Summary
Nasuni is hiring a Security Engineer II to strengthen vulnerability management across cloud workloads, on-premises infrastructure, network assets, and employee endpoints. The role owns vulnerability scanning, triage, risk-based prioritization, remediation coordination, closure validation, reporting, tooling improvements, and incident support within an on-call rotation.
Responsibilities
- Own recurring vulnerability scanning, triage, prioritization, remediation tracking, exception follow-up, and closure validation across hybrid infrastructure
- Operate and improve vulnerability-management tooling, including Rapid7 InsightVM or comparable platforms
- Use Wiz and other asset or cloud-security data to add workload, exposure, ownership, and business context to vulnerability decisions
- Maintain accurate visibility into servers, network devices, endpoints, cloud workloads, and other in-scope assets by reconciling scanner, endpoint, cloud, and inventory data
- Prioritize findings using exploitability, exposure, asset criticality, business impact, compensating controls, and available threat intelligence—not CVSS alone
- Partner with Engineering, SRE, IT, and Infrastructure teams to assign owners, agree on remediation plans, manage blockers, and verify that risk has been reduced
- Track remediation SLAs, exceptions, recurring weaknesses, and coverage gaps; escalate material risk using clear evidence
- Produce concise reporting that helps technical teams act and gives security leadership an accurate view of exposure and progress
- Recommend practical improvements to patching, configuration hygiene, asset ownership, reporting, and remediation workflows
- Lead and support security incidents as part of an on-call rotation
- Maintain runbooks, evidence, scan records, and remediation documentation for operational continuity and audit readiness
- Use AI-assisted tools to accelerate triage, analysis, reporting, and workflow improvement while protecting sensitive data, validating outputs, and remaining accountable for decisions
Skills
- * Hands-on experience operating a recurring vulnerability management program or major workstream
- * Experience with vulnerability discovery, triage, risk-based prioritization, remediation coordination, and closure validation
- * Experience working with infrastructure, endpoint, network, or cloud asset owners to drive remediation
- * Practical experience with a platform such as Rapid7 InsightVM, Tenable, Qualys, or equivalent
- * Experience supporting security incidents as part of an on-call rotation
- * Demonstrable experience in vulnerability management in a hybrid environment (AWS preferred)
- * Understanding of CVE/CVSS concepts, exploitability, asset criticality, network exposure, and compensating controls
- * Working knowledge of infrastructure and network security fundamentals
- * Ability to translate technical findings into clear priorities and actions
- * Demonstrated ownership, follow-through, and early escalation of blockers
- * Practical experience using AI-assisted tools in a professional workflow, with appropriate review, validation, and data-handling judgment
- Typically, 3–5 years of relevant security experience, including at least 2 years of direct vulnerability-management responsibility. Equivalent practical experience is valued
- * Experience with Rapid7 InsightVM
- * Experience using Wiz or another CSPM platform for cloud workload vulnerability context
- * Experience reconciling scanner data with CMDB, endpoint, cloud inventory, or ticketing systems
- * Familiarity with CIS Benchmarks, CISA Known Exploited Vulnerabilities, EPSS, and risk-exception workflows
- * Scripting, API, workflow-automation, or security-reporting experience
- * Demonstrated improvement in asset coverage, remediation SLA performance, backlog quality, or recurring-finding rates
- * Experience across cloud, on-premises, network, and endpoint assets
- * Experience creating repeatable, securely validated AI-assisted security workflows
- A relevant degree or certifications such as Security+, CySA+, or a cloud-security certification is helpful but not required
Qualifications
Must Haves
- * Hands-on experience operating a recurring vulnerability management program or major workstream
- * Experience with vulnerability discovery, triage, risk-based prioritization, remediation coordination, and closure validation
- * Experience working with infrastructure, endpoint, network, or cloud asset owners to drive remediation
- * Practical experience with a platform such as Rapid7 InsightVM, Tenable, Qualys, or equivalent
- * Experience supporting security incidents as part of an on-call rotation
- * Demonstrable experience in vulnerability management in a hybrid environment (AWS preferred)
- * Understanding of CVE/CVSS concepts, exploitability, asset criticality, network exposure, and compensating controls
- * Working knowledge of infrastructure and network security fundamentals
- * Ability to translate technical findings into clear priorities and actions
- * Demonstrated ownership, follow-through, and early escalation of blockers
- * Practical experience using AI-assisted tools in a professional workflow, with appropriate review, validation, and data-handling judgment
- Typically, 3–5 years of relevant security experience, including at least 2 years of direct vulnerability-management responsibility. Equivalent practical experience is valued
Nice to Haves
- * Experience with Rapid7 InsightVM
- * Experience using Wiz or another CSPM platform for cloud workload vulnerability context
- * Experience reconciling scanner data with CMDB, endpoint, cloud inventory, or ticketing systems
- * Familiarity with CIS Benchmarks, CISA Known Exploited Vulnerabilities, EPSS, and risk-exception workflows
- * Scripting, API, workflow-automation, or security-reporting experience
- * Demonstrated improvement in asset coverage, remediation SLA performance, backlog quality, or recurring-finding rates
- * Experience across cloud, on-premises, network, and endpoint assets
- * Experience creating repeatable, securely validated AI-assisted security workflows
- A relevant degree or certifications such as Security+, CySA+, or a cloud-security certification is helpful but not required
Benefits
- Best in class employee onboarding and training
- “Take What You Need” paid time off policy
- Comprehensive health, dental and vision plans
- Company-paid life and disability insurance
- 401(k) and Roth IRA retirement plan
- Generous employee referral bonuses
- Flexible remote work policy
- 10 Paid Holidays
- Wide array of wellbeing offerings
- Pre-tax savings accounts with company contributions
- Great team culture and social activities
- Collaborative workspaces
- Free on-site fitness centers and stocked kitchens in select office locations
- Professional development resources