Summary
AppFolio is a technology leader powering the future of the real estate industry through innovative software and trusted partnerships. The Vulnerability Management Specialist will support security engineering initiatives by validating, prioritizing, communicating, and tracking vulnerabilities, responding to emerging threats, and improving vulnerability management through artificial intelligence, machine learning, and automation.
Responsibilities
- You will validate, prioritize, communicate, and track vulnerabilities to continuously improve the overall security posture of AppFolio technology systems and applications
- You will respond to emerging threats and potential security events as 0-day vulnerabilities are released
- You will work to ensure compliance with our vulnerability management policies, processes, and procedures, and drive the adoption of emerging industry best practices
- You will help streamline the vulnerability management process through the use of Artificial Intelligence, Machine Learning, and automation, improving the end-to-end process and reducing the time-to-action for known vulnerabilities
- Through an exceptional vulnerability management program, you will build trust and confidence with our customers and partners
Skills
- * BS in Computer Science or a related technical discipline, or equivalent industry experience
- * Cybersecurity-relevant certifications, such as but not limited to GCIA, GCIH, CEH, CISSP, CISM, or OSCP
- * Project management-relevant certifications, such as but not limited to CAPM or PMP
- * 2-5 years of experience in a related cybersecurity role, preferably with a focus on Vulnerability Management, Penetration Testing, or Incident Response
- * Ability to write scripts in Ruby, Python, or other scripting languages
- * Hands-on experience with Vulnerability Management tools such as DefectDojo, Invicti, Wiz, or Cycode
- * Hands-on experience with manual testing tools, especially validating vulnerabilities
- * Understanding the capabilities and limitations of SAST, DAST, SCA, and pen test tools
- * Proficiency in various operating systems (Linux, MacOS, Windows)
- * Ability to assess security risks associated with vulnernabilities and prioritize them using existing frameworks like CVSS, accounting for local environmental factors
- * Strong communication skills and an ability to explain complex security issues to technical and non-technical stakeholders
- * Ability to maintain strict organization while overseeing complex security findings, applying structured project-style oversight to guide multiple simultaneous vulnerabilities to remediation or risk acceptance
- Experience in vulnerability management at a Software-as-a-Service company is preferred
- * Hands-on experience with network protocol vulnerabilities
- * Experience identifying and managing vulnerabilities during CI/CD
- * Hands-on experience in cloud environments (AWS, GCP, Azure)
- * Hands-on experience with Burp Suite and Tenable or similar
- * Hands-on experience with Metasploit Framework or similar
Qualifications
Must Haves
- * BS in Computer Science or a related technical discipline, or equivalent industry experience
- * Cybersecurity-relevant certifications, such as but not limited to GCIA, GCIH, CEH, CISSP, CISM, or OSCP
- * Project management-relevant certifications, such as but not limited to CAPM or PMP
- * 2-5 years of experience in a related cybersecurity role, preferably with a focus on Vulnerability Management, Penetration Testing, or Incident Response
- * Ability to write scripts in Ruby, Python, or other scripting languages
- * Hands-on experience with Vulnerability Management tools such as DefectDojo, Invicti, Wiz, or Cycode
- * Hands-on experience with manual testing tools, especially validating vulnerabilities
- * Understanding the capabilities and limitations of SAST, DAST, SCA, and pen test tools
- * Proficiency in various operating systems (Linux, MacOS, Windows)
- * Ability to assess security risks associated with vulnernabilities and prioritize them using existing frameworks like CVSS, accounting for local environmental factors
- * Strong communication skills and an ability to explain complex security issues to technical and non-technical stakeholders
- * Ability to maintain strict organization while overseeing complex security findings, applying structured project-style oversight to guide multiple simultaneous vulnerabilities to remediation or risk acceptance
Nice to Haves
- Experience in vulnerability management at a Software-as-a-Service company is preferred
- * Hands-on experience with network protocol vulnerabilities
- * Experience identifying and managing vulnerabilities during CI/CD
- * Hands-on experience in cloud environments (AWS, GCP, Azure)
- * Hands-on experience with Burp Suite and Tenable or similar
- * Hands-on experience with Metasploit Framework or similar
Benefits
- Regular full-time employees are eligible for benefits.
- You may be eligible for discretionary bonuses based on your role and/or employment type.
- Opportunities for growth.
- Coaching and mentorship with our best-in-class leaders.
- Time and tools to develop your skills.
- Hybrid work with a flexible, personal, and connected environment.