28 vulnerability engineer jobs at 23 companies in Longmont, CO

6h
Save
Mark Applied
Hide
Cyber Security Analyst & Vulnerability Management Engineer
Westminster or Centennial
$120k-$160k/yr FieldFull Time
Loenbro
Loenbro: Provides technical construction and maintenance for critical infrastructure.
5+ YOERequires 5–10+ years in cybersecurity or information security, vulnerability program management, incident response, change management, risk reporting, and infrastructure, cloud, networking, and endpoint technologies.
Tenable, CrowdStrike Falcon, Windows, Linux, Active Directory, Azure AD, Entra ID, MDR, Threat Intelligence, ticketing systems, change management systems
3w
Save
Mark Applied
Hide
Senior Cybersecurity Engineer (Remote)
San Diego or Denver or Bend or Arizona or Arkansas or Colorado or Connecticut or Delaware or Florida or Georgia or Idaho or Illinois or Indiana or Iowa or Kansas or Kentucky or Louisiana or Maine or Maryland or Massachusetts or Michigan or Minnesota or Mississippi or Missouri or Montana or Nebraska or Nevada or New Hampshire or New Jersey or New Mexico or New York or North Carolina or North Dakota or Ohio or Oklahoma or Oregon or Pennsylvania or Rhode Island or South Carolina or South Dakota or Tennessee or Utah or Vermont or Virginia or Washington or West Virginia or Wisconsin or Wyoming or Texas or Alabama
$127k-$153k/yr RemoteFull Time
SOLV Energy
SOLV EnergyNasdaq: MWH: Builds and maintains utility-scale solar and energy storage infrastructure.
7+ YOE7+ years cybersecurity experience securing cloud (Azure/Entra ID/M365) and OT/ICS, hands-on incident response, vulnerability management, and M&A security due diligence.
Azure, Microsoft 365, Microsoft Entra ID, Microsoft 365 Defender, Amazon Web Services (AWS), Microsoft Sentinel, Splunk, IBM QRadar, PowerShell, Python, KQL, MITRE ATT&CK
3w
Save
Mark Applied
Hide
Cybersecurity Assessment Engineer
Washington or Maryland or Virginia or Raleigh or Durham or Chapel Hill or Denver or Colorado Springs or Dallas or Fort Worth
$125k-$140k/yr RemoteFull Time
Second Front Systems
Second Front Systems: Secure cloud hosting and automated compliance for government software.
3+ YOE3+ years cybersecurity experience; hands-on cloud and DevSecOps knowledge; familiarity with NIST RMF/SP 800-53, FedRAMP, vulnerability analysis, and authorization artifacts; ability to attain DoD 8570 IAT II (CYSA+ preferred).
Anchore, Trivy, Tenable, Docker, GitLab, Kubernetes, Python, Bash, AWS, Azure, GCP
2w
Save
Mark Applied
Hide
AWS Security Engineer - Senior Associate
New York City or Tampa or Denver or Chicago or Boston or Cleveland or Philadelphia or Houston
$77k-$202k/yr OnsiteFull Time
PwC
PwC: Providing audit, tax, and management consulting services to businesses.
2+ YOEBachelor's degree required, minimum 2 years' experience, proficiency with AWS CloudFormation, Terraform, Ansible, Puppet, GitHub, Jenkins, and Python; security incident management and vulnerability assessment experience.
AWS CloudFormation, Terraform, Ansible, Puppet, GitHub, Jenkins, Python
2mo
Save
Mark Applied
Hide
Cyber Security Engineer Technical Lead
Littleton, Colorado, United States
$124k-$218k/yr OnsiteFull Time
Lockheed Martin
Lockheed MartinNYSE: LMT: Designs and manufactures global security and aerospace systems.
TS/SCI clearance and US citizenship required; DoD 8570 IAM/IAT II certifications; experience in satellite and ground operations, RMF/ATO processes, SOC operations, vulnerability scanning/EVSS, DoD cybersecurity standards, SIEM, RHEL/Windows, and incident response.
NetBrain, Zenoss, Hewlett Packard Network Automation (HPNA), eMASS, HBSS, ACAS, SCAP Compliance Checker (SCC), DISA STIGs, EVSS, RHEL, Windows Server, SIEM, LogRhythm, Splunk, Jira, Confluence
1mo
Save
Mark Applied
Hide
Engineer - Cybersecurity
Denver, Colorado, United States
$100k-$133k/yr OnsiteFull Time
Frontier Airlines
Frontier AirlinesNasdaq: ULCC: Provides low-fare passenger air transportation services across the Americas.
