Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Workstreet

Vulnerability Management Engineer

Workstreet

Vulnerability Management Engineer for Workstreet assisting startups in managing cybersecurity risks. Focusing on hands-on vulnerability identification, prioritization, and remediation within client environments.

Posted 7/21/2026full-timeRemote • 🇮🇳 IndiaMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in orchestrating vulnerability scanning infrastructure and executing threat analysis, with a strong focus on risk prioritization and compliance with regulatory frameworks. Proven ability to translate technical vulnerabilities into actionable guidance while maintaining effective communication with stakeholders.

Highest-signal resume keywords
Vulnerability Scanning Infrastructure ManagementRisk Prioritization Using CVSS and EPSSThreat Analysis and False Positive ValidationRegulatory Compliance Frameworks (SOC 2, ISO 27001, HIPAA, CMMC)Cloud-Native Security Engineering

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability Discovery Platforms (Tenable/Nessus, Qualys, Rapid7 InsightVM, Vanta)Advanced Risk Scoring ArchitecturesPatch Management PipelinesTechnical Change Management WorkflowsCloud Security Configuration (AWS, GCP, Azure)
Soft Skills
Stakeholder CommunicationCollaborative RemediationClient Relationship ManagementTechnical Escalation HandlingTrust Building
Tools & Technologies
CVSSEPSSNational Vulnerability Database (NVD)Threat Intelligence FeedsContinuous Monitoring Records
Certifications & Qualifications
CompTIA Security+Certified Ethical Hacker (CEH)Tenable Certified Security AssociateGIAC GEVA
Industry Keywords
Vulnerability ManagementThreat AnalysisRegulatory ComplianceCloud-Native EnvironmentsManaged Service Provider (MSP/MSSP)

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityGoogle Cloud Platform

About the role

Key responsibilities & impact
  • Orchestrate Vulnerability Scanning Infrastructure: Configure, schedule, and maintain authenticated credentials, scan policies, and asset groups across client networks and cloud-native environments using enterprise platforms (Tenable/Nessus, Qualys, Rapid7 InsightVM, and Vanta).
  • Execute Threat Analysis and Risk Prioritization: Evaluate raw scan outputs and filter false positives; apply advanced risk-based prioritization data utilizing CVSS base scores, EPSS real-time exploit indices, global threat intelligence feeds, and critical client asset contexts.
  • Drive Collaborative Remediation and Governance: Translate technical vulnerabilities into clear, actionable architectural guidance and patch-management workflows; partner directly inside the trenches with client software engineers and IT teams to multi-thread remediation efforts and accelerate their sub-30-day time-to-remediate velocity.
  • Manage Exceptions and Audit Compliance: Document, verify, and track formal client requests for temporary vulnerability exceptions or long-term risk acceptances; map operational patching data directly to control evidence required for regulatory audits (SOC 2, ISO 27001, HIPAA, CMMC, and NIST).
  • Own the Advisory Client Experience: Act as the strategic primary point of contact and trusted security advisor for an assigned portfolio of fast-growth startups; deliver regular project milestones, handle high-priority technical escalations with calm professionalism, and generate regular status reports and executive summaries that communicate technical risk as clear business value.

Requirements

What you’ll need
  • Proven enterprise vulnerability engineer - Command direct operational execution configuring, deploying, and maintaining industry-leading vulnerability discovery platforms, explicitly leveraging Tenable/Nessus, Qualys, Rapid7 InsightVM, or Vanta.
  • Surgical risk prioritizer - Mastered advanced risk scoring architectures including CVSS base scores and EPSS real-time exploit probability indices to isolate, rank, and target high-consequence threats.
  • Precision threat analyst - Deconstructed massive raw scanning datasets, systematically validated results to eliminate false positives, and converted intricate technical threat data into clear business risk metrics.
  • Advanced infrastructure posture auditor - Diagnosed, categorized, and cataloged diverse vulnerability classes, cloud/container exposure vectors, active exploit mechanisms, and configuration weaknesses across distributed system architectures.
  • GRC architecture strategist - Aligned automated infrastructure scanning protocols directly against regulatory compliance frameworks, specifically matching continuous monitoring records to strict audit evidence controls for SOC 2, ISO 27001, HIPAA, and CMMC.
  • High-velocity technical consultant - Engineered clear technical blueprints, structured project milestones, and progress matrices while simultaneously orchestrating deliverables across an active portfolio of client accounts.
  • Elite stakeholder diplomat - Built immediate trust and drove technical risk calibrations directly with US-based tech founders, engineering executives, and corporate leaders using clear, business-friendly communication.
  • Orchestration of patch management pipelines - Proven history managing full-lifecycle patch deployments, technical change management workflows, and remediation sequences alongside distributed IT, DevOps, and software engineering teams within a managed service provider (MSP/MSSP) or consulting environment.
  • Credentialed cybersecurity specialist - Hold active, validated professional industry markers such as CompTIA Security+, CEH, Tenable Certified Security Associate, or GIAC GEVA.
  • Cloud-native security engineering - Direct exposure mapping, configuring, and defending cloud-native vulnerability surfaces across public multi-cloud public hosting platforms, explicitly AWS, GCP, and Azure environments.
  • Command of threat intelligence syndication - Advanced navigation of the CVE lifecycle, National Vulnerability Database (NVD) registries, and active threat feed integrations to intercept and anticipate real-world exploits.

Benefits

Comp & perks
  • Career Development: Clear path with mentorship and training opportunities
  • Technical Training: Comprehensive onboarding on security and compliance frameworks
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.