Vulnerability Management Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Rose International ยท 18 hours ago

Vulnerability Management Engineer

Rose International is a staffing organization in the government sector, seeking a Vulnerability Management Engineer. The role involves assessing, managing, and reducing security vulnerabilities across enterprise environments, including performing vulnerability scans, recommending remediation plans, and ensuring compliance with security standards.

Human ResourcesInformation TechnologyOutsourcingProject ManagementStaffing Agency
check
Growth Opportunities
badNo H1Bnote

Responsibilities

Perform recurring vulnerability scans for servers and workstations
Analyze scan results to identify actionable risks, false positives, and exposures
Prioritize vulnerabilities using CVSS, KEV, CISA frameworks
Coordinate with application owners for patching and remediation scheduling
Partner with server and desktop teams for patching cycles
Provide technical guidance on workarounds, hotfixes, and configuration issues
Validate remediation success post-deployment
Refine patch and configuration baselines
Develop dashboards tracking remediation progress, aging vulnerabilities, SLA/KPI compliance, and platform trends
Report critical vulnerabilities and escalating risks to leadership
Operate and tune vulnerability scanning and endpoint management tools (Qualys, Defender, Intune, SCCM, Azure Update Manager, etc.)
Recommend configuration improvements and automation optimizations
Integrate scan results into workflow tools (ServiceNow, Jira)
Ensure adherence to security policies, CIS benchmarks, NIST guidance
Improve patching and vulnerability management SOPs, runbooks, and governance processes
Support audit and compliance reporting requirements

Qualification

CISSCCMVulnerability ManagementWindows Server 2016Windows 10Microsoft IntuneAzure Update ManagerServiceNowNIST standardsPowerShellBashPythonLinuxTechnical GuidanceAutomation Scripts

Required

Experience in vulnerability management, patch management, or endpoint/server security operations (3-7 Years)
Technical proficiency with Windows Server and Windows desktop platforms
Experience with patch deployment and configuration management
Experience operating one or more security scanning platforms (e.g., Qualys, Microsoft Defender, Azure Update Manager, PatchMyPC)
Ability to analyze scan output, identify false positives, and provide remediation guidance
Strong understanding of CVEs, CVSS scoring, exploitability assessments, and common ransomware/threat vectors

Preferred

Experience in mixed operating system environments (Windows and Linux)
Familiarity with Microsoft Intune, SCCM, Azure Update Manager, Azure Arc, ServiceNow
Knowledge of CIS or NIST standards
Ability to create automation scripts (PowerShell, Bash, Python, or similar)
Experience working in enterprise or government environments

Company

Rose International

company-logo
Rose International is provider of Workforce Solutions and Information Technology Solutions .

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Eric Token
Chief Revenue Officer (CRO)
linkedin
leader-logo
Sue Bhatia
Founder and Chairwoman
linkedin
Company data provided by crunchbase