Talent.com
Senior Security Engineer - Vulnerability Management
Senior Security Engineer - Vulnerability ManagementCARFAX • Columbia, MO, United States
[error_messages.no_longer_accepting]
Senior Security Engineer - Vulnerability Management

Senior Security Engineer - Vulnerability Management

CARFAX • Columbia, MO, United States
[job_card.variable_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Description

Join Team CARFAX as a Senior Security Engineer - Vulnerability Management

Isn't it time you bragged about where you work? At CARFAX, we do, every day. We pride ourselves on being mission-focused on helping to grow a brand built on accuracy and integrity. We care deeply about our products and our customers. We're more than just a company : We help millions of consumers make more informed decisions every day. We know that our teammates are our most valuable asset, and we value a balanced life while tackling challenging projects in a fast-paced environment.

We are seeking a highly skilled and motivated Senior Cyber Security Engineer - Vulnerability Management plays a vital role in safeguarding the organization's information assets by designing, implementing, and maintaining robust security measures. This role involves identifying and mitigating security vulnerabilities, responding to security incidents, and ensuring compliance with security policies and standards. The Senior Cyber Security Engineer - Vulnerability Management collaborates with various IT and business teams to integrate security best practices into every aspect of the organization's operations.

At CARFAX, we believe in the power of teamwork and value in-person interactions so that we can collaborate and thrive together. This position will require 3 days per week in our Columbia, MO office subject to change with future business needs.

What you'll be doing :

  • Oversee the end-to-end vulnerability management lifecycle, including scanning, assessment, prioritization, remediation tracking, and reporting.
  • Perform regular vulnerability scans across infrastructure, endpoints, and applications, ensuring accurate detection, proper asset coverage, and alignment with security and compliance requirements.
  • Perform risk-based analysis and triage vulnerability findings based on business impact, asset criticality, threat intelligence, and exploitability. Guide stakeholders on remediation priorities.
  • Collaborate with system owners to drive timely remediation. Develop actionable plans for patching or mitigating vulnerabilities.
  • Ensure system hardening and configuration compliance using industry benchmarks such as CIS and DISA STIGs.
  • Deploy, manage, and optimize vulnerability and compliance scanning tools. Automate scanning, reporting, and alerting to improve coverage and reduce manual effort.
  • Incorporate threat intelligence and exploit data to contextualize vulnerabilities and adjust risk ratings accordingly.
  • Develop clear, concise reports and dashboards that communicate vulnerability status, trends, KPIs, and risk posture to technical and non-technical stakeholders.
  • Continuously evaluate and improve vulnerability management processes, scanning schedules, and remediation workflows to align with evolving threats and organizational needs.
  • Ensure vulnerability management activities align with compliance requirements (e.g., PCI-DSS, SOC II, ISO 27001) and support audit documentation and responses.
  • Act as a liaison between security, infrastructure, application, and business teams. Serve as a subject matter expert on vulnerability-related issues.
  • Provide guidance to junior team members and support knowledge sharing within the cybersecurity team.

What we're looking for :

  • Bachelor's degree in computer science, Information Security, or a related field.
  • Minimum of 5+ years of experience in cybersecurity, with at least 3-4 years focused on vulnerability management.
  • Industry certifications such as CISSP, CEH, CompTIA Security+, or relevant vulnerability management credentials.
  • Strong experience with vulnerability scanning tools (e.g., Qualys, Tenable Nessus, Rapid7 InsightVM).
  • Solid understanding of vulnerability classification standards (e.g., CVSS, CWE, CAPEC) and security frameworks.
  • Familiarity with patch management, system hardening, and configuration management tools and processes.
  • Working knowledge of Linux, Windows, and macOS environments, including OS-level security controls.
  • Understanding of networking protocols, firewalls, and network security best practices.
  • Experience with compliance frameworks such as PCI-DSS, SOC II, or ISO 27001.
  • Strong analytical and problem-solving skills, with the ability to assess complex environments and identify potential exposures.
  • Excellent communication skills, with the ability to convey technical risk to both technical and non-technical stakeholders.
  • Ability to manage multiple projects and tasks in a dynamic, fast-paced environment.
  • What's in it for you :

  • Competitive compensation, benefits and generous time-off policies
  • 4-Day summer work weeks and a winter holiday break
  • 401(k) / DCPP matching
  • Annual bonus program
  • Casual, dog-friendly, and innovative office spaces
  • For a comprehensive list of benefits, please visit our website :
  • Don't just take our word for it :

  • 10X Virginia Business Best Places to Work
  • 10X Washingtonian Great Places to Work
  • 9X Washington Post Top Workplace
  • St.Louis Post-Dispatch Best Places to Work
  • About CARFAX and S&P Global Mobility

    S&P Global has recently announced the intent to separate our Mobility Segment into a standalone public company.

