Summary
Nelnet is a diversified company providing student loan servicing, professional services, consumer lending, payments processing, renewable energy solutions, and education services. The Vulnerability Management Engineer will lead and improve the organization’s vulnerability management strategy, oversee scanning tools, analyze risks, and coordinate remediation efforts with technology and business teams.
Responsibilities
- Lead the design, development, and continuous improvement of the organization’s vulnerability management strategy, aligning with business objectives and security requirements
- Stay up to date on emerging security threats and vulnerabilities, and ensure the program adapts accordingly
- Oversee the configuration and maintenance of vulnerability scanning tools
- Analyze vulnerability data to assess risk and recommend appropriate mitigation strategies
- Develop and implement vulnerability remediation plans, working collaboratively with all technology teams and the business
- Collaborate with cross-functional teams to assess vulnerability risks, prioritize remediation efforts, and ensure timely resolution of critical vulnerabilities to minimize security risks and operational impact
- Knowledge of CIS benchmarks, DISA STIGs, NSA Hardening Guides, and other industry security frameworks
- Demonstrated passion for continuous learning
Skills
- This position requires work in support of the Company's contract with the United States Department of Education (“ED”). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance
- In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions
- This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates Living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week
- Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship
- Knowledge of CIS benchmarks, DISA STIGs, NSA Hardening Guides, and other industry security frameworks
- Bachelor's degree in cyber security or information systems OR relevant work experience
- 2+ years of experience in vulnerability management and/or security operations
- Experience with Vulnerability management solutions (Rapid 7, Qualys, Tenable, etc.)
- Experience with patching tools like Microsoft MECM
- Experience with EDR administration (Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Network Cortex XDR, Tanium etc.)
- Solid understanding of cloud-based hosting platforms, with background on security threats deriving from Azure, AWS and GCP hosted services being preferred
- Knowledge of python programming language is required
- Cyber Security related certifications such as GIAC GSEC, GCED, GEVA, CompTIA Security+ , CySA+, ISC2 CISSP are a plus
Qualifications
Must Haves
- This position requires work in support of the Company's contract with the United States Department of Education (“ED”). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance
- In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions
- This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates Living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week
- Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship
- Knowledge of CIS benchmarks, DISA STIGs, NSA Hardening Guides, and other industry security frameworks
- Bachelor's degree in cyber security or information systems OR relevant work experience
- 2+ years of experience in vulnerability management and/or security operations
- Experience with Vulnerability management solutions (Rapid 7, Qualys, Tenable, etc.)
- Experience with patching tools like Microsoft MECM
- Experience with EDR administration (Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Network Cortex XDR, Tanium etc.)
- Solid understanding of cloud-based hosting platforms, with background on security threats deriving from Azure, AWS and GCP hosted services being preferred
- Knowledge of python programming language is required
Nice to Haves
- Cyber Security related certifications such as GIAC GSEC, GCED, GEVA, CompTIA Security+ , CySA+, ISC2 CISSP are a plus
Benefits
- This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates Living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week.
- Medical
- Dental
- Vision
- HSA and FSA
- Generous earned time off
- 401K/student loan repayment
- Life insurance & AD&D insurance
- Employee assistance program
- Employee stock purchase program
- Tuition reimbursement
- Performance-based incentive pay
- Short- and long-term disability
- A robust wellness program