This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

A
Posted 3mo ago

Security Engineer, Vulnerability & Attack Surface Management

AspenView
Denver or São Paulo or Colombia or Argentina or Brazil or Costa Rica or United States
RemoteContract
Responsibilities
  • designing scanning
  • building remediation
  • maintaining inventory
Requirements
  • 4+ years cybersecurity experience focused on vulnerability and attack surface management
  • Familiarity with VM/ASM tools
  • Scripting (Python/PowerShell)
  • ServiceNow/Jira
  • Security+ or GEVA and vendor certifications preferred
Technical tools mentioned
Tenable NessusQualys VMDRRapid7 InsightVMMicrosoft Defender Vulnerability ManagementCortex XpanseMicrosoft Defender EASMAxoniusServiceNowJiraPythonPowerShellCVSS v3/v4EPSSCISA KEV

Job description

The Security Engineer, Vulnerability & Attack Surface Management operates across the full vulnerability lifecycle. You will act as the technical engine of the VM program, transforming it from a reactive process into a proactive, intelligence-driven capability. By embedding AI across scanning, triage, and remediation, you will ensure high-risk vulnerabilities are addressed before exploitation across IT, cloud, and OT-adjacent environments.

What you will do:

AI-Driven Scanning & Prioritization

  • Design and operate AI-augmented vulnerability scanning pipelines across IT, cloud, and hybrid environments.
  • Deploy and tune AI-driven prioritization models combining CVSS, EPSS, CISA KEV, threat intelligence, and asset criticality.
  • Correlate vulnerability data with live threat intelligence and active exploit activity to keep prioritization models current and accurate.

Automated Remediation & Workflows

  • Build and maintain automated remediation workflows, including AI-generated ticket creation and resolution tracking through ITSM platforms.
  • Monitor SLA compliance across workflows using automated alerting and predictive SLA breach detection.
  • Produce AI-generated operational dashboards and executive reporting to translate raw vulnerability data into clear risk narratives.

Attack Surface & Asset Management

  • Maintain asset inventory accuracy and CMDB integrations, using AI-assisted asset discovery to identify shadow IT and coverage gaps.
  • Contribute to attack surface management using AI-powered exposure analysis to map external trends and model risk reduction scenarios.
  • Support exception documentation and compensating control tracking through structured, audit-ready workflows.

Tools & Technologies:

  • Scanning Platforms: Tenable Nessus, Qualys VMDR, Rapid7 InsightVM, or Microsoft Defender Vulnerability Management.
  • Risk Scoring: CVSS v3/v4, EPSS, CISA KEV, and asset-criticality-based prioritization frameworks.
  • ASM Platforms: Cortex Xpanse, Microsoft Defender EASM, or Axonius.
  • Scripting & ITSM: ServiceNow, Jira, Python, and PowerShell.

What you bring:

  • Experience: 4-6+ years in cybersecurity with a primary focus on vulnerability management, attack surface management, or security operations.
  • Certification: Security+ or GEVA preferred; vendor certifications (Tenable, Qualys) or AI/ML security coursework are a strong plus.
  • Communication: Strong analytical skills with the ability to translate AI-generated vulnerability insights into risk narratives for technical teams and executive stakeholders.
  • Collaboration: Effective at driving remediation velocity across IT, cloud, and application teams using data to influence prioritization.


Equal Opportunity Employer:

AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.


Visa Sponsorship Disclaimer USA
AspenView does not provide visa sponsorship for this role. Candidates must already be legally authorized to work in their country of residence.

Build the Future with AspenView Technology Partners

At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently. As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.

Why Join AspenView?

At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.

Here’s what you can expect:

  • Competitive base
  • Comprehensive benefits and wellness support
  • Flexible work model: hybrid, remote, or in-office
  • Real growth opportunities and leadership visibility
  • Inclusive, respectful culture that blends U.S. innovation with Colombian heart
  • A company that listens, invests in you, and celebrates wins together

About AspenView

Provides nearshore software engineering and digital transformation services.

