Talent.com
AXON Networks
Security Specialist, Vulnerability Management (US - Remote)AXON Networks • Irvine, CA, United States
Security Specialist, Vulnerability Management (US - Remote)

Security Specialist, Vulnerability Management (US - Remote)

AXON Networks • Irvine, CA, United States
2 days ago
Job type
  • Full-time
Job description

Security Specialist, Vulnerability Management

AXON Networks delivers a robust AI-driven, analytics-based orchestration platform and a wide portfolio of next-gen high-speed routers that leverage the newest Wi-Fi technologies. Together, these technologies give ISPs the ability to manage and troubleshoot their networks in real time, and to deliver an outstanding customer experience.

AXON Networks is a trusted strategic partner for its customers, helping them evaluate their current technologies and business models, and creating and executing strategies that enable them to innovate faster, accelerate their digital transformations, and strengthen their relationships with consumers.

AXON Networks is headquartered in Irvine, CA USA with Asia HQ in Singapore and also operating in Denmark, Spain and Vietnam.

The Security Specialist, Vulnerability Management will establish and operate a risk-based vulnerability management capability across the companys cloud platform, applications, Kubernetes and container environments, network infrastructure, software supply chain, and cloud-managed customer-premises equipment (CPE), including broadband gateways, routers, ONTs and connected-home devices. This is a hands-on security engineering role for someone who can distinguish a scanner finding from a vulnerability that is relevant and exploitable in the companys actual environment.

The engineer will select and configure scanning approaches, validate findings, analyze CVEs, prioritize risk, coordinate remediation, verify closure and create the dashboards, evidence and operating standards needed for a repeatable program. The engineer will explain risk clearly to operational and engineering leaders and will not rely on severity scores alone.

Role Mandate

  • Establish authoritative visibility into vulnerabilities across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware and CPE asset classes.

  • Determine whether findings and CVEs apply to the versions, configurations, exposure paths and controls actually present in the environment.

  • Prioritize remediation using technical severity, known exploitation, likelihood, reachability, asset criticality, customer impact and compensating controls.

  • Create a durable operating model for intake, validation, assignment, service levels, exceptions, rescanning, closure and executive reporting.

  • Partner with Engineering, DevOps, NOC, Support, Product and Compliance to reduce measurable exposure without disrupting reliable customer service.

What You Will Own

Scanning Strategy and Coverage

  • Inventory the attack surface and define coverage for internet-facing and internal assets, cloud services, hosts, network devices, containers, Kubernetes clusters, applications, APIs, source code, third-party dependencies, images, infrastructure as code and supported CPE/firmware.

  • Design, configure and maintain authenticated and unauthenticated scans, agent-based assessments, cloud-native configuration checks, container and dependency scans, external attack-surface discovery and targeted validation tests.

  • Establish safe scan windows, credentials, rate limits, exclusions and testing procedures so scans do not destabilize production, customer environments or large CPE fleets.

  • Evaluate, select and administer appropriate capabilities from platforms such as Tenable Nessus, Qualys, Rapid7, Wiz, Orca, Prisma Cloud, Snyk, Veracode, Checkmarx, Trivy, Grype, Nuclei or equivalent tools; integrate results rather than requiring one product to solve every use case.

  • Measure coverage, scan health, credential success, stale assets and blind spots; continuously improve asset-to-owner mapping and data quality.

Finding Validation and CVE Analysis

  • Review new and existing scan findings and determine whether each is a true positive, false positive, duplicate, accepted risk, mitigated condition or actionable vulnerability.

  • Analyze CVE applicability using affected component and version, package provenance, CPE or firmware bill of materials, runtime reachability, configuration, network exposure, privileges, exploit prerequisites and existing controls.

  • Reproduce or safely validate material findings when needed using vendor advisories, proof-of-concept analysis, logs, configuration evidence, package inspection and non-production testing.

  • Document defensible disposition evidence and prevent unsupported suppression of findings or indefinite exception status.

  • Monitor vulnerability intelligence and vendor advisories for cloud, Kubernetes, Linux, networking, broadband/CPE, open- source and commercial technologies used by the company.

Risk-Based Prioritization and Response

  • Use CVSS as a severity input, not a standalone risk decision, and enrich prioritization with CISA Known Exploited Vulnerabilities, EPSS, exploit availability, exposure, reachability, asset criticality, tenant/customer impact and compensating controls.

