experience with scripting languages such as Python for automating tasks, developing custom scripts, and enhancing system administration workflows, with an ability to write, debug, and optimize code for various operational needs.
  • Analytical and Problem-Solving Skills: This role demands a strong ability to analyze scan data, understand complex infrastructure dependencies, and devise actionable and efficient remediation plans.
  • Communication and Coordination Abilities: This position requires excellent interpersonal skills to communicate vulnerability issues clearly to non-technical stakeholders and to coordinate remediation efforts across diverse teams.
  • Risk-Based Approach to Security: A successful engineer will apply a risk-based approach to vulnerability prioritization and mitigation, focusing resources on the most impactful issues, and balancing security needs with business goals.
  • Industry certifications such as CISSP, CASP, or GIAC are a plus.
  • Relevant vendor specific certifications are a plus.

Work Experience:

  • Typically, 5+ years with bachelor's or equivalent.

Education and Certification(s):

  • Bachelor's degree or equivalent experience from which comparable knowledge and job skills can be obtained.

The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities, duties, and skills.

Top Skills

Python
The Company
HQ: Phoenix, AZ
11,000 Employees
On-site Workplace

What We Do

Avnet is a global electronic components distributor with extensive design, product, marketing and supply chain expertise for customers and suppliers at every stage of the product lifecycle. For the past 100 years, Avnet has helped its customers and suppliers around the world realize the transformative possibilities of technology.

Our culture was founded on new ideas and emerging technology. Headquartered in Phoenix, Arizona, Avnet is a leading global technology distributor and solutions provider at the center of the technology value chain. Founded in 1921, we work with suppliers in every major technology segment to serve customers worldwide across a broad range of markets. Whether working on large-scale production or early prototypes, we meet customer needs through individualized, end-to-end service to streamline solutions and improve efficiency for customers worldwide. Headquartered in Phoenix, Arizona, we serve more than 1 million customers in more than 140 countries and partner with global suppliers from almost every technology segment.

Similar Jobs

BlackLine Logo BlackLine

Senior Software Engineer - SAP ABAP

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Hybrid
Bengaluru, Karnataka, IND
1810 Employees
Hybrid
Bengaluru, Karnataka, IND
289097 Employees

Spotnana Logo Spotnana

Staff Software Engineer, Frontend

Big Data • Cloud • Information Technology • Software • Travel
Easy Apply
Bengaluru, Karnataka, IND
356 Employees

Spotnana Logo Spotnana

Staff Software Engineer, Backend

Big Data • Cloud • Information Technology • Software • Travel
Easy Apply
Bengaluru, Karnataka, IND
356 Employees

Similar Companies Hiring

Jobba Trade Technologies, Inc. Thumbnail
Software • Professional Services • Productivity • Information Technology • Cloud
Chicago, IL
45 Employees
RunPod Thumbnail
Software • Infrastructure as a Service (IaaS) • Cloud • Artificial Intelligence
Charlotte, North Carolina
53 Employees
Hedra Thumbnail
Software • News + Entertainment • Marketing Tech • Generative AI • Enterprise Web • Digital Media • Consumer Web
San Francisco, CA
14 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account