Vulnerability Management Engineer
Fanatics
This job is no longer accepting applications
See open jobs at Fanatics.See open jobs similar to "Vulnerability Management Engineer" Insight Partners.Vulnerability Assessment & Management
Manage vulnerability programs for IT assets, containers (e.g., Docker, Kubernetes), and base golden images across operating systems (Windows, Linux, Unix).
Conduct regular scans using industry-standard tools.
Analyze and prioritize vulnerabilities based on risk, exploitability, and asset criticality.
Track and report remediation progress.
Security Operations
Collaborate with IT, DevOps, and development teams for timely remediation.
Develop policies and remediation plans, including golden image review processes.
Support incident response for vulnerability exploits.
Assess risks and recommend mitigation strategies.
Reporting & Communication
Create executive dashboards on vulnerability and golden image security status.
Communicate findings to technical teams and leadership.
Maintain accurate vulnerability, asset, and golden image inventories.
Change Management
Continuous Improvement
Stay updated on emerging threats, vulnerabilities, and golden image security best practices.
Recommend tools for vulnerability, container, and golden image security management.
Support penetration testing, audits, and security training.
Required Qualifications
Technical Skills
2+ years in vulnerability management, cybersecurity or related experience.
Deep, hands-on expertise with leading vulnerability scanning platforms (Tenable, Qualys, etc.)
Assessment of golden image reviews for Windows, Linux, Unix and Containers.
Familiarity with network protocols, operating systems, and cloud platforms (AWS, Azure, GCP).
Experience with patch and configuration management tools (e.g., Tanium, Intune, SSM, JAMF).
Expert understanding of the vulnerability lifecycle, risk assessment, and advanced prioritization techniques (CVSS, EPSS, CWE, CISA KEV).
Understanding of frameworks like NIST, OWASP.
Familiarity with compliance standards (e.g., PCI DSS, SOX).
Knowledge of threat modeling and penetration testing. Familiar with scripting languages.
General skills:
Strong critical thinking and analytical skills
Ability to approach problem solving in a constructive and collaborative way that does not require absolute security.
- The ability to communicate complicated technical issues and risks to programmers, network engineers and managers.
- Strong project and team-building skills
- Exceptional communication skills with diverse audiences; the ability to be an application security subject matter expert who can explain relevant topics to general audiences.
EDUCATIONAL REQUIREMENTS:
Bachelor’s degree in computer science, Information Systems, or equivalent combination of education and experience
Certifications in the field of Information Security (at least one of the following: CEH, GIAC CPEN, OSCP, OSWE, CWAPT, GWAPT, GWEB)
EXPERIENCE REQUIRED:
A minimum of 2 years of experience.
Fanatics is searching for an experienced application security specialist to help protect Fanatics-developed applications which are used externally and internally. A successful candidate will display strong communication and technical skills and be comfortable and effective working independently and as part of a larger, highly distributed team. We are seeking a skilled Security Engineer to join our cybersecurity team, focusing on identifying, assessing, and mitigating vulnerabilities across enterprise systems, including containerized environments. The ideal candidate has expertise in vulnerability assessment tools and security frameworks.
This job is no longer accepting applications
See open jobs at Fanatics.See open jobs similar to "Vulnerability Management Engineer" Insight Partners.