  • Define remediation and mitigation targets by risk tier; rapidly escalate actively exploited or internet-reachable vulnerabilities and coordinate emergency response when required.

  • Create clear remediation records with affected assets, evidence, owners, due dates, recommended actions, validation criteria and customer or operational considerations.

  • Partner with Engineering and DevOps on patches, upgrades, configuration changes, image rebuilds, dependency updates, firmware releases and compensating controls; verify closure through rescans or equivalent evidence.

  • Manage risk exceptions with documented rationale, accountable approval, compensating controls, expiration dates and scheduled reassessment.

Cloud-to-CPE Security Context

  • Understand the end-to-end service path from cloud control plane and APIs through messaging, device-management protocols and access networks to broadband gateways, routers, ONTs and connected-home devices.

  • Assess vulnerabilities in the context of multi-tenant cloud services, remote device management, certificates and secrets, provisioning, telemetry, firmware delivery, administrative interfaces and fleet-scale exposure.

  • Work with Engineering to identify affected device models, hardware revisions, firmware branches, software components and deployed cohorts; support safe remediation planning and rollout validation.

  • Recognize the different evidence and remediation paths required for cloud software, third-party dependencies, network appliances, embedded Linux and customer-deployed CPE.

Program Operations, Automation and Reporting

  • Build integrations and automation for asset enrichment, deduplication, risk scoring, ticket creation, ownership routing, SLA tracking, notifications, rescans, exception expiry and evidence collection.

  • Maintain dashboards for coverage, exploitable exposure, aging, remediation performance, repeat findings, exceptions, asset ownership and risk trends by service, customer, product and device cohort.

  • Develop playbooks, standards and procedures for routine vulnerability handling, critical CVEs, zero-day response, scanner administration and tool outages.

  • Provide concise reporting to technical owners and leaders, separating raw finding volume from material risk and clearly identifying decisions or overdue actions.

  • Support audits and customer security inquiries with traceable evidence while protecting sensitive vulnerability and customer information.

Required Qualifications

  • 5+ years of hands-on experience in vulnerability management, vulnerability assessment, security engineering, product security, cloud security or a closely related discipline.

  • Demonstrated ownership of enterprise scanning and vulnerability-management workflows, including scanner configuration, authenticated scanning, coverage analysis, finding validation, false-positive handling, remediation tracking and rescanning.

  • Strong CVE analysis skills and the ability to determine applicability and exploitability using versions, configurations, exposure, reachability, privileges, controls and business context.

  • Experience with one or more enterprise vulnerability platforms and practical familiarity with complementary cloud, container, dependency, application and open-source scanning tools.

  • Working knowledge of CVE/CWE, NVD, CVSS, CISA KEV, EPSS, vendor advisories, software bills of materials and risk-based prioritization.

  • Hands-on knowledge of Linux, TCP/IP, DNS, TLS/PKI, identity and access controls, APIs, cloud infrastructure, containers and Kubernetes.

  • Ability to read code, package manifests, container images, configurations, logs and network evidence sufficiently to validate findings and guide remediation.

  • Scripting or programming ability in Python, Go, PowerShell, Bash or a comparable language, plus experience integrating security platforms with

Create a job alert for this search

Security Specialist, Vulnerability Management (US - Remote) • Irvine, CA, United States

Similar jobs

Infection Prevention and Control Technical Specialist - Remote

TradeJobsWorkForce92618 Irvine, CA, US
Remote
Full-time

Infection Prevention and Control Technical Specialst Job Duties: Consolidate, review and revise Americares existing technical materials related to disease outb... Show more

 • Promoted

Principal Compliance Specialist, Product Stewardship

Edwards LifesciencesIrvine, CA, United States
Full-time

Principal Compliance Specialist, Product StewardshipInnovation starts from the heart.Edwards Lifesciences is the leading global structural heart innovation company, driven by a passion to improve p... Show more

 • Promoted

Senior Offensive Security Consultant

EYIrvine, CA, United States
Full-time

At EY, we're dedicated to empowering you to shape your career with confidence.Join a dynamic environment where your professional path is your own, and together, we can build a better working world.... Show more