6+ YOEBachelor's in CS/technology or equivalent, 6+ years cybersecurity engineering experience, 4+ years with EDR, SEGs, vulnerability management and SIEM, cloud (Azure/AWS) security, industry cert (CISSP, Security+, etc.) required or to be attained within 3 months.
DLP, SIEM, SOAR, EDR, SentinelOne, CrowdStrike, Cylance, Mimecast, Proofpoint, Microsoft Office365 Exchange, Nessus, Qualys, Rapid7, Splunk, LogRhythm, Wireshark, NMAP, Azure, AWS, Windows
1w
Save
Mark Applied
Hide
Senior Security Engineer
Lafayette, Colorado, United States
$110k-$130k/yr RemoteFull Time
KPA
KPA: Provides EHS software and workforce compliance consulting services.
5+ YOE5+ years security engineering experience; strong cloud, identity, endpoint, vulnerability management, incident response, and DevSecOps skills; PowerShell/Python scripting; SOC 2/NIST familiarity; excellent communication and leadership.
CrowdStrike, Rapid7, InsightIDR, InsightVM, InsightAppSec, MDR, Cisco Umbrella, Cisco Duo, KnowBe4, Cisco Meraki, VPN, Azure, AWS, Microsoft 365, Entra ID, AWS Identity Center, Auth0, SSO, SCIM, Conditional Access, PIM, Snyk, SendGrid, Amazon SES, SPF, DKIM, DMARC, PowerShell, Python, Microsoft Graph, REST APIs, ChatGPT Enterprise, Claude, MCP, Kubernetes
2d
Save
Mark Applied
Hide
Senior Corporate Security Engineer
Bellevue or Menlo Park or New York City or Washington or Denver or Westlake or Chicago or Lake Mary or Clearwater or Gainesville
$166k-$195k/yr HybridFull Time
Robinhood
RobinhoodNASDAQ: HOOD: Provides a commission-free platform for investing and financial services.
5+ YOERequires 5+ years in information security spanning security engineering, systems administration, and enterprise infrastructure; cloud, AI tooling, identity systems, vulnerability management, and automation experience.
Okta, OpenAI, Claude, Cursor, Google Cloud Platform
2mo
Save
Mark Applied
Hide
Senior Cybersecurity Engineer
Princeton or Boulder
$121k-$147k/yr OnsiteFull Time
SciTec
SciTec: Provides advanced remote sensing and missile defense technology solutions.
6+ YOEBachelor's in a related field, CySa+ (or similar), 6+ years cybersecurity engineering, 2+ years CrowdStrike EDR/NG-SIEM experience, NIST 800-171/CMMC, vulnerability scanning, Linux/Windows/AD/IAM, scripting (Python, PowerShell, Bash), DoD clearance eligible.
CrowdStrike EDR, CrowdStrike NG-SIEM, SIEM, Tenable, NinjaOne, AWS, Azure, Python, PowerShell, Bash, NIST 800-171, CMMC, Active Directory, IAM, DevSecOps
3w
Save
Mark Applied
Hide
Intermediate Cyber Security Engineer
Cedar Rapids or Denver or Philadelphia
$70k-$84k/yr HybridFull Time
Transamerica
TransamericaNYSE: AEG: Provides insurance, retirement solutions, and investment products to customers.
1+ YOE1+ years cyber security engineering experience; knowledge of application security, vulnerability management, SDLC, and security frameworks; bachelor’s in related field or equivalent; certifications desirable (OSCP,CISSP,CEH,Security+/CySA/CASP).
NIST CSF, SIEM, Rapid7, ServiceNow Vulnerability Response (VR), Synk, CrowdStrike, ServiceNow, JIRA
4w
Save
Mark Applied
Hide
Senior Offensive Security Engineer - Pentester
Denver or Washington or Seattle or Charlotte or Jacksonville or Jersey City or Chicago
$160k-$205k/yr OnsiteFull Time
Bank of America
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOE5+ years offensive security experience, proficiency with pentesting tools, strong understanding of networks/OS/Active Directory, ability to code (Python/Java/C#), report vulnerabilities, mentor junior engineers.
Burp Suite, Metasploit, nmap, Python, Java, C#
1mo
Save
Mark Applied
Hide
Project Cyber Engineer
Aurora, Colorado, United States
$145k-$241k/yr OnsiteFull Time
Deloitte
Deloitte: Provides professional audit, consulting, advisory, and tax services.
3+ YOEBachelor's degree and 3+ years experience, active TS/SCI or SCI eligibility, onsite Aurora CO 5 days/week, experience with identity and access management, network management, NIST RMF, and vulnerability management.
5d
Save
Mark Applied
Hide
Slalom Flex (Project Based) – CI/CD Infrastructure Software Engineer - DevSecOps Operations
Centennial or Denver
$85-$94/hr OnsiteContract
Slalom
Slalom: Provides business and technology consulting and software engineering services.
