1,218 vulnerability engineer jobs at 662 companies in United States
3w
Save
Mark Applied
Hide
3w
Vulnerability Engineer
Washington, District of Columbia, United States
$100k-$130k/yrHybridFull Time
BDR Solutions: Service-disabled veteran-owned small IT services firm modernizing health, social-service, and disaster-relief systems for U.S. federal agencies.
7+ YOEUS citizen with active Top Secret clearance, 7+ years managing Windows servers and vulnerability remediation, bachelor's in networking/cybersecurity, proficiency with AD, SQL Server, SCCM, Nessus and BigFix, scripting (PowerShell, Python, Azure/AWS CLI).
Tenable Nessus, BigFix, Microsoft Active Directory, SQL Server, System Center Configuration Manager (SCCM), PowerShell, Azure CLI, AWS CLI, Python, VBScript, Microsoft Excel, Microsoft PowerPoint, Microsoft Visio, Microsoft Word, Ansible
CapgeminiEuronext Paris: CAP: Global leader in consulting, digital transformation, and engineering services.
Engineering leader to engage executives, lead engineering teams, drive delivery and code, enable AI/GenAI adoption, SRE transformation, SDLC modernization, and provide hands-on technical guidance.
7+ YOERequires 7+ years in software security, open source maintenance, or vulnerability disclosure; responsible disclosure expertise; scalable process automation; open source community experience; and standards-body coordination.
Python, Java, JavaScript, Go, Chainguard Images, Linux Foundation, CISA, CVE
United States or Centreville or Chantilly or Herndon
$148k-$267k/yrHybridFull Time
ParsonsNYSE: PSN: Technology and engineering solutions for defense and infrastructure.
10+ YOEBachelor's degree and 10+ years related experience (master's may substitute), 10+ years programming (Python,C,C++), 5+ years vulnerability research, ability to obtain TS/SCI, U.S. citizenship required.
Python, C, C++, x86, ARM, MIPS, Windows, Linux, CI / CD Pipelines, Git
The Pennsylvania State University: A public, land-grant research university based in Pennsylvania.
3+ YOEExperience in reverse engineering, vulnerability research, exploit development, and cyber operations; TS/SCI clearance required; bachelor's degree and 3+ years experience (senior level up to 6+).
Ghidra, IDA, Kali Linux, Angr, AFL++, QEMU, Unicorn, JIRA, Confluence
CACINYSE: CACI: Provider of specialized IT and mission-critical government services.
6+ YOEU.S. citizenship, bachelor's degree plus 6 years of vulnerability management and cybersecurity experience, Qualys expertise, scanning-tool experience, risk analysis, and vulnerability prioritization skills.
Qualys, dbProtect, WebInspect, Tenable, Tableau, Power BI, Splunk, DISA STIGs
SoFiNasdaq Global Select Market: SOFI: Public U.S. digital financial-services helping members borrow, save, spend, invest, and protect their money.
Deep vulnerability management and security engineering expertise; strong software engineering skills in Python/Go/JavaScript/TypeScript; experience with cloud, containers, SBOMs, and vulnerability tooling; ability to lead technical initiatives and incident response.
CognizantNASDAQ: CTSH: Global professional services providing technology and consulting services.
5+ YOERequires 5–10 years of cybersecurity experience, including 3+ years in vulnerability management, security operations, or cyber risk; expertise with vulnerability tools, risk prioritization, reporting, and remediation coordination.
NelnetNew York Stock Exchange: NNI: Public diversified holding providing student-loan servicing, education technology, payment processing, government services, and consumer lending.
2+ YOERequires 2+ years in vulnerability management or security operations, Python, vulnerability scanning and patching tools, EDR administration, cloud security knowledge, and a cybersecurity or information systems degree or relevant experience.
Rapid7, Qualys, Tenable, Microsoft MECM, Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Networks Cortex XDR, Tanium, Azure, AWS, GCP, Python
SAS: Global leader in analytics, AI, and data management software.
5+ YOEUS citizen required; 5+ years information security experience; Bachelor’s in CS/Engineering or equivalent; hands-on Tenable/Rapid7/Qualys; vulnerability management and remediation experience; programming (Python/Perl/Bash) and ServiceNow familiarity.
1Password: Canadian identity-security software providing password, secrets, and access-management tools for businesses and consumers.
5+ YOE5+ years security/engineering experience with incident response, coordinated vulnerability disclosure, strong communication, code-reading for forensics, and experience applying AI/ML to security workflows.
Southern CompanyNew York Stock Exchange: SO: Public American electric and natural-gas utility holding serving homes and businesses through subsidiaries.
