Rose International ยท 18 hours ago
Vulnerability Management Engineer
Rose International is a staffing organization in the government sector, seeking a Vulnerability Management Engineer. The role involves assessing, managing, and reducing security vulnerabilities across enterprise environments, including performing vulnerability scans, recommending remediation plans, and ensuring compliance with security standards.
Human ResourcesInformation TechnologyOutsourcingProject ManagementStaffing Agency
Responsibilities
Perform recurring vulnerability scans for servers and workstations
Analyze scan results to identify actionable risks, false positives, and exposures
Prioritize vulnerabilities using CVSS, KEV, CISA frameworks
Coordinate with application owners for patching and remediation scheduling
Partner with server and desktop teams for patching cycles
Provide technical guidance on workarounds, hotfixes, and configuration issues
Validate remediation success post-deployment
Refine patch and configuration baselines
Develop dashboards tracking remediation progress, aging vulnerabilities, SLA/KPI compliance, and platform trends
Report critical vulnerabilities and escalating risks to leadership
Operate and tune vulnerability scanning and endpoint management tools (Qualys, Defender, Intune, SCCM, Azure Update Manager, etc.)
Recommend configuration improvements and automation optimizations
Integrate scan results into workflow tools (ServiceNow, Jira)
Ensure adherence to security policies, CIS benchmarks, NIST guidance
Improve patching and vulnerability management SOPs, runbooks, and governance processes
Support audit and compliance reporting requirements
Qualification
Required
Experience in vulnerability management, patch management, or endpoint/server security operations (3-7 Years)
Technical proficiency with Windows Server and Windows desktop platforms
Experience with patch deployment and configuration management
Experience operating one or more security scanning platforms (e.g., Qualys, Microsoft Defender, Azure Update Manager, PatchMyPC)
Ability to analyze scan output, identify false positives, and provide remediation guidance
Strong understanding of CVEs, CVSS scoring, exploitability assessments, and common ransomware/threat vectors
Preferred
Experience in mixed operating system environments (Windows and Linux)
Familiarity with Microsoft Intune, SCCM, Azure Update Manager, Azure Arc, ServiceNow
Knowledge of CIS or NIST standards
Ability to create automation scripts (PowerShell, Bash, Python, or similar)
Experience working in enterprise or government environments
Company
Rose International
Rose International is provider of Workforce Solutions and Information Technology Solutions .
Funding
Current Stage
Late StageRecent News
Company data provided by crunchbase