Vulnerability Management Engineer (VM Engineer)
Remote
Location: Remote
Position Overview
Our client is seeking a Vulnerability Management Engineer to support their Cybersecurity Vulnerability Management team. This individual will play a key role in driving the organization’s vulnerability and exposure management program by integrating security tooling, managing vulnerability workflows, and partnering with remediation teams to reduce organizational risk.
This is a highly technical engineering role with regular interaction across infrastructure, application, and security teams. The ideal candidate is someone who can quickly learn new technologies, adapt to a fast-paced environment, and confidently communicate technical remediation guidance to stakeholders.
The ideal candidate is:
- Highly technical with a strong engineering mindset.
- Comfortable learning new platforms and technologies quickly.
- Adaptable in a rapidly changing environment.
- Proactive and capable of taking ownership without constant direction.
- Able to communicate confidently with technical audiences while maintaining credibility.
- Comfortable facilitating meetings with remediation owners and driving accountability across teams.
Primary Responsibilities
- Support and enhance the organization’s Vulnerability Management (VM) and Vulnerability Exposure Management (VEM) program.
- Configure, maintain, and improve ServiceNow Vulnerability Response (VR) integrations and workflows.
- Integrate vulnerability data from CrowdStrike Falcon Exposure Management into ServiceNow.
- Correlate vulnerability findings with CMDB assets and ensure accurate asset mapping.
- Assign vulnerabilities to the appropriate remediation owners and support groups.
- Work directly with infrastructure, application, and asset owners to drive timely remediation.
- Provide technical guidance and actionable remediation recommendations.
- Assist with ongoing implementation and optimization of new vulnerability management tooling.
- Participate in projects related to vulnerability automation and workflow improvements.
- Present vulnerability findings and remediation priorities to technical stakeholders and cross-functional teams.
Required Qualifications
- Strong experience in Vulnerability Management or Cybersecurity Engineering.
- Hands-on experience with ServiceNow Vulnerability Response (VR).
- Experience integrating vulnerability data into ServiceNow workflows.
Understanding of:
- Vulnerability lifecycle management
- Vulnerability prioritization
- Remediation processes
- Asset management and CMDB relationships
- Ability to communicate technical vulnerability information to engineering and infrastructure teams.
- Strong troubleshooting and analytical skills.
- Ability to thrive in an evolving, project-driven environment.
Preferred Qualifications
- Experience with CrowdStrike Falcon Exposure Management.
- Experience with Attack Surface Management (ASM) platforms.
- Experience with Palo Alto Expanse.
- Experience supporting enterprise vulnerability management programs.
- Exposure to security automation and vulnerability orchestration.
Nice to Have
- Experience working with CMDB governance.
- Familiarity with enterprise cybersecurity operations.
- Experience working across multiple infrastructure teams and business units.
- Strong organizational and project management skills.
Key Technologies
- ServiceNow Vulnerability Response (Required)
- CrowdStrike Falcon Exposure Management (Preferred)
- Palo Alto Expanse (Not required but this is what they are using)
- CMDB
- Vulnerability Management
- Vulnerability Exposure Management
- Attack Surface Management
- Cybersecurity Engineering