Year founded
2024

Similar jobs

Security Engineer roles near Denver, Colorado
1w
Save
Mark Applied
Hide
Senior Security Engineer
Lafayette, Colorado, United States
$110k-$130k/yr RemoteFull Time
KPA
KPA: Provides EHS software and workforce compliance consulting services.
5+ YOE5+ years security engineering experience; strong cloud, identity, endpoint, vulnerability management, incident response, and DevSecOps skills; PowerShell/Python scripting; SOC 2/NIST familiarity; excellent communication and leadership.
CrowdStrike, Rapid7, InsightIDR, InsightVM, InsightAppSec, MDR, Cisco Umbrella, Cisco Duo, KnowBe4, Cisco Meraki, VPN, Azure, AWS, Microsoft 365, Entra ID, AWS Identity Center, Auth0, SSO, SCIM, Conditional Access, PIM, Snyk, SendGrid, Amazon SES, SPF, DKIM, DMARC, PowerShell, Python, Microsoft Graph, REST APIs, ChatGPT Enterprise, Claude, MCP, Kubernetes
2w
Save
Mark Applied
Hide
Security Engineer III, Incident Response
Boulder, Colorado, United States
$147k-$210k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
2+ YOEBachelor's degree or equivalent experience,2+ years security engineering and assessments,2+ years coding experience,incident response experience preferred,strong communication and critical thinking.
2w
Save
Mark Applied
Hide
Security Engineer (Denver, CO) - Heartland (Remote)
Denver, Colorado, United States
RemoteFull Time
GuidePoint Security
GuidePoint Security: Provides cybersecurity consulting, managed services, and integrated technology solutions.
Hands-on network security experience with firewalls and secure access; troubleshooting networking (routing, NAT, VPN); OS proficiency (Windows, macOS, Linux); strong communication and advisory skills; pre-sales/client-facing experience preferred.
Palo Alto Networks, Checkpoint, Fortinet, CrowdStrike, SentinelOne, Zscaler, Microsoft Defender, Carbon Black, Splunk, Cisco, Greenhouse, Zoom Scheduler
1mo
Save
Mark Applied
Hide
Security Engineer
Kansas City or Atlanta or Clayton or New York or Los Angeles or Birmingham or Boston or Chattanooga or Charleston or Dallas or Denver or Edwardsville or Fort Lauderdale or Fort Worth or Houston or Jefferson City or Miami or Nashville or Park City or Philadelphia or Phoenix or Raleigh or Seattle or San Francisco or Salt Lake City or Wilmington or Washington
$120k-$150k/yr RemoteFull Time
Polsinelli
Polsinelli: Am Law 100 law firm providing comprehensive legal services.
2+ YOE2-4 years security engineering experience in on-premises environments, Bachelor's in CS/CE/IS or equivalent, experience with metrics/events/logging, detection engineering, scripting (Python, PowerShell), Microsoft Active Directory and Azure.
Splunk, Microsoft Active Directory, Azure, SIEM, Python, PowerShell, Microsoft Teams, Zoom, MITRE ATT&CK Framework, NIST Cyber Security Framework, CIS Controls
1mo
Save
Mark Applied
Hide
Insider Threat Investigator
Atlanta or Boulder or Reston
$152k-$228k/yr HybridFull Time
Workday
WorkdayNASDAQ: WDAY: Provides cloud-based software for financial and human capital management.
8+ YOE8+ years in insider threat/counterintelligence/corporate investigations or related fields; bachelor’s degree; proficiency with SIEM/UEBA platforms; working knowledge of DLP, endpoint detection, and digital forensics; strong communication and judgment.
SIEM, UEBA, Splunk, QRadar, Sentinel, Exabeam, Proofpoint, DTEX, Purview
1mo
Save
Mark Applied
Hide
Principal Security Engineer
Englewood or Austin
HybridFull Time
Jeppesen ForeFlight
Jeppesen ForeFlight: Provides integrated software and data solutions for aviation flight planning.
10+ YOE10+ years in security engineering or architecture with 3+ years as a principal/staff-level IC; hands-on with cloud (AWS, Microsoft Azure), IAM, VPC, Okta/Entra ID/Azure AD, EDR/XDR, SIEM, SOAR; knowledge of NIST CSF, ISO 27001, SOC 2; strong communication and risk-to-engineering delivery.
Okta, Microsoft Entra ID, Microsoft Azure AD, AWS, Microsoft Azure, IAM, VPC, EDR, XDR, SIEM, SOAR, NIST CSF, ISO 27001, SOC 2, FAA, EASA, DoD, CMMC
1mo
Save
Mark Applied
Hide
Artificial Intelligence Senior Security Engineer
Chicago or Washington or Denver or Jersey City or Boston
$145k-$193k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
7+ YOE7+ years cybersecurity experience with hands-on AI/ML, agentic AI and LLM development, offensive/defensive security expertise, large-scale data and model deployment, and executive communication.
Azure AI Foundry, AWS Bedrock, GCP Vertex, PyTorch, TensorFlow, LangChain
2mo
Save
Mark Applied
Hide
Security Engineer
Denver, Colorado, United States
$114k-$149k/yr HybridFull Time
DAT Freight & Analytics
DAT Freight & Analytics: Software platform for freight matching and logistics data analytics.
2+ YOEHands-on security engineering for cloud and DevSecOps: Terraform/CloudFormation, container hardening, CI/CD security, logging/monitoring, NIST/SOC2/CIS frameworks, 2+ years experience preferred.
Terraform, CloudFormation, Docker, Kubernetes, CI/CD, SAST, DAST, SCA, NIST 800-53, SOC 2, CIS Benchmarks, Zero Trust Network Architecture, MITRE ATT&CK
This job has expired