Talent.com
Widenet Consulting
VULNERABILITY MANAGEMENT ENGINEERWidenet Consulting • Seattle, WA, US
VULNERABILITY MANAGEMENT ENGINEER

VULNERABILITY MANAGEMENT ENGINEER

Widenet Consulting • Seattle, WA, US
2 days ago
Job type
  • Temporary
Job description
Job Description: Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST. Job Description: This position supports advancing the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate. Detect: – Maintain and expand scan and sensor coverage across endpoints, servers, cloud workloads, containers, network devices, and SaaS – Close asset visibility gaps, including shadow IT, unmanaged devices, and assets provisioned outside IT – Tune authenticated scanning, credential health, agent health, and scan cadence to reduce false negatives – Reconcile vulnerability data across multiple sources into a single authoritative inventory Prioritize: – Build and operate risk-based prioritization that blends CVSS severity, EPSS likelihood, CISA KEV exploitation status, and SSVC decision logic – Enrich findings with business context: asset criticality, data classification, internet exposure, compensating controls, application owner, and business unit – Replace severity-only queues with defensible, tiered remediation SLAs – Operate the exception and risk acceptance workflow, including expiration and re-review Report: – Design and publish program metrics: coverage, mean time to remediate by tier, backlog aging, SLA compliance, and burndown – Deliver executive and operational dashboards, including Power BI reporting fed by automated pipelines – Produce audit and assurance evidence on request – Translate technical findings into business risk language for non-technical stakeholders Remediate: – Drive remediation campaigns in partnership with IT operations, endpoint, cloud, and application teams – Automate ticket creation, routing, and closure into the ITSM platform – Perform closed-loop verification that remediation actually reduced exposure – Support emergency response for actively exploited vulnerabilities Platform and program: – Direct, hands-on experience implementing or migrating to a new enterprise vulnerability management platform, including requirements definition, proof of concept, integration, data migration, and rollout – Direct experience driving continuous improvement to an established VM program, including maturity assessment, process redesign, and runbook development Required Qualifications – 5+ years hands-on vulnerability management or security engineering – Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium) – Demonstrated experience building prioritization models that incorporate business context, not severity alone – Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration – Working fluency with KQL or an equivalent query language for security data – Experience integrating VM data with CMDB, ITSM, and BI platforms – Cloud vulnerability management experience across Azure and at least one other provider – Ability to work independently and produce written deliverables without heavy oversight Preferred – Experience with Tanium and Microsoft Defender for Endpoint as data sources – Container and image scanning experience – Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns – Exposure to CTEM or exposure management program models – Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500 Pay Range: $75.00 – $85.00 per hour, depending upon experience. Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state. SLA Describe hiring preference (C/CTH/FTE) 12 month contract Bill rate or FTE Salary range and target: Target rate: We need to make our best offer, so let’s discuss rates, keeping in mind they can go a bit higher than for our other clients. Potential target: $140 to $155/hr Work Authorization Requirements: No C2C without approval 1099 ok Budget Confirmed? Yes Why is the position open? New role How long has the position been open? Just opened Is there HR/vendor competition? Exclusive? Competition – this is an RFP process Interview Process: 2 interviews – likely team fit/leadership + technical Work location: Local and onsite 2-3 days a week is ideal and will be prioritized over remote Open to remote but must be in PST. This is not preferred. Team size Enterprise wide Project overview: Advance the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate. Top 5: 5+ years hands-on vulnerability management or security engineering Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium) Demonstrated experience building prioritization models that incorporate business context, not severity alone Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration Working fluency with KQL or an equivalent query language for security data Experience integrating VM data with CMDB, ITSM, and BI platforms Cloud vulnerability management experience across Azure and at least one other provider Nice to Have: Experience with Tanium and Microsoft Defender for Endpoint as data sources Container and image scanning experience Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns Exposure to CTEM or exposure management program models Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500 Job Description: Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST. Job Description: This position supports advancing the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate. Detect: – Maintain and expand scan and sensor coverage across endpoints, servers, cloud workloads, containers, network devices, and SaaS – Close asset visibility gaps, including shadow IT, unmanaged devices, and assets provisioned outside IT – Tune authenticated scanning, credential health, agent health, and scan cadence to reduce false negatives – Reconcile vulnerability data across multiple sources into a single authoritative inventory Prioritize: – Build and operate risk-based prioritization that blends CVSS severity, EPSS likelihood, CISA KEV exploitation status, and SSVC decision logic – Enrich findings with business context: asset criticality, data classification, internet exposure, compensating controls, application owner, and business unit – Replace severity-only queues with defensible, tiered remediation SLAs – Operate the exception and risk acceptance workflow, including expiration and re-review Report: – Design and publish program metrics: coverage, mean time to remediate by tier, backlog aging, SLA compliance, and burndown – Deliver executive and operational dashboards, including Power BI reporting fed by automated pipelines – Produce audit and assurance evidence on request – Translate technical findings into business risk language for non-technical stakeholders Remediate: – Drive remediation campaigns in partnership with IT operations, endpoint, cloud, and application teams – Automate ticket creation, routing, and closure into the ITSM platform – Perform closed-loop verification that remediation actually reduced exposure – Support emergency response for actively exploited vulnerabilities Platform and program: – Direct, hands-on experience implementing or migrating to a new enterprise vulnerability management platform, including requirements definition, proof of concept, integration, data migration, and rollout – Direct experience driving continuous improvement to an established VM program, including maturity assessment, process redesign, and runbook development Required Qualifications – 5+ years hands-on vulnerability management or security engineering – Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium) – Demonstrated experience building prioritization models that incorporate business context, not severity alone – Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration – Working fluency with KQL or an equivalent query language for security data – Experience integrating VM data with CMDB, ITSM, and BI platforms – Cloud vulnerability management experience across Azure and at least one other provider – Ability to work independently and produce written deliverables without heavy oversight Preferred – Experience with Tanium and Microsoft Defender for Endpoint as data sources – Container and image scanning experience – Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns – Exposure to CTEM or exposure management program models – Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500 Pay Range: $75.00 – $85.00 per hour, depending upon experience. Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.
Create a job alert for this search

