Job Description
Title: Senior Vulnerability Management Engineer – US Remote
Location: United States – Remote
Type: Full-time
Workplace: remote
Job Description:
We are looking for a Senior Vulnerability Management Engineer who can navigate complex threat scenarios and remain committed to decreasing the overall attack surface of the company. Infrastructure Vulnerability Management remains a top priority at Guidewire, and you will be responsible for implementing and managing enterprise vulnerability tools and processes in a cloud environment, to reduce technical and business risks due to vulnerabilities and misconfigurations. This includes identifying and evaluating vulnerabilities, misconfigurations and supporting remediation activities.
Responsibilities
- Management, operation, and enhancement of vulnerability management, cloud posture management and container security tools.
- Provide security guidance to Cloud Engineering teams encompassing perimeter, misconfigurations, asset visibility, policies, container, patching cadence, and vulnerability scanning. Partner with cloud architecture, engineering and application development teams to establish and maintain comprehensive visibility into potential risk events across a large scale cloud environment.
- Improve and mature vulnerability reporting to key stakeholders, and drive remediation efforts by communicating, clearly articulating, and prioritizing risk and impact to all stakeholders to convey the urgency and need to remediate a vulnerability/misconfiguration.
- Develop processes and automation by engaging with stakeholders to harden and deploy AMI and docker container images.
- Stay abreast of emerging threats, and promote understanding of associated risk with stakeholders by reviewing and analyzing vulnerability data to identify trends and patterns.
- Supporting compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks.
- Partner with the leadership team to report program roadmap status, define Key Risk Indicators and automated dashboards presenting risks and KPIs.
Requirements
- Knowledge of vulnerability scoring systems and prioritization techniques (CVSS, EPSS, SSVC, etc.)
- Experience with cloud specific tooling such as Cloud Security Posture Management (CSPM), Cloud Workload Protection Platform (CWPP) and Cloud Native Application Protection Platform (CNAPP).
- Thorough understanding of enterprise security controls, cloud security, network protocols and operating system (Windows/Linux/MAC).
- Familiar with best practices in securing Kubernetes and have a firm grasp on the challenges and solutions around securing containers and K8 clusters.
- Hands-on experience handling vulnerability management operations for cloud workloads at scale in AWS/Azure/GCP.
- Ability to conduct thorough analysis, automate redundant processes using scripting languages (Python or similar languages) and recommend data driven actions.
- Results-oriented, high energy, self-motivated and love for a team environment.