    CARFAX, part of S&P Global Mobility, helps millions of people every day confidently shop, buy, service and sell used cars with innovative solutions powered by CARFAX vehicle history information. The expert in vehicle history since 1984, CARFAX provides exclusive services like CARFAX Used Car Listings, CARFAX Car Care, CARFAX History-Based Value and the flagship CARFAX® Vehicle History Report™ to consumers and the automotive industry. CARFAX owns the world's largest vehicle history database and is nationally recognized as a top workplace by The Washington Post and Glassdoor.com. Shop, Buy, Service, Sell - Show me the CARFAX™. S&P Global Mobility is a division of S&P Global (NYSE : SPGI). S&P Global is the world's foremost provider of credit ratings, benchmarks, analytics and workflow solutions in the global capital, commodity and automotive markets.

    US Equal Opportunity Employer Statement : CARFAX is an Affirmative Action / Equal Opportunity Employer. It is the policy of CARFAX to provide equal employment opportunity to all persons regardless of race, color, sex, pregnancy, religion, national origin, age, ancestry, citizenship status, veteran status, military status, disability or handicap, sexual orientation, genetic information or any other status protected by federal, state or local law. In addition, CARFAX will provide reasonable accommodations for qualified individuals with disabilities. We maintain a drug-free workplace. We are a participant in E-Verify.

    Canadian Equal Opportunity Employer Statement : CARFAX Canada is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to race / ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law.

    We're committed to providing accommodations by request for candidates taking part in all aspects of the recruitment and selection process. For a confidential inquiry or to request an accommodation, please contact your recruiter or email [email protected].

    [job_alerts.create_a_job]

    Security Engineer • Columbia, MO, United States

    [internal_linking.related_jobs]
    Security Researcher

    Security Researcher

    Sonatype • Columbia, Missouri, United States, 65201
    [job_card.full_time]
    Sonatype is the software supply chain security company.We provide the worlds best end-to-end software supply chain security solution, combining the only proactive protection against malicious open ...[show_more]
    [last_updated.last_updated_variable_days]
    Managed Services Security Analyst

    Managed Services Security Analyst

    GFI Digital • Columbia Township, MO, United States
    [job_card.full_time]
    The Managed Service Security Analyst is responsible for monitoring, detecting, and responding to security incidents to protect client environments. This role involves the identification of vulnerabi...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Engineer - New Product Development

    Senior Engineer - New Product Development

    Watlow • Columbia, MO, United States
    [job_card.full_time]
    Watlow is a global technology and manufacturing leader who provides world class engineering expertise through innovative thermal products and systems, enabling our customers to thrive.We are making...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Purchasing Manager

    Senior Purchasing Manager

    Hitachi • Jefferson City, Missouri, USA
    [job_card.full_time]
    Jefferson City Missouri United States of America.Customer Service & Contact Center Operations.Step into a leadership role where your expertise drives operational excellence.As a Senior Purchasi...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Director, Corporate Compliance, Risk Management (Remote)

    Senior Director, Corporate Compliance, Risk Management (Remote)

    Remote Staffing • Jefferson City, MO, US
    [filters.remote]
    [job_card.full_time]
    Senior Corporate Compliance Director, Risk Management.We are the first publicly-traded biotech or pharmaceutical company to take the form of a public benefit corporation. Our public benefit purpose ...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Compliance Examiner

    Compliance Examiner

    Missouri Secretary of State • Jefferson City, MO, US
    [job_card.full_time]
    As a Compliance Examiner, you will help safeguard Missouri investors and promote fairness and integrity in our financial markets. Your work ensures that investment advisers and broker-dealers operat...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Technology Risk Analyst