VULNERABILITY MANAGEMENT ENGINEER • Seattle, WA, US

Similar jobs

M365 ENGINEER (RENTON, WA)

Widenet ConsultingRenton, WA, US
Full-time

Job Description: Location: This position will require the candidate to work onsite in Renton, WA.About the Role: We’re looking for an experienced Microsoft 365 & Identity Engineer to join our IT te... Show more

 • Promoted

WASMI3-Project Management Specialist 3 - P20 - General Project Mgmt

ACL DigitalRenton, WA, United States
Full-time

In this role you will: The Project Management specialist will lead project execution for the 737 Payloads team.You will work with leadership and cross-functional teams to build and maintain an inte... Show more

 • Promoted

SHIPBUILDING SPECIALIST

US NavyEverett, WA, United States
Full-time

You will develop repair specifications and government estimates in support of various shipbuilding contracts.You will review and evaluate contractor proposals for the purpose of providing input or ... Show more

 • Promoted

Chief Engineer (Limited or DDE Unlimited)- Seattle/Tacoma Based

Foss MaritimeSeattle, WA, United States
Full-time

Number003-4332Job DescriptionAbout Foss MaritimeFoss Maritime is one of the most recognized and respected maritime brands in the U.While deeply rooted in tradition, Foss is evolving at a fast pace,... Show more

 • Promoted

Licensed Facilities Maintenance Manager

IntelliSourceMarysville, WA, United States
Full-time

General Maintenance / Facilities.Marysville, WA, 98270, United States. Show more

 • Promoted

Infrastructure Verification Engineer

TechBiz Global GmbHSeattle, WA, US
Full-time

At TechBiz Global, we are providing recruitment service to our TOP clients from our portfolio.We are currently seeking a Continuous Integration & Verification Infrastructure Engineer to join on... Show more