 • Promoted

Team Lead - Security

Glidewell DentalIrvine, CA, United States
Full-time

DescriptionPosition at Glidewell DentalEssential Functions:Guides team members in the execution of duties and responsibilities according to established protocols and procedures.Trains and mentors n... Show more

 • Promoted

Labor Compliance Specialist

HDRClaremont, CA, United States
Full-time +1

Labor Compliance SpecialistAt HDR, our employee-owners are fully engaged in creating a welcoming environment where each of us is valued and respected, a place where everyone is empowered to bring t... Show more

 • Promoted

Verification Specialist

PrideStaffLaguna Niguel, CA, United States
Full-time

Job DescriptionJob DescriptionA company in Laguna Niguel is seeking a detail-oriented Verification Specialist to conduct thorough screenings, ensure compliance, and provide exceptional service.This... Show more

 • Promoted

Mission Security Lead

Launch Tech USATustin, CA, United States
Full-time

Location: Vandenberg Space Force Base, CAClearance Required: Active DoD Secret Security ClearanceTravel Required: Up to 10%LaunchTech is a veteran-owned company that prides itself on delivering ser... Show more

 • Promoted

Closing Support Specialist

loanDepotIrvine, CA, United States
Full-time

Position SummaryResponsible for providing support to the Closing department with a focus on either Wires, Funding or Scheduling.Ensures the performance of all duties in accordance with the company'... Show more

 • Promoted

Security Operations Center Lead

TekfortuneIrvine, CA, United States
Full-time

Security Operations Center Lead (Onshore).The Security Operations Center Lead (Onshore) is responsible for managing and enhancing the organization's Security Operations Center (SOC) and related cyb... Show more

 • Promoted

Credentialing Specialist

AmeriPharmaLaguna Hills, CA, United States
Full-time

AmeriPharma is a rapidly growing healthcare company where you will have the opportunity to contribute to our joint success on a daily basis.We value new ideas, creativity, and productivity.We like ... Show more

 • Promoted

Regional Facilities Security Manager

Crane WWChino, CA, United States
Full-time

Collaborate with Crane Global Security to develop and oversee compliance to loss prevention measures to mitigate risk of theft or pilferage within the Region.Collaborate with Crane Global Security ... Show more

 • Promoted

Security awareness Project Manager-US

Zortech SolutionsRancho Cucamonga, CA, United States
Full-time

Security Awareness Project Manager.Location: Rancho Cucamonga CA (Onsite).Develop the strategy, goals, and objectives for the information security training, education, and awareness program.Drive p... Show more

 • Promoted

Safety Specialist

Quanta ServicesOntario, CA, United States
Full-time

About UsHBK Engineering, LLC is a fully licensed, professional engineering design firm headquartered in Chicago, IL with a staff approaching 700 individuals.HBK provides civil, environmental, struc... Show more

 • Promoted

Remote Research Panel Participant

GL IncDana Point, California
$15.00 hourly
Remote
Part-time +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Show more

 • Promoted

Work From Home - Product Specialist - $45 per hour

GL1Dana Point, California
$45.00 hourly
Remote
Part-time +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Show more

 • Promoted

Operations Incident Specialist

MurataIrvine, CA, United States
Full-time

Operations Incident Specialist.For 80 years, Murata Electronics has been a tireless innovator, committed to developing technologies that profoundly change the world around us.Our solutions are insi... Show more

 • Promoted

Senior Specialist, Global Security Policy

AbbVieIrvine, CA, United States
Full-time

Company DescriptionAbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow.We strive to ... Show more

 • Promoted

Loss Prevention & Security Manager-US

JD.comChino, CA, United States
Full-time

Loss Prevention & Safety Manager.This position plays a key role in ensuring the resilience, safety, and operational integrity of global warehouse operations.The Global Safety & Loss Prevention Mana... Show more

 • Promoted

Compliance Manager

MobilUpland, CA, United States
Full-time

The Compliance Manager has demonstrated experience with fueling systems, including underground storage tanks, fuel dispensing equipment, leak detection systems, and associated monitoring and contro... Show more

 • Promoted

Remote Work – Product Assessments - $25-$45 per hour (No Experience)

Online Consumer Panels AmericaDana Point, California, US
$25.00–$45.00 hourly
Remote
Part-time +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Show more