Summary
PCI Professional Services is seeking a Security Engineer - Vulnerability Management to manage and enhance its vulnerability management program. The role focuses on identifying, assessing, and mitigating vulnerabilities across systems, networks, and applications while collaborating with IT, security, and development teams to strengthen security posture and compliance. The position also supports process improvement, risk communication, reporting, and incident response related to exploited vulnerabilities.
Responsibilities
- Managing and enhancing the organization's vulnerability management program
- Identifying, assessing, and mitigating security vulnerabilities across the organization's systems, networks, and applications
- Working closely with IT, security, and development teams to ensure a robust security posture and compliance with industry standards
- Identifying and addressing security gaps
- Implementing best practices
- Communicating risks effectively to stakeholders
- Contributing to the continuous improvement of vulnerability management processes, tools, and reporting mechanisms
Skills
- Minimum of 4–6 years of experience in vulnerability management or a related information security role
- Advanced knowledge of vulnerability management tools and platforms such as Tenable Nessus, Qualys, Rapid7, OpenVAS, or similar
- Strong understanding of vulnerability scanning, assessment, and risk prioritization
- Familiarity with common vulnerability scoring systems and frameworks (e.g., CVSS, NIST 800-53, OWASP Top 10)
- Understanding of operating systems (Windows, Linux, macOS) and their associated vulnerabilities
- Knowledge of network protocols and components (e.g., TCP/IP, DNS, firewalls, routers, and switches)
- Experience with patch management processes and tools
- Basic understanding of compliance requirements, such as FISMA, and SOX
- Familiarity with security frameworks such as NIST Cybersecurity Framework, ISO 27001, and CIS critical security controls
- Ability to assess vulnerabilities, identify risks, and assist in incident response processes when vulnerabilities have been exploited
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent work experience)
- Advanced skills in vulnerability exploitation and proof of concept (PoC) development
- Familiarity with exploit frameworks like Metasploit
- Experience with cloud security tools and platforms (e.g., AWS Inspector, Azure - Security Center, or GCP Security Command Center)
- Expertise in identifying and mitigating critical vulnerabilities in complex environments
- Experience with configuration assessment tools such as SCAP or CIS-CAT
- Knowledge of threat intelligence tools and processes to correlate vulnerabilities with real-world threats
- Understanding of threat modeling and attack surface analysis
- Experience with SIEM tools (e.g., Splunk, QRadar) and integration with vulnerability management processes
- Knowledge of log analysis and event correlation
- Advanced certifications, such as:
- GIAC Certified Vulnerability Analyst (GCVA)
- Offensive Security Certified Professional (OSCP)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
Qualifications
Must Haves
- Minimum of 4–6 years of experience in vulnerability management or a related information security role
- Advanced knowledge of vulnerability management tools and platforms such as Tenable Nessus, Qualys, Rapid7, OpenVAS, or similar
- Strong understanding of vulnerability scanning, assessment, and risk prioritization
- Familiarity with common vulnerability scoring systems and frameworks (e.g., CVSS, NIST 800-53, OWASP Top 10)
- Understanding of operating systems (Windows, Linux, macOS) and their associated vulnerabilities
- Knowledge of network protocols and components (e.g., TCP/IP, DNS, firewalls, routers, and switches)
- Experience with patch management processes and tools
- Basic understanding of compliance requirements, such as FISMA, and SOX
- Familiarity with security frameworks such as NIST Cybersecurity Framework, ISO 27001, and CIS critical security controls
- Ability to assess vulnerabilities, identify risks, and assist in incident response processes when vulnerabilities have been exploited
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent work experience)
Nice to Haves
- Advanced skills in vulnerability exploitation and proof of concept (PoC) development
- Familiarity with exploit frameworks like Metasploit
- Experience with cloud security tools and platforms (e.g., AWS Inspector, Azure - Security Center, or GCP Security Command Center)
- Expertise in identifying and mitigating critical vulnerabilities in complex environments
- Experience with configuration assessment tools such as SCAP or CIS-CAT
- Knowledge of threat intelligence tools and processes to correlate vulnerabilities with real-world threats
- Understanding of threat modeling and attack surface analysis
- Experience with SIEM tools (e.g., Splunk, QRadar) and integration with vulnerability management processes
- Knowledge of log analysis and event correlation
- Advanced certifications, such as:
- GIAC Certified Vulnerability Analyst (GCVA)
- Offensive Security Certified Professional (OSCP)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)