    Senior Technology Risk Analyst

    Coinbase • Jefferson City, MO, United States
    [job_card.full_time]
    Are you ready to explore your full potential? At Coinbase, we are driven by our mission to foster economic freedom around the globe. This is an exciting opportunity that requires dedication as we wo...[show_more]
    [last_updated.last_updated_variable_hours] • [promoted] • [new]
    Manufacturing Engineer Co-Op

    Manufacturing Engineer Co-Op

    Watlow • Columbia, MO, United States
    [job_card.full_time]
    Watlow is a global technology and manufacturing leader who provides world class engineering expertise through innovative thermal products and systems, enabling our customers to thrive.We are making...[show_more]
    [last_updated.last_updated_30] • [promoted]
    IT Risk & Control Senior Analyst

    IT Risk & Control Senior Analyst

    City National Bank • Jefferson City, MO, United States
    [job_card.full_time]
    IT RISK & CONTROL SENIOR ANALYST.The IT Risk Senior Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cybe...[show_more]
    [last_updated.last_updated_1_day] • [promoted]
    Senior Analyst, Technology Risk

    Senior Analyst, Technology Risk

    Coinbase • Jefferson City, MO, United States
    [job_card.full_time]
    Ready to be pushed beyond what you think you’re capable of?.At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, ...[show_more]
    [last_updated.last_updated_1_day] • [promoted]
    Senior Fire and Security Technician

    Senior Fire and Security Technician

    Tech Electronics • Columbia, MO, USA
    [job_card.full_time]
    [filters_job_card.quick_apply]
    We provide systems and services that help our customers work smarter, feel safer, and collaborate more effectively.Tech Electronics is a technology services organization headquartered in St.Louis, ...[show_more]
    [last_updated.last_updated_30]
    Bomb Technician

    Bomb Technician

    U.S. Navy • Moberly, MO, United States
    [job_card.full_time]
    ABOUT Explosive Ordnance Disposal (EOD) Technicians have expertise in the most conventional and unconventional explosives to ensure the secure disposal of explosive weaponry.They are on call to res...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Virtualization Lead Engineer

    Virtualization Lead Engineer

    JPS Tech Solutions LLC • Jefferson City, Missouri, USA
    [job_card.full_time]
    Job Title : Virtualization Lead Engineer.We are looking for an experienced Virtualization Lead Engineer to oversee design and manage enterprise virtualization platforms and infrastructure services.T...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Network Infrastructure Engineer

    Network Infrastructure Engineer

    Two95 International Inc. • Columbia, MO, US
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Job Title : Network Infrastructure Engineer.A minimum of five years of experience working in networking as an engineer or administrator. Must have hands-on experience with Cisco route...[show_more]
    [last_updated.last_updated_30]
    Explosive Ordnance Disposal Technician

    Explosive Ordnance Disposal Technician

    U.S. Navy • Ashland, MO, United States
    [job_card.full_time]
    ABOUT Explosive Ordnance Disposal (EOD) Technicians have expertise in the most conventional and unconventional explosives to ensure the secure disposal of explosive weaponry.They are on call to res...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Satellite Tech for Starlink Installation Pros

    Satellite Tech for Starlink Installation Pros

    WebProps.org • Columbia, MO, US
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Are you a tech-savvy problem solver with a passion for excellent customer service? We want YOU! 🌟.Nationwide - Work anywhere in the USA. Install satellite internet systems at customer locations.Mou...[show_more]
    [last_updated.last_updated_30]
    Senior Quality Assurance Engineer

    Senior Quality Assurance Engineer

    Insurance Office of America • Columbia, MO, US
    [job_card.full_time]
    Title : Senior Quality Assurance Engineer – IOA Technology.Fully Remote for candidates in EST / CST time zones.Please note : If this position is posted as either fully remote and / or hybrid, in accordan...[show_more]
    [last_updated.last_updated_variable_hours] • [new]
    Building Engineer I

    Building Engineer I

    Howard Hughes Corporation • Columbia, MO, US
    [job_card.full_time]
    The Howard Hughes name is synonymous with entrepreneurial vision, tenacity and a pioneering spiritvalues still embodied by The Howard Hughes Corporation today. While Hughes' passion for aviation and...[show_more]
    [last_updated.last_updated_30] • [promoted]