Sunrun

Staff Vulnerability Management Engineer

Sunrun

full-time

Posted on:

Location Type: Hybrid

Location: 🇺🇸 United States

Visit company website
AI Apply
Apply

Salary

💰 $150,290 - $180,348 per year

Job Level

Lead

Tech Stack

AWSAzureCloudCyber SecurityDockerGoogle Cloud PlatformKubernetesPython

About the role

  • Develop and own the enterprise vulnerability management strategy, roadmap, policies, and standards
  • Act as the subject matter expert on vulnerability threats, exploitation techniques, and mitigation strategies
  • Define the organization's risk appetite in collaboration with executive leadership
  • Mentor and guide junior engineers and analysts
  • Lead the end-to-end vulnerability management lifecycle
  • Architect, manage, and optimize vulnerability management tools
  • Drive automation and continuous improvement within the program
  • Build partnerships with Engineering, IT, DevOps, and Application Development teams
  • Develop metrics, KPIs, and KRIs to measure program effectiveness
  • Design and deliver actionable dashboards and reports for technical and executive audiences
  • Champion "shift-left" principles with DevSecOps teams

Requirements

  • 8+ years of progressive experience in cybersecurity
  • 5+ years specifically dedicated to enterprise-scale vulnerability management in hybrid environments
  • Deep, hands-on expertise with leading vulnerability scanning platforms (Tenable, Qualys, etc.)
  • Expert understanding of the vulnerability lifecycle, risk assessment, and prioritization techniques (CVSS, EPSS, CISA KEV)
  • Proficiency in assessing vulnerabilities across on-premise infrastructure, multi-cloud platforms (AWS, Azure, GCP), and container technologies (Docker, Kubernetes)
  • Exceptional leadership and communication skills
  • Bachelor’s degree in a relevant field (Computer Science, Cybersecurity, etc.) or equivalent extensive experience
  • Experience with scripting languages (Python, PowerShell)
  • Knowledge of "Security as Code" principles and CI/CD pipeline integration
  • Familiarity with compliance frameworks (PCI DSS, HIPAA, SOX, NIST)
Benefits
  • Medical/Dental/Vision Insurance
  • Life Insurance
  • Disability Insurance
  • 401k Plan + Company Match
  • Stock Purchase Plan
  • Paid Vacations/Holidays
  • Paid Baby Bonding Leave
  • Employee Discounts
  • PowerU - 100% Funded Education Programs
  • Employee Donation Matching
  • Volunteer Hour Rewards

Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard skills
vulnerability managementrisk assessmentvulnerability scanningscripting languagesvulnerability lifecycleautomationmetrics developmentdashboardsCI/CD pipeline integrationSecurity as Code
Soft skills
leadershipcommunicationmentoringcollaborationguidancepartnership buildingcontinuous improvementstrategic thinkingproblem-solvingpresentation skills
PJM Interconnection

Lead Engineer I, II

PJM Interconnection
Seniorfull-timePennsylvania · 🇺🇸 United States
Posted: 3 hours agoSource: pjm.wd5.myworkdayjobs.com
SQL
Duke Energy Corporation

Engineer II – Transmission Planning

Duke Energy Corporation
Junior · Midfull-timeFlorida · 🇺🇸 United States
Posted: 6 hours agoSource: dukeenergy.wd1.myworkdayjobs.com
Python
Kimberly-Clark

Senior Process Engineer

Kimberly-Clark
Seniorfull-time$106k–$131k / yearTexas, Wisconsin · 🇺🇸 United States
Posted: 15 hours agoSource: kimberlyclark.wd1.myworkdayjobs.com
Expleo Group

Ingeniero/a Junior Auto

Expleo Group
Juniorfull-time🇪🇸 Spain
Posted: 16 hours agoSource: expleo-jobs-es-en.icims.com