Sr. Vulnerability Management Engineer
LPL FinancialAbout the role
What if you could build a career where ambition meets innovation? At LPL Financial, we empower professionals to shape their success while helping clients pursue their financial goals with confidence.
What if you could have access to cutting-edge resources, a collaborative environment, and the freedom to make an impact? If you're ready to take the next step, discover what’s possible with LPL Financial.
Job Overview:
LPL Financial is in search of an Sr. Vulnerability Management Engineer to mature and operate the existing VM program at LPL. As a member of the Information Security organization, the Sr. Vulnerability Management Engineer will play a key role in ensuring that security vulnerabilities are effectively identified and managed within the environment. A successful candidate can expect to work closely with infrastructure, engineering, and application teams to ensure that vulnerabilities are remediated. The Sr. Vulnerability Management Engineer is expected to identify solutions for common security problems while participating in a broader Information Security team focused on building relationships with stakeholders throughout the organization.
Responsibilities:
Perform as a vulnerability management SME in several of the following areas: Microsoft platform (Server, workstation, applications), Open Systems platforms (Linux, UNIX, VM Ware ESX), virtualization platforms (e.g. Citrix), Networking, Databases (Oracle, SQL Server, DB2, IMS), and Cloud (AWS, Azure, Google).
Lead efforts to define/implement processes, policies, and procedures to govern vulnerability remediation, external attack surface, and compliance policy scanning efforts and track open vulnerabilities/issues from identification to resolution, following up with remediation owners and escalating risk as necessary
Assist with the implementation, management and maintenance of vulnerability management and external attack surface platforms/tools, including troubleshooting and resolving technical/functional issues and ensuring successful platform operations
Configure integrations between vulnerability management/external attack surface and issue tracking tools to most effectively communicate and track identified vulnerabilities
Develop scripts and implement automated mechanisms to automate manual processes and tasks for gathering and consolidating information
Configure and maintain custom compliance policy scanning rulesets based on CIS benchmarks and develop automated processes for reporting results to stakeholders
Be able to successfully partner with other security and IT professionals to assess potential impact from vulnerabilities specific to LPL Financials environment, and determine and implement mitigating controls.
Identify and recommend appropriate measures to manage and remediate vulnerabilities or security exposures and reduce potential impacts on information resources to a level acceptable to the senior management of the company.
Be a champion for vulnerability management and information security including broadening awareness and use of the team’s services, education of security best practices and integration with other business areas.
Perform manual testing of vulnerabilities and exploits leveraging tools such as Metasploit, NMAP, and BurpSuite to identify false positives, validate security defenses and identify risk areas
Understands vulnerability exploitation techniques and stays up to date on the latest vulnerabilities and exploits
Develop and improve KPIs, metrics, and trending for vulnerability management functions.
What are we looking for?
We want strong collaborators who can deliver a world-class client experience. We are looking for people who thrive in a fast-paced environment, are client-focused, team oriented, and are able to execute in a way that encourages creativity and continuous improvement.
Requirements:
5+ years of practical experience in information security field within a large enterprise environment
3+ years of vulnerability management experience, including directly managing scanning tools (ex. Qualys, Rapid7, Tenable) and understanding types of vulnerabilities and techniques/compensating controls to mitigate associated risk
1+ years of managing and configuring external attack surface management platforms (ex. AssetNote, XPanse, CyCognito)
Preferences:
Bachelors and/or Master’s Degree or equivalent in Information Security, Engineering, Computer Science.
Experience building/managing integrations between vulnerability management tools with issue tracking tools (ex.JIRA, Ser
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s