Cloudflare4 days ago

Lead Vulnerability Management Engineer

Salary not specified
MARKET
13,534median for this role
Tech Lead / Team Lead · 166 jobs with disclosed pay
5,250half of the offers: 9,771–18,1061.2 млн
The employer didn't disclose pay — compare with the market yourself.
Hybrid

Responsibilities

  • 01Serve as the primary technical lead for the Vulnerability Management team, providing architectural guidance and mentoring team members on complex technical challenges.
  • 02Lead the architecture, systems design, technology evaluation, and systems integration for the global VM program, ensuring tooling is effectively embedded across the technology stack.
  • 03Oversee and conduct advanced vulnerability scanning, performing in-depth validation of findings to verify accuracy, filter false positives, and lead the triage and prioritization of critical risks.
  • 04Collaborate closely with technology owners and establish strong, trust-based relationships with engineering teams to drive the remediation or mitigation of complex vulnerabilities.
  • 05Strategically manage and track the remediation backlog, maintaining a high-level view of risk reduction progress and reporting on systemic security trends.
  • 06Design and implement AI-driven solutions to manage the vulnerability lifecycle and automate repetitive operational tasks within the vulnerability management domain.
  • 07Contribute to the continuous improvement of global vulnerability management standards, procedures, and playbooks.
  • 08Act as the primary technical liaison for the GRC team, translating complex technical vulnerabilities and mitigations into clear compliance context to support continuous readiness for audits (e.g., SOC-2, PCI-DSS, FedRAMP).
  • 09Own the technical reporting and evidence generation process for internal and external audits, ensuring scanning cadences and remediation workflows consistently meet or exceed compliance baselines.
  • 10Interpret evolving regulatory and compliance requirements into actionable technical scanning policies, ensuring newly mandated checks are quickly integrated into the active scanning program

Requirements

  • 01Solid understanding of modern security frameworks (e.g., SOC-2, NIST, PCI) and their application in enterprise environments.
  • 025+ years of Vulnerability Management experience, with a proven track record in a senior or lead technical capacity.
  • 03Bachelor's degree in Computer Science, Information Security, or security certifications in a related field.
  • 04Strong communication (written and verbal) and interpersonal skills, with the ability to effectively collaborate with technical and non-technical teams.
  • 05A strong understanding of vulnerability risk scoring (e.g., CVSS, EPSS) and how to apply these risk assessment methodologies in a business context to support remediation.
  • 06Hands-on experience with vulnerability scanning platforms (e.g., Qualys, Nessus, Rapid7 InsightVM).
  • 07Strong analytical skills to identify patterns in data and distinguish between theoretical risk and actual exploitability.
  • 08Demonstrated experience using AI to develop and manage complex workflows and applications.
  • 09Proven experience supporting GRC or external audit cycles (e.g., PCI-DSS, SOC-2, ISO 27001) by providing technical evidence, explaining compensating controls, or articulating risk-acceptance justifications.
  • 10The ability to translate high-level compliance policies and regulatory requirements into precise, technical vulnerability scanning configurations and remediation SLAs.
  • 11Bonus points: Experience with scripting languages (e.g., Python) for automation.
  • 12Experience with specific AI-development tooling such as Opencode or Windsurf.
  • 13Proficiency in usi

What we offer

  • 01Available Locations: Austin, TX
  • 02May require flexibility to be on-call outside of standard working hours to address technical issues as needed.