Senior Cyber Security Engineer, Vulnerability Management
Community Health SystemsAbout the role
Job Summary
As a member of the Cyber Security team, the Cyber Security Senior Engineer for Vulnerability Management will be responsible for developing, implementing, and operating vulnerability management solutions to identify, classify, and report existing and emerging vulnerabilities detected in enterprise infrastructure. The Senior Engineer will operate within the existing exposure management team as an expert in vulnerability management, ensuring sound practices while designing, growing, and maintaining the vulnerability management program, contributing to vulnerability identification and remediation methodologies, supporting penetration testing practices, report generation, and more. The Senior Engineer will be responsible for seeking out and reporting on vulnerability discoveries and classifications of new vulnerabilities as well as partnering with Threat Intelligence to incorporate current threat activity into risk prioritization. The Senior Engineer will work directly with other security and information technology team members to develop plans for reporting and remediation of vulnerabilities across all operating systems and applications in the enterprise.
Essential Duties and Responsibilities
- Develop, implement, and operate vulnerability management solutions to identify, classify, and report existing and emerging vulnerabilities in enterprise infrastructure including application and multi-cloud technologies.
- Serve as the subject matter expert in vulnerability management within the exposure management team, contributing to the development, engineering, and maintenance of the vulnerability management program.
- Apply industry best practices and standards to vulnerability identification and remediation methodologies, penetration testing practices, and report generation.
- Stay up to date on the latest vulnerability discoveries and classifications, and proactively assess and report their potential impact on the organization's systems and applications.
- Collaborate with security and IT team members to develop comprehensive plans for reporting and remediation of vulnerabilities across all operating systems, cloud computing systems, and applications in the enterprise.
- Conduct regular vulnerability assessments, utilizing automated tools and manual techniques to ensure thorough coverage and accuracy.
- Analyze vulnerability assessment results and provide recommendations for prioritizing and remediating vulnerabilities based on risk and impact.
- Collaborate with the Threat Intelligence and Incident Response teams to correlate emerging threats with exposure data.
- Contribute to the development and maintenance of vulnerability management policies, procedures, and documentation.
- Provide guidance and support to junior team members, fostering knowledge sharing and professional growth within the vulnerability management team.
- Develop and present metrics, dashboards, and executive reports related to vulnerability trends, SLA compliance and risk posture.
- Business and Soft Skill expectations:
- Communicate and interact effectively and professionally with co-workers, management, customers, etc.
- Maintain complete confidentiality of company business.
- Communicate with management regarding development within areas of assigned responsibilities and perform special projects as required or requested.
Education
- H.S. Diploma or GED required
- Bachelor’s or Master’s Degree in Cyber Security, Computer Science, Information Systems (or other related field), or equivalent work experience preferred
Required Experience
- Duration:
- 3+ years of IT or information security, and
- 2+ years of vulnerability management
- Activities:
- Practical experience with designing and implementing technologies related to vulnerability management including vulnerability scanning, penetration testing, and configuration management
- Served as expert thought leader for vulnerability management technologies and influenced the strategy for remediation
- Worked in process-driven structured environments and participated in process optimization activities.
- Competencies:
- In-depth knowledge of CVEs, CVSS, threat modeling, and vulnerability scanning technologies.
- Familiarity with industry frameworks and standards such as NIST, CIS, and CVSS.
- Strong understanding of operating systems, network protocols, and web applications.
- Hands-on experience with vulnerability scanning and assessment tools (e.g., Nessus, Qualys, OpenVAS).
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s