Project Engineer

Condon-Johnson & AssociatesKent, WA, United States
Full-time

In this position, you will have the opportunity to learn the fundamentals of construction project management and the technical details of ground improvement, shoring, and foundation drilling while ... Show more

 • Promoted

SHIPBUILDING SPECIALIST

US Marine CorpsEverett, WA, United States
Full-time

You will develop repair specifications and government estimates in support of various shipbuilding contracts.You will review and evaluate contractor proposals for the purpose of providing input or ... Show more

 • Promoted

Construction Cost Control Engineer

JLM Strategic Talent PartnersTacoma, WA, United States
Full-time

We partner with National & International prime contractors to provide them with qualified talent they can trust.We accomplish this by sourcing & vetting high level career seeking candidates in the ... Show more

 • Promoted

EVNSC Site Manager

Salvation Army Western TerritoryEverett, WA, United States
Full-time

Everett New Start Center Site Manager.The Site Manager is responsible for the day-to-day operational management of the facility, ensuring safe, consistent, and effective 24/7 operations.Working clo... Show more

 • Promoted

Project Engineer

Syntricate TechnologiesEverett, WA, United States
Full-time

Position: Project Engineer (GC/USC only) Location: Onsite in Everette, WA (No remote / No Hybrid) Salary: $120- $130K/YR Preferred: Boeing project management experience.Develops overall project pla... Show more

 • Promoted

Chief Engineer

Stonebridge CompaniesSeattle, WA, United States
Full-time

Supervises: Maintenance Department.Job Summary: The Area Chief Engineer oversees maintenance operations for multiple hotels, including systems such as refrigeration, heating, plumbing, and energy c... Show more

 • Promoted

Senior Project Manager, Transportation Engineer

StantecBellevue, WA, United States
Full-time

Stantec is seeking a Washington state based, highly motivated and technically proficient Senior Project Manager with a diverse background in the Transportation Infrastructure sector to join our gro... Show more

 • Promoted

Project Engineer

SS Landscaping ServicesTacoma, WA, United States
Full-time

We specialize in complex commercial landscape construction projects, irrigation systems, site amenities, multi-family developments, HOA communities, commercial campuses, and public works projects.A... Show more

 • Promoted

SHIPBUILDING SPECIALIST

US Department of WarEverett, WA, United States
Full-time

You will develop repair specifications and government estimates in support of various shipbuilding contracts.You will review and evaluate contractor proposals for the purpose of providing input or ... Show more

 • Promoted

Chief Bldg Engineer

CBRE GroupMercer Island, WA, United States
Full-time

Chief Building EngineerCBRE Global Workplace Solutions (GWS) works with clients to make real estate a meaningful contributor to organizational productivity and performance.Our account management mo... Show more

 • Promoted

Chief Engineer - Maritime

Zeno PowerSeattle, WA, United States
Permanent

Zeno is seeking a highly motivated Chief Engineer - Maritime to support the mission-oriented efforts of developing and bringing to market Radioisotope Power Systems (RPS) technologies.As Chief Engi... Show more

 • Promoted

Development Engineering Services Manager

City of Marysville, WAMarysville, WA, United States
Full-time

This position manages the Development Services division within the Engineering Services Department.The Development Services division provides technical review and permitting for private site-develo... Show more

 • Promoted

Project Engineer

YochanaEverett, WA, United States
Full-time

Act as the primary customer contact for projects, representing Collins Aerospace with professionalism and expertise.Work cross-functionally with program management, design engineering, certificatio... Show more

 • Promoted

Future Opening: Mitigation Manager

Paul Davis RestorationEverett, WA, United States
Full-time

Mitigation Manager with Paul Davis.What does a Mitigation Manager with Paul Davis do?.Lead a team of hardworking individuals serving others within your community.Make a difference for others that h... Show more