3+ YOERequires 3+ years in enterprise technology support or related disciplines, Windows endpoint experience, troubleshooting, communication, coordination, and organizational skills. Bachelor's degree preferred.
Microsoft Windows, Microsoft Intune, MECM/SCCM, Microsoft Configuration Manager, PowerShell, Excel, Power BI, ServiceNow, Helix, Remedy, Tenable, Qualys, Rapid7, CrowdStrike Spotlight, Tanium, Microsoft Defender Vulnerability Management, Delinea Privilege Manager, BeyondTrust, CyberArk Endpoint Privilege Manager, Microsoft Endpoint Privilege Management, NIST, CIS, Zero Trust, CVSS, CISA Known Exploited Vulnerabilities, Microsoft 365 Certified: Endpoint Administrator Associate (MD-102), Microsoft Certified: Security Operations Analyst Associate (SC-200), Microsoft Certified: Power BI Data Analyst Associate (PL-300), CompTIA Security+, CompTIA CySA+, ITIL Foundation, Microsoft Security, Azure
CACINYSE: CACI: Provider of specialized IT and mission-critical government services.
6+ YOEBachelor's degree plus 6 years of vulnerability management and cybersecurity experience; U.S. citizenship, Qualys expertise, scanning-tool experience, risk analysis, and strong analytical skills required.
Qualys, dbProtect, Webinspect, Tenable, Tableau, Microsoft Power BI, Splunk
CognizantNASDAQ: CTSH: Global professional services providing technology and consulting services.
3+ YOERequires 5–10 years of cybersecurity experience, including 3+ years in vulnerability management, security operations, or cyber risk; hands-on assessment, remediation, risk prioritization, reporting, and stakeholder coordination.
CognizantNASDAQ: CTSH: Global professional services providing technology and consulting services.
5+ YOERequires 5–10 years of cybersecurity experience, including 3+ years in vulnerability management, security operations, or cyber risk; hands-on assessment, remediation, risk prioritization, reporting, and stakeholder coordination.
Tenable.io, Tenable.sc, Qualys VMDR, Rapid7 InsightVM, ServiceNow Vulnerability Response, Wiz, Prisma Cloud, Microsoft Defender Vulnerability Management, Microsoft Power BI, Tableau, Jira, ServiceNow, Python, PowerShell, Bash
Pune or Milpitas or Seattle or Princeton or Cape Town or London or Zurich or Singapore or Mexico City or North America or Europe or Africa or Asia
RemoteFull Time
ZensarNSE: ZENSARTECH: Experience-led digital solutions and engineering services.
4+ YOEBachelor's degree in a related field and 4–10 years of vulnerability management, Windows infrastructure, cybersecurity operations, or endpoint security experience; requires enterprise remediation, risk assessment, and Windows security expertise.
Qualys, Tenable, Rapid7, Microsoft Defender Vulnerability Management, Windows Server, Windows 10/11, Microsoft Defender for Endpoint, SCCM/MECM, Microsoft Intune, Active Directory, Group Policy, Entra ID (Azure AD), DNS, DHCP, CVSS, Common Vulnerabilities and Exposures (CVE), CIS Benchmarks, NIST, ISO 27001, PowerShell, Azure
MaximusNYSE: MMS: Government services and health administration partner for public programs.
10+ YOEActive TS/SCI clearance, Bachelor’s in CS/Cybersecurity, 10+ years vulnerability research, DoD 8140 certifications (CISA, CSM, GCIH, GSNA) and proficiency with reverse engineering and exploit development.
CloudflareNYSE: NET: Cloud-based security, performance, and reliability services for Internet applications.
5+ YOERequires 5+ years of vulnerability management experience in a senior or lead capacity, vulnerability scanning platforms, risk scoring, AI workflow development, audit support, and strong communication skills.
Bowhead Weapons Development Solutions (BWDS): Alaska Native 8(a) defense contractor providing weapons research, testing, sustainment, cybersecurity, and program-management services to federal agencies.
BS in engineering/physics, proficiency in 3D modeling, programming/scripting, analytical mechanics/materials knowledge, experience with vulnerability/lethality analysis and classified program work; ability to obtain Secret clearance.
Northrop GrummanNYSE: NOC: Global aerospace and defense technology.
3+ YOERequires STEM bachelor's +5 yrs or master's +3 yrs, U.S. Secret security clearance, experience with vulnerability analysis tools (COVART/AJEM), NX model construction, JMP/DOE, live fire testing and VAR authoring.
COVART, AJEM, NX, JMP, Amesim, LS-Dyna, Designs of Experiment (DOE)