Jobs and Careers
CO

Principal Cyber Vulnerability Engineer Dallas or Detroit metro

Comerica Incorporated
Auburn Hills, United Statesfull_timeVerifiedPosted 5 Aug 2025

About the role

Principal Cyber Vulnerability Engineer


The Cyber Vulnerability Operations Team consists of both the Application Security (AppSec) teams and the Vulnerability Management Operations (VM Ops) teams. Together, the Vulnerability Operations team collaborates with peers across Comerica to provide visibility into vulnerabilities within applications and infrastructure and ensures they are remediated, as well as facilitates and enforces the use of secure development practices across the bank.
The ideal candidate will have experience with Qualys Policy Compliance module and VMDR module is required for this role. Ideal candidate will have experience with scripting, regular expressions and expertise in at least one programming language.
The Principal Cyber Vulnerability Operations Engineer role is responsible for vulnerability scanning, prioritizing vulnerabilities, and driving remediations while partnering with the application and infrastructure teams. The ideal candidate for this role will have hands-on expertise working in vulnerability management and operations and will have knowledge of tools such as Qualys, PowerBI, and/or SAST/DAST. This candidate will be experienced working with cross-functional teams in vulnerability management and prioritization and will have the ability to automate while using a programming language.
Provide knowledge of Vulnerability Operations including but not limited to:

  • Maintain, optimize, configure, and solve the vulnerability management solutions deployed enterprise-wide.
  • Perform enterprise-wide scheduled and ad-hoc vulnerability assessments, including network, agent, and authenticated scans.
  • Ensure coverage and accuracy of the various vulnerability scanning and reporting tools throughout the infrastructure and applications.
  • Develop and integrate dynamic and data-driven dashboards and workflows that provide up to date vulnerability information to asset owners and leadership teams.
  • Improve procedures by automating Vulnerability Management processes through data extraction/transformation and tool integrations.
  • Review and refine vulnerability findings to reduce false positives and other issues.
  • Collaborate and communicate detailed vulnerability findings to the teams responsible for remediation.
  • Leverage criteria such as threat intelligence, asset and business impact, and compensating controls to develop risk prioritization standards that help target remediation activities and program goals.
  • Assist in vulnerability management platform configurations, evaluations and POVs.
  • Design and deliver clear, actionable Vulnerability Management reports, metrics, and briefings.
  • Review new vulnerabilities, assess potential risks to Comerica, and draft alert bulletins.
  • Apply standard processes and develop security documentation under the guidance of Vulnerability Management leads.
  • Collaborate with technical leads across Comerica to ensure assets are appropriately covered by the Vulnerability Management program.
  • Work with asset owners and technical teams to develop scanning schedules, configurations, and asset exclusion lists for each Business Unit.

 

Position Responsibilities:
Vulnerability Management Operations

  • Perform vulnerability assessments and common baseline control scans across the Comerica environment and report on Key Risks Indicators (KRIs).
  • Lead security vulnerabilities and risk management activities across Comerica, including identifying vulnerabilities and supporting application/system owners to manage risks/remediate vulnerabilities.
  • Establish and mature processes around vulnerability management, remediation, and reporting.
  • Lead key projects such as vulnerability prioritization to remediate critical key vulnerabilities.
  • Participate in vendor evaluations and selection for vulnerability management products, such as external attack surface management.
  • Implement and support those products on a continuous basis.
  • Stay current on vulnerability management best practices across the industry.

Administration & Reporting

  • Develop a comprehensive set of metrics to track on enterprise risks and remediation trends and keep Management informed of them through accurate, timely, and appropriate reporting.
  • Support monthly KRI reporting through data collection, working with application and infrastructure teams to remediate vulnerabilities.
  • Create presentations based off KRI materials and keep Management informed of them.

Technical Consulting & Communication

  • Drive technical excellence and implementation of vulnerability management best practices in collaboration with technology teams across the enterprise

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Comerica Incorporated

View company profile →