Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Workstreet

Vulnerability Management Engineer

Workstreet

Vulnerability Management Engineer providing consultative security services by identifying and remediating vulnerabilities for fast-growth startups. Hands-on role requiring expertise in cloud platforms like AWS, Azure, and GCP.

Posted 7/21/2026full-timeRemote • 🇵🇭 PhilippinesMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in orchestrating vulnerability scanning infrastructure and executing threat analysis while ensuring compliance with regulatory frameworks. Capable of translating technical vulnerabilities into actionable guidance and fostering collaborative remediation efforts with client teams.

Highest-signal resume keywords
Vulnerability Scanning Infrastructure ManagementRisk Prioritization Using CVSS and EPSSThreat Analysis and False Positive ValidationRegulatory Compliance Auditing (SOC 2, ISO 27001, HIPAA, CMMC)Client Relationship Management and Communication

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability Discovery Platforms (Tenable/Nessus, Qualys, Rapid7 InsightVM, Vanta)Advanced Risk Scoring ArchitecturesData Analysis and Threat Metrics ConversionInfrastructure Posture AuditingAutomated Infrastructure Scanning Protocols
Soft Skills
Stakeholder DiplomacyClear Business CommunicationProject Management
Industry Keywords
Vulnerability ManagementThreat IntelligenceCloud SecurityConfiguration WeaknessesContinuous Monitoring

Tech Stack

Tools & technologies
Cloud

About the role

Key responsibilities & impact
  • Orchestrate Vulnerability Scanning Infrastructure: Configure, schedule, and maintain authenticated credentials, scan policies, and asset groups across client networks and cloud-native environments using enterprise platforms (Tenable/Nessus, Qualys, Rapid7 InsightVM, and Vanta).
  • Execute Threat Analysis and Risk Prioritization: Evaluate raw scan outputs and filter false positives; apply advanced risk-based prioritization data utilizing CVSS base scores, EPSS real-time exploit indices, global threat intelligence feeds, and critical client asset contexts.
  • Drive Collaborative Remediation and Governance: Translate technical vulnerabilities into clear, actionable architectural guidance and patch-management workflows; partner directly inside the trenches with client software engineers and IT teams to multi-thread remediation efforts and accelerate their sub-30-day time-to-remediate velocity.
  • Manage Exceptions and Audit Compliance: Document, verify, and track formal client requests for temporary vulnerability exceptions or long-term risk acceptances; map operational patching data directly to control evidence required for regulatory audits (SOC 2, ISO 27001, HIPAA, CMMC, and NIST).
  • Own the Advisory Client Experience: Act as the strategic primary point of contact and trusted security advisor for an assigned portfolio of fast-growth startups; deliver regular project milestones, handle high-priority technical escalations with calm professionalism, and generate regular status reports and executive summaries that communicate technical risk as clear business value.

Requirements

What you’ll need
  • Proven enterprise vulnerability engineer - Command direct operational execution configuring, deploying, and maintaining industry-leading vulnerability discovery platforms, explicitly leveraging Tenable/Nessus, Qualys, Rapid7 InsightVM, or Vanta.
  • Surgical risk prioritizer - Mastered advanced risk scoring architectures including CVSS base scores and EPSS real-time exploit probability indices to isolate, rank, and target high-consequence threats.
  • Precision threat analyst - Deconstructed massive raw scanning datasets, systematically validated results to eliminate false positives, and converted intricate technical threat data into clear business risk metrics.
  • Advanced infrastructure posture auditor - Diagnosed, categorized, and cataloged diverse vulnerability classes, cloud/container exposure vectors, active exploit mechanisms, and configuration weaknesses across distributed system architectures.
  • GRC architecture strategist - Aligned automated infrastructure scanning protocols directly against regulatory compliance frameworks, specifically matching continuous monitoring records to strict audit evidence controls for SOC 2, ISO 27001, HIPAA, and CMMC.
  • High-velocity technical consultant - Engineered clear technical blueprints, structured project milestones, and progress matrices while simultaneously orchestrating deliverables across an active portfolio of client accounts.
  • Elite stakeholder diplomat - Built immediate trust and drove technical risk calibrations directly with US-based tech founders, engineering executives, and corporate leaders using clear, business-friendly communication.

Benefits

Comp & perks
  • Career Development: Clear path with mentorship and training opportunities
  • Technical Training: Comprehensive onboarding on security and compliance frameworks
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.