Jobs and Careers
PR

Senior Security Engineer, Vulnerability Management

Proofpoint
United Statesfull_timeVerifiedPosted 27 Jun 2025
💰 $207,680/yr($109,410/yr$207,680/yr)

About the role

About Us:
We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead of bad actors and safeguard the digital world. Join us in our pursuit to defend data and protect people.


How We Work:
At Proofpoint, you’ll be part of a global team that breaks barriers to redefine cybersecurity, guided by our BRAVE core values: Bold in how we dream and innovate, Responsive to feedback, challenges, and opportunities, Accountable for results and best-in-class outcomes, Visionary in future-focused problem-solving, Exceptional in execution and impact.

Corporate Overview
Proofpoint is a leading cybersecurity company protecting organizations’ greatest assets and biggest risks: vulnerabilities in people. With an integrated suite of cloud-based solutions, Proofpoint helps companies around the world stop targeted threats, safeguard their data, and make their users more resilient against cyber-attacks. Leading organizations of all sizes, including more than half of the Fortune 1000, rely on Proofpoint for people-centric security and compliance solutions mitigating their most critical risks across email, the cloud, social media, and the web.
 

We are singularly devoted to helping our customers protect their greatest assets and biggest security risk: their people. That’s why we’re a leader in next-generation cybersecurity.
 

Protection Starts with People.  Proofpoint.
 

The Role

We are seeking a highly skilled and experienced Senior Security Engineer specializing in Vulnerability Management to join our Information Security team. This individual will play a pivotal role in safeguarding our infrastructure, applications, and services through proactive vulnerability identification, risk assessment, and remediation strategy development. The ideal candidate has deep, hands-on expertise with Tenable Security Center, Tenable.io, Wiz, and Veracode, as well as substantial experience managing and supporting FedRAMP and ISO 27001 audits. This is a technical leadership role that also involves strategic program design, stakeholder communication, audit preparation, and artifact maintenance. Based in Draper Utah, this key role will drive key vulnerability management initiatives for Proofpoint Product portfolio.

Key Responsibilities:

Vulnerability Management Operations:

  • Lead enterprise-wide vulnerability management initiatives, ensuring coverage across cloud, on-premises, and hybrid environments.
  • Manage, operate, and optimize Tenable Security Center, Tenable.io, Qualys VMDR, Wiz, and Veracode platforms.
  • Analyze and prioritize vulnerabilities based on business risk, CVSS scores, threat intelligence, and asset criticality.
  • Collaborate with IT and DevOps teams to drive timely remediation or mitigation.
  • Maintain a metrics-driven approach to track vulnerability trends, SLAs, and program effectiveness. Security Audit and Compliance Support
  • Serve as a key technical point of contact for FedRAMP and ISO 27001 assessments for the Vulnerability Management area.

Generate, update, and maintain FedRAMP security artifacts including:

  • System Security Plan (SSP)
  • Plan of Action and Milestones (POA&M)
  • Continuous Monitoring (ConMon) reports
  • Security Assessment Reports (SAR)

Risk Assessments and Control Implementation Summaries:

  • Assist with gap assessments, readiness reviews, and coordinate with Third Party Assessment Organizations (3PAOs).
  • Support audit interviews, evidence gathering, and remediation plans.
  • Ensure continuous compliance with FedRAMP Moderate/High and ISO 27001 controls. Policy, Documentation, and Risk Management
  • Draft and maintain security policies, standards, procedures, and guidelines related to vulnerability and patch management.
  • Integrate vulnerability management findings into enterprise Risk Register.
  • Develop executive-level dashboards and reports on risk visibility and leadership decision-making. Collaboration and Leadership
  • Act as a technical SME and mentor to junior engineers on vulnerability management tooling and methodologies.
  • Work cross-functionally with product security, IT, cloud, and compliance teams.
  • Advocate for secure development practices and continuous improvement in vulnerability detection and response.

What You Bring:

  • 6+ years of hands-on experience in information security, with at least 4 years specifically in vulnerability management.
  • Demonstrable deep expertise with Tenable Security Center, Tenable.io, Wiz, and Veracode platforms.
  • Expertise in automating / integrating the above platforms with Jira and othe

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Proofpoint

View company profile →