Security Engineer
convisoWashington (DC)
About the role
Conviso Inc is hiring Security Engineer. This is remote role and it comes with benefits, 401K & some accrued PTO. The Ideal Candite will have good understanding/foundation in vulnerability management, compliance support, and cloud infrastructure security. Title: Security Engineer
Location: Remote, Washington, DC
Experience Level: 1-3 Years
Key Responsibilities:
Vulnerability Management• Monitor, track, and support remediation activities for vulnerabilities identified through tools such as Nessus, Defender for Cloud, Invicti, and Sonar Qube.• Deliver weekly Splunk auditable events reports.• Lead weekly security meetings, providing updates on ongoing vulnerability and remediation efforts.• Ensure all vulnerability related certificates remain valid and current.• Track and verify that all software licenses are up to date. Patch & System Assurance• After scheduled patching cycles, validate that all Virtual Machines (VMs) are operational.• Communicate status updates to application teams and key stakeholders and coordinate testing to ensure systems function as expected. Auditing & Compliance• Support Plan of Action and Milestones (POA&M) tracking and drive closure of outstanding items.• Maintain and update Security Engineering checklists to ensure continuous compliance.• Fulfill A&A (Assessment & Authorization) data requests as needed.• Respond to FNA Security inquiries regarding vulnerabilities during Change Request review cycles. Baseline & Configuration Management• Generate and deliver monthly baseline reports for environments, including:– Software inventories– Software end of life assessments– Ports and protocols validation– Azure infrastructure baselines– Azure VM configuration reviews Agile/Scrum Participation• Maintain accuracy of JIRA boards by aligning stories and sub tasks with active sprint work.• Prepare materials and updates for sprint reviews on the first day of each sprint.
Qualifications:
• 1-3 years of experience in security engineering or related IT security roles.• Hands on experience with vulnerability scanning tools (e.g., Nessus, Invicti, Sonar Qube).• Familiarity with cloud security frameworks (Azure preferred).• Working knowledge of patch management processes, compliance frameworks, and auditing practices.• Exposure to SIEM tools (Splunk preferred).• Experience working in Agile/Scrum environments and using tools such as JIRA.• Strong communication skills and ability to collaborate effectively in remote teams.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
