Back to jobs

VULNERABILITY MANAGEMENT ENGINEER

Paragon Cyber Solutions
Full-timeseniorHealth Care Plan (Medical, Dental & Vision).Retirement Plan (401K w/ employer matching).Paid Time Off & Paid Federal Holidays.Short and Long-Term Disability.Healthy Work-Life Balance.

Job description

Paragon Cyber Solutions is a woman-, veteran-, and minority-owned cybersecurity and IT services firm that supports government and commercial clients with compliance, cyber defense, and mission-focused technology solutions. Our team takes pride in solving complex technical challenges and delivering innovative, customer-focused outcomes. The Vulnerability Management Engineer III is responsible for leading vulnerability identification, assessment, prioritization, remediation tracking, and reporting activities across enterprise environments. This role serves as a subject matter expert on vulnerability management platforms, security risk analysis, automation, and compliance reporting. This position is contingent upon contract award. • Administer and optimize enterprise vulnerability management platforms. • Conduct vulnerability scanning, assessment, and remediation tracking. • Analyze CVEs, CVSS scores, threat intelligence, and exploitability. • Develop remediation plans with system owners and infrastructure teams. • Automate vulnerability reporting, ticketing, and remediation workflows. • Produce executive-level dashboards and security metrics. • Support federal audits, security assessments, and compliance activities. • Develop standard operating procedures and platform documentation. • Improve asset inventory accuracy and vulnerability coverage. • Assist with patch management coordination and verification. Education • Bachelor's degree or equivalent experience. Experience • 5+ years of vulnerability management or security engineering experience. • Experience with process automation and reporting. • Splunk dashboard, reporting, and query development. • Experience generating scan evidence, mitigation documentation, and audit artifacts. • Experience supporting federal cybersecurity directives and data calls. • SOP development for vulnerability management programs. Experience with vulnerability assessment platforms such as: • Tenable • Qualys • Rapid7 Strong experience with: • Asset management • Patch management • Vulnerability remediation workflows Preferred Certifications (one or more): Must meet IAM Level II IAWF baseline certification standards under DoD 8140/8570.01-M, with at least one of the following: • CAP (Certified Authorization Professional) • CASP+ CE (CompTIA Advanced Security Practitioner) • CISM (Certified Information Security Manager) • CISSP (or Associate) • GSLC (GIAC Security Leadership Certification) • CCISO (Certified Chief Information Security Officer) • HCISPP (HealthCare Information Security and Privacy Practitioner) • Health Care Plan (Medical, Dental & Vision). • Retirement Plan (401K w/ employer matching). • Paid Time Off & Paid Federal Holidays. • Short and Long-Term Disability. • Healthy Work-Life Balance.

Skills

TenableQualysRapid7SplunkAsset managementPatch managementVulnerability remediation workflowsAutomationReportingDashboard developmentCVECVSSThreat intelligenceExploitability analysisCompliance reportingAudit supportSOP developmentFederal cybersecurity directivesData callsSecurity risk analysis