Avnet Logo

Avnet

Vulnerability Management Engineer

Posted 5 Days Ago
Be an Early Applicant
5 Locations
Senior level
5 Locations
Senior level
The Vulnerability Management Security Engineer oversees the vulnerability management process, deploying tools for scanning, assessing, and remediating vulnerabilities. Responsibilities include coordinating with IT teams, preparing reports, ensuring compliance with standards, and integrating threat intelligence. The role demands strong analytical skills, technical expertise in vulnerability management tools, and effective communication capabilities.
The summary above was generated by AI

Job Summary:

The Vulnerability Management Security Engineer is responsible to assist the Security Operations team in the comprehensive execution and management of vulnerability identification, assessment, and remediation processes across the organization. This role includes deploying and operating vulnerability assessment tools, refining scan results, providing technical assistance in coordinating with internal teams for remediation, and providing actionable insights to enhance the organization's security posture. The individual in this role must have a solid understanding of information security, risk assessment methodologies, and remediation best practices to address vulnerabilities effectively. The engineer will work closely with IT, development, and compliance teams to ensure that risks are managed within acceptable thresholds and regulatory requirements.

Principal Responsibilities:

  • Vulnerability Scanning and Assessment: Deploy and maintain vulnerability scanning tools to identify weaknesses across the organization's IT infrastructure, including servers, endpoints, networks, and applications. Conduct scheduled and ad-hoc vulnerability scans, ensuring comprehensive coverage and accuracy of scanning results. Assist in analyzing scan data to identify trends, patterns, and high-risk vulnerabilities, prioritizing issues based on potential impact and exploitability.
  • Remediation Coordination and Tracking: Work closely with IT and Security operations, application development, and other internal teams to track and support remediation efforts for identified vulnerabilities. Develop and document remediation plans and timelines based on vulnerability criticality and business impact. Facilitate the communication of remediation guidance and oversee the execution of risk mitigation actions.
  • Reporting and Documentation: Prepare detailed vulnerability assessment reports, including metrics on scan results, remediation status, and risk mitigation progress. Develop executive-level dashboards and summaries to provide a high-level overview of vulnerability management activities. Maintain documentation of processes, procedures, and vulnerability management playbooks, ensuring consistency and repeatability.
  • Continuous Improvement and Automation: Identify opportunities to improve the efficiency and effectiveness of the vulnerability management toolset, including process automation. Develop and implement scripts, automation workflows, and tools to enhance vulnerability scanning, reporting, and remediation tracking. Collaborate with other security teams to integrate vulnerability data with security incident response and threat intelligence workflows.
  • Compliance and Security Standards Adherence: Ensure vulnerability management activities align with industry standards, such as NIST, ISO 27001, and regulatory requirements like PCI-DSS and SOX. Maintain up-to-date knowledge of compliance requirements and emerging vulnerability management frameworks, incorporating relevant changes into existing processes.
  • Threat Intelligence Integration: Work with threat intelligence teams to contextualize vulnerabilities within the broader threat landscape. Adjust scanning priorities and remediation efforts based on emerging threats, zero-day vulnerabilities, and relevant exploit activity in the industry.
  • Other Duties as Assigned

Distinguishing Characteristics:

  • Technical Expertise in Vulnerability Management: The engineer should have deep expertise in vulnerability management tools and technologies, such as Qualys, Tenable, Rapid7, or similar platforms, and be skilled in configuring, tuning, and optimizing these tools.
  • Experience in Network Engineering: Demonstrated proficiency in managing and troubleshooting layer 2 and layer 3 devices.
  • Proficiency in Scripting Languages: Experience with scripting languages such as Python for automating tasks, developing custom scripts, and enhancing system administration workflows, with an ability to write, debug, and optimize code for various operational needs.
  • Analytical and Problem-Solving Skills: This role demands a strong ability to analyze scan data, understand complex infrastructure dependencies, and devise actionable and efficient remediation plans.
  • Communication and Coordination Abilities: This position requires excellent interpersonal skills to communicate vulnerability issues clearly to non-technical stakeholders and to coordinate remediation efforts across diverse teams.
  • Risk-Based Approach to Security: A successful engineer will apply a risk-based approach to vulnerability prioritization and mitigation, focusing resources on the most impactful issues, and balancing security needs with business goals.
  • Industry certifications such as CISSP, CASP, or GIAC are a plus.
  • Relevant vendor specific certifications are a plus.

Work Experience:

  • Typically, 5+ years with bachelor's or equivalent.

Education and Certification(s):

  • Bachelor's degree or equivalent experience from which comparable knowledge and job skills can be obtained.

The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities, duties, and skills.

Top Skills

Python

Similar Jobs

10 Days Ago
New Delhi, Delhi, IND
Senior level
Senior level
Food • Retail • Agriculture • Manufacturing
The DevSecOps Engineer will design, implement, and monitor secure infrastructure while defining best practices for Build & Release processes. This role will involve working with cloud environments, automating deployment pipelines, and collaborating with cross-functional teams to enhance developer productivity and security measures.
Top Skills: BashC#C++JavaPowershellPython
8 Hours Ago
Hybrid
Delhi, Connaught Place, New Delhi, Delhi, IND
Entry level
Entry level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
The role involves providing scientific expertise in vaccines, building relationships with key opinion leaders, ensuring the ethical soundness of policies, and supporting clinical research and development initiatives. Responsibilities include educational interactions, contributing to product management strategies, and disseminating medical information to healthcare professionals.
15 Hours Ago
Remote
Hybrid
18 Locations
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The role involves developing the IOT Discover product by building systems to ingest partner data and enhance asset visibility. You will define, build, and maintain the product, troubleshoot issues, and collaborate with product managers and engineers to ensure high-quality performance.
Top Skills: GoJavaPython

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account