Cloudflare4 days ago
Lead Vulnerability Management Engineer
Salary not specified
MARKET
13,534 ₽median for this role
Tech Lead / Team Lead · 166 jobs with disclosed pay
5,250half of the offers: 9,771–18,1061.2 млн
The employer didn't disclose pay — compare with the market yourself.
Hybrid
Responsibilities
- 01Serve as the primary technical lead for the Vulnerability Management team, providing architectural guidance and mentoring team members on complex technical challenges.
- 02Lead the architecture, systems design, technology evaluation, and systems integration for the global VM program, ensuring tooling is effectively embedded across the technology stack.
- 03Oversee and conduct advanced vulnerability scanning, performing in-depth validation of findings to verify accuracy, filter false positives, and lead the triage and prioritization of critical risks.
- 04Collaborate closely with technology owners and establish strong, trust-based relationships with engineering teams to drive the remediation or mitigation of complex vulnerabilities.
- 05Strategically manage and track the remediation backlog, maintaining a high-level view of risk reduction progress and reporting on systemic security trends.
- 06Design and implement AI-driven solutions to manage the vulnerability lifecycle and automate repetitive operational tasks within the vulnerability management domain.
- 07Contribute to the continuous improvement of global vulnerability management standards, procedures, and playbooks.
- 08Act as the primary technical liaison for the GRC team, translating complex technical vulnerabilities and mitigations into clear compliance context to support continuous readiness for audits (e.g., SOC-2, PCI-DSS, FedRAMP).
- 09Own the technical reporting and evidence generation process for internal and external audits, ensuring scanning cadences and remediation workflows consistently meet or exceed compliance baselines.
- 10Interpret evolving regulatory and compliance requirements into actionable technical scanning policies, ensuring newly mandated checks are quickly integrated into the active scanning program
Requirements
- 01Solid understanding of modern security frameworks (e.g., SOC-2, NIST, PCI) and their application in enterprise environments.
- 025+ years of Vulnerability Management experience, with a proven track record in a senior or lead technical capacity.
- 03Bachelor's degree in Computer Science, Information Security, or security certifications in a related field.
- 04Strong communication (written and verbal) and interpersonal skills, with the ability to effectively collaborate with technical and non-technical teams.
- 05A strong understanding of vulnerability risk scoring (e.g., CVSS, EPSS) and how to apply these risk assessment methodologies in a business context to support remediation.
- 06Hands-on experience with vulnerability scanning platforms (e.g., Qualys, Nessus, Rapid7 InsightVM).
- 07Strong analytical skills to identify patterns in data and distinguish between theoretical risk and actual exploitability.
- 08Demonstrated experience using AI to develop and manage complex workflows and applications.
- 09Proven experience supporting GRC or external audit cycles (e.g., PCI-DSS, SOC-2, ISO 27001) by providing technical evidence, explaining compensating controls, or articulating risk-acceptance justifications.
- 10The ability to translate high-level compliance policies and regulatory requirements into precise, technical vulnerability scanning configurations and remediation SLAs.
- 11Bonus points: Experience with scripting languages (e.g., Python) for automation.
- 12Experience with specific AI-development tooling such as Opencode or Windsurf.
- 13Proficiency in usi
What we offer
- 01Available Locations: Austin, TX
- 02May require flexibility to be on-call outside of standard working hours to address technical issues as needed.