- Company Name
- DMG Delta
- Job Title
- Vulnerability Engineer
- Job Description
-
Job Title: Vulnerability Engineer
Role Summary:
Lead and expand a scalable vulnerability management (VM) function across hybrid on‑prem and cloud environments. Build automated scanning, triage, and remediation pipelines; embed VM into CI/CD and development workflows; sustain policy compliance with ISO 27001, NIST, and CIS standards. Drive continuous improvement through automation, metrics, and stakeholder collaboration.
Expectations:
- Demonstrated experience managing VM in mixed infrastructure.
- Proven ability to design, implement, and scale automated VM processes.
- Strong ownership, initiative, and proactive problem‑solving.
- Ability to communicate complex security topics to technical and non‑technical audiences.
Key Responsibilities:
1. Develop, deploy, and maintain an automated VM program using Tenable and complementary tools.
2. Establish and enforce vulnerability policies, scan configurations, and best practices aligned to ISO 27001, NIST, and CIS.
3. Integrate vulnerability scanning and remediation into CI/CD pipelines and dev workflows.
4. Automate data collection, triage, reporting, and ticketing via Python, Bash, PowerShell, or Go.
5. Collaborate with IT, DevOps, and engineering teams to remediate vulnerabilities swiftly.
6. Scope, coordinate, and track penetration testing activities and risk acceptance.
7. Monitor, report, and analyze VM performance metrics (KPIs, SLAs, risk scores).
8. Document and evolve VM processes, policies, and escalation procedures.
9. Lead remediation meetings and present findings to the security steering committee.
10. Stay current on emerging threats, vulnerabilities, and mitigation tools; evolve VM strategy accordingly.
11. Provide guidance and training on secure development and remediation practices.
Required Skills:
- Hands‑on Tenable expertise and VM tool integration into CI/CD.
- Proficiency in scripting languages: Python, Bash, PowerShell, or Go.
- Experience with APIs and automation workflows (Jira, ServiceNow, Slack).
- Ability to scope and manage penetration test findings.
- Deep understanding of ISO 27001, NIST, and CIS frameworks.
- Strong communication, presentation, and stakeholder‑influencing skills.
- Analytical, solution‑oriented mindset and independent improvement drive.
Required Education & Certifications:
- Education: Not specified.
- Certifications: Not specified.