Vulnerability Engineer

Posted 2 days ago

insight globalMilwaukee (WI)

SENIORITY

Lead

Apply

About the role

Required Skills & Experience: • 3+ years of professional experience in cybersecurity, vulnerability management, security engineering, network security, or a closely related field.• 2+ years of hands-on vulnerability management experience, including vulnerability identification, evaluation, prioritization, remediation coordination, and validation.• Hands-on experience working with an enterprise vulnerability scanning or vulnerability management platform.• Strong understanding of the vulnerability management lifecycle, from initial discovery through remediation and validation.• Ability to analyze vulnerability findings and determine which vulnerabilities pose the greatest risk and should receive the highest remediation priority.• Experience partnering with infrastructure, networking, security, or other technical teams to drive vulnerability remediation.• Strong knowledge of enterprise networking concepts and network infrastructure.• Experience working across a variety of enterprise technologies, including Windows, Linux, network devices, appliances, routers, and firewalls.• Understanding of zero-day vulnerabilities and emerging cybersecurity threats and the ability to evaluate their relevance to an enterprise environment.• Strong analytical, troubleshooting, and problem-solving capabilities.• Excellent written and verbal communication skills, with the ability to clearly explain technical vulnerabilities, associated risks, and remediation priorities.• Strong interpersonal and influencing skills with the ability to gain buy-in from technical teams and stakeholders.
Nice to Have: Skills & Experience• Experience helping build, mature, or expand an enterprise vulnerability management program.• Experience extending vulnerability scanning into new asset types, technologies, or environments.• Experience with vulnerability management platforms such as Tenable/Nessus, Qualys, Rapid 7 InsightVM, or comparable technology.• Experience working within a large enterprise, regulated organization, utility, or critical infrastructure environment.• Exposure to cloud infrastructure and cloud vulnerability management.• Experience developing vulnerability management reports, metrics, dashboards, or KPIs.• Experience with scripting or automation technologies such as Power Shell or Python.• Knowledge of cybersecurity frameworks and vulnerability classification methodologies.• Relevant cybersecurity certifications such as Security+, CySA+, CISSP, GIAC, or similar.
Job Description: Insight Global is seeking an IT Cybersecurity Analyst – Vulnerability Engineer to join one of our largest utility clients in the Midwest. This individual will join the Cybersecurity organization and play a critical role in identifying, evaluating, prioritizing, communicating, and driving the remediation of vulnerabilities across a large enterprise environment. This role goes beyond simply operating a vulnerability scanning tool. The Vulnerability Engineer will work closely with infrastructure, networking, cybersecurity, and other technical teams to identify vulnerabilities, evaluate their potential impact, determine appropriate priorities, and help coordinate remediation efforts. A major component of this position is communication and influence. The ideal candidate will be able to take complex technical vulnerabilities and clearly explain what the risk is, why it matters, and why certain vulnerabilities need to be addressed ahead of others. This individual will also proactively monitor zero-day vulnerabilities and emerging cyber threats while helping continuously improve and expand the organization's vulnerability management program across servers, endpoints, network infrastructure, appliances, and other connected technologies.
Day-to-Day: Responsibilities• Identify, analyze, evaluate, and prioritize vulnerabilities across the enterprise environment.• Operate and support enterprise vulnerability scanning and vulnerability management technologies.• Analyze vulnerability findings to determine actual risk, severity, potential impact, and remediation priority.• Partner with infrastructure, networking, cybersecurity, and other technical teams to communicate vulnerability findings and coordinate remediation.• Clearly explain why a vulnerability is a priority, helping technical teams understand the associated risk and gain buy-in around remediation efforts.• Assist teams with identifying appropriate remediation or risk-reduction strategies for identified vulnerabilities.• Track vulnerabilities throughout the remediation lifecycle and validate remediation efforts as needed.• Proactively monitor zero-day vulnerabilities, emerging cybersecurity threats, security advisories, and newly disclosed vulnerabilities that could impact the organization.• Evaluate emerging vulnerability information and determine its relevance and potential impact to the enterprise.• Help continuously improve, mature, and expand the vulnerability management program by identifying opportunities for additional scanning and security coverage.• Expand vulnerability scanning across a broad range of assets, including Windows servers, Linux servers, workstations, network devices, appliances, routers, firewalls, and other network-connected technologies.• Apply networking knowledge to support vulnerability scanning across complex enterprise environments.• Work cross-functionally to gather information on technologies, assets, and environments that should be incorporated into the vulnerability management program.• Support continuous improvement of vulnerability management processes, procedures, reporting, and overall security posture.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this