3+ YOERequires 3–5+ years in DevOps, software engineering, cybersecurity, or cloud operations; CI/CD and DevSecOps experience; troubleshooting skills; and familiarity with vulnerability management, cloud, containers, and automation.
GitLab, JFrog Artifactory, XRay, SonarQube, AWS, Kubernetes, Amazon EKS, Bash, Python, PowerShell, Terraform, CloudFormation, Ansible, CMMC, NIST
1w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Boston or Chicago or Dallas or Houston or Englewood or Raleigh or New York or Southfield or Washington or Toronto or Calgary
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides independent credit ratings, market benchmarks, and financial analytics.
8+ YOE8+ years in information security focused on penetration testing, vulnerability management and application/cloud security; offensive security certification required; strong scripting skills and ability to communicate findings.
Burp Suite, Nessus, Metasploit, Nmap, MITRE ATT&CK, Bash, Python, Go, PowerShell, JavaScript, DAST, SAST, SCA, AWS, Azure, GCP
2w
Save
Mark Applied
Hide
Cyber Security Engineer III
Denver, Colorado, United States
OnsiteFull Time
Cherokee Federal
Cherokee Federal: Provides specialized professional and technical services to federal government agencies.
Perform RMF/FISMA activities, maintain SSPP and security artifacts, conduct continuous monitoring, vulnerability assessments, POA&M management, incident response support, and provide cybersecurity briefings.
Bison GRC, Xacta 360, GIS
3w
Save
Mark Applied
Hide
Information Systems Security Engineer
King of Prussia or Aurora
$75k-$158k/yr OnsiteFull Time
CACI
CACINYSE: CACI: Provides information technology and professional services to government clients.
5+ YOELead RMF lifecycle, manage NIST 800-53/171 controls, perform vulnerability assessments, maintain ATOs, and provide cloud security oversight for AWS/Azure.
Xacta, SNOW, Nessus, Splunk, Anchore, AWS, Azure
1mo
Save
Mark Applied
Hide
Technology Engineer - JAVA/.NET/Security Code Review
Pittsburgh or Strongsville or Denver or Phoenix or Birmingham or Dallas or Cleveland or Lakewood
$86k-$158k/yr OnsiteFull Time
PNC Financial Services
PNC Financial ServicesNYSE: PNC: Provides banking, lending, and investment services to customers.
3+ YOE3+ years of software development experience, proficiency in Java and/or .NET, application security knowledge (OWASP Top 10), vulnerability triage/remediation, SDLC security, strong communication skills.
Java, .NET, OWASP Top 10, Interactive Application Security Testing (IAST)
1mo
Save
Mark Applied
Hide
Sr. Application Security Engineer
Denver, Colorado, United States
$130k-$165k/yr HybridFull Time
Vertafore
VertaforeNYSE: ROP: Provides cloud-based software solutions for the insurance industry.
7+ YOE7+ years in application/product/cloud security; Bachelor's in relevant field or equivalent experience; hands-on experience with threat modeling, secure SDLC, vulnerability management, CI/CD security, cloud (AWS/Azure), API and AI security; strong communication skills.
SAST, DAST, SCA, IaC scanning, container scanning, API security testing, secrets scanning, AI runtime scanning, WAF, CNAPP, CSPM, CI/CD, SIEM, AWS, Azure, OWASP ASVS, NIST CSF, NIST SSDF, OWASP SAMM
1w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Calgary or Toronto or Englewood or Chicago or Raleigh or New York or Dallas or Houston
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides financial data, analytics, and credit ratings worldwide.
8+ YOE8+ years information security experience focused on penetration testing, application/cloud security, vulnerability management; offensive security certification required; scripting (Bash, Python, Go, PowerShell, JavaScript); experience with DAST/SAST/SCA and CI/CD integration; bachelor's degree or equivalent.
Burp Suite, Nessus, Metasploit, Nmap, OWASP Top 10, MITRE ATT&CK, DAST, SAST, SCA, Bash, Python, Go, PowerShell, JavaScript, AWS, Azure, GCP
1w
Save
Mark Applied
Hide
AI Security Engineer, AI Security Unit
Denver or California
RemoteFull Time
Check Point Software Technologies
Check Point Software TechnologiesNASDAQ: CHKP: Provides network, cloud, and mobile cybersecurity solutions.
Offensive security and red teaming experience against AI systems, knowledge of LLM vulnerabilities and threat modeling, ability to develop automated tooling, client-facing delivery and strong technical writing.
OWASP Top 10 for LLM Applications, OWASP Top 10 for Agentic Applications, MITRE ATLAS, Model Context Protocol (MCP)