Vulnerability Management Engineer
Job description
About the role
You will report directly to the Vulnerability Manager and own the end to end lifecycle of vulnerability management across Cloudflare infrastructure and cloud environments. This role focuses on identifying, analysing, and enabling the remediation of security findings while maintaining rigorous alignment with DOD IL4 and FedRAMP requirements. You will leverage modern AI-driven tooling to improve scanning accuracy, streamline triage, and support automated remediation decisions. The position requires proactive ownership of complex remediation initiatives in parallel with strong attention to detail and accuracy. You will act as a bridge between security operations, engineering, and compliance to ensure vulnerability risk is managed consistently across the organization. Success in this role will be measured by reduced exposure time, improved compliance evidence, and stronger partnerships with delivery teams. You will contribute directly to building a more secure and resilient Internet for millions of customers worldwide.
Key facts
What you'll do
- Conduct vulnerability scanning and perform in-depth analysis of findings from scanning tools such as Qualys, Nessus, and Rapid7 to verify accuracy and identify systemic patterns.
- Triage, validate, and prioritise vulnerabilities using risk-based approaches to determine real business impact and collaborate with engineering and compliance teams on remediation actions and timelines.
- Develop, document, and deliver technical remediation guidance and solutions to enable application and infrastructure teams to remediate efficiently and consistently.
- Support DOD IL4 and FedRAMP preparation by ensuring vulnerability management processes, evidence, reporting, and controls meet regulatory and assurance expectations.
- Work closely with engineering and service teams to embed vulnerability management into delivery pipelines, operational processes, and change management activities.
- Leverage AI security tools and automation to streamline triage, improve pattern recognition, and enhance risk prioritisation across the environment.
- Establish strong relationships with engineering teams to track remediation progress and provide clear status reporting to stakeholders.
- Manage and track the remediation backlog to maintain focus on risk reduction and measurable progress against SLAs.
- Contribute to the continuous improvement of vulnerability management standards, procedures, and playbooks while ensuring alignment with IL4, FedRAMP, and other compliance requirements.
- Apply AI-driven methodologies to enhance scanning efficiency, triage accuracy, and automated remediation pathways across cloud and on-premises assets.
- Collaborate with cross-functional teams to ensure vulnerability treatment activities are integrated into secure development lifecycles.
- Monitor emerging threats and vulnerability trends to inform proactive risk mitigation strategies and improve detection capabilities.
- Validate remediation effectiveness through retesting and evidence collection to support audit and assessment activities.
- Communicate technical findings and recommendations clearly to both technical and non-technical audiences during incident response and compliance discussions.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field or equivalent practical experience.
- Current active TS/SCI with Polygraph or ability to obtain is required.
- Must be eligible for and able to maintain a U.S. Government Public Trust Position (Tier V or equivalent).
- Minimum of 5 years of experience in vulnerability management, security operations, or a related field.
- Demonstrated experience with vulnerability scanning platforms such as Qualys, Nessus, Rapid7, or similar enterprise tools.
- Strong understanding of security frameworks, controls, and compliance requirements including DOD IL4 and FedRAMP.
- Experience with cloud environments including AWS, Azure, or GCP and infrastructure hardening practices.
- Proficiency in scripting and automation using languages such as Python, Bash, or PowerShell to support vulnerability workflows.
- Excellent analytical, problem-solving, and critical thinking skills with the ability to manage multiple priorities in a fast-paced environment.
- Strong written and verbal communication skills to effectively collaborate with technical and non-technical stakeholders.
- Ability to maintain discretion and handle sensitive security information with professionalism.
- Willingness to work within US time zones and support occasional on-call responsibilities as needed.
Nice to have
- Experience with DevSecOps toolchains, CI/CD pipelines, and infrastructure as code platforms.
- Familiarity with ATT&CK framework, threat intelligence, and malware analysis concepts.
- Knowledge of container security, Kubernetes environments, and cloud native protection mechanisms.
- Previous work in regulated government, defense, or high assurance environments.
- Experience developing security playbooks, runbooks, and standard operating procedures.
- Background in risk and compliance management, audit support, or evidence collection.
- Familiarity with security orchestration, automation, and response platforms.
Practical notes
- This is a full-time position based in the United States with hybrid work expectations.
- Candidates must be able to work within US time zones.
- Travel is not required for this role.
- Visa sponsorship is available for eligible candidates.
- Applicants must meet all eligibility requirements prior to offer acceptance.
- Compensation range is provided in USD and is reflective of experience, location, and relevant skills.