Senior Vulnerability Management Engineer at Sunrun managing enterprise vulnerability mitigation. Responsible for leading strategy and development of vulnerability management programs in diverse environments.
Responsibilities
Develop and own the enterprise vulnerability management strategy, roadmap, policies, and standards
Act as the subject matter expert on vulnerability threats, exploitation techniques, and mitigation strategies
Define the organization's risk appetite in collaboration with executive leadership
Mentor and guide junior engineers and analysts
Lead the end-to-end vulnerability management lifecycle
Architect, manage, and optimize vulnerability management tools
Drive automation and continuous improvement within the program
Build partnerships with Engineering, IT, DevOps, and Application Development teams
Develop metrics, KPIs, and KRIs to measure program effectiveness
Design and deliver actionable dashboards and reports for technical and executive audiences
Champion "shift-left" principles with DevSecOps teams
Requirements
8+ years of progressive experience in cybersecurity
5+ years specifically dedicated to enterprise-scale vulnerability management in hybrid environments
Deep, hands-on expertise with leading vulnerability scanning platforms (Tenable, Qualys, etc.)
Expert understanding of the vulnerability lifecycle, risk assessment, and prioritization techniques (CVSS, EPSS, CISA KEV)
Proficiency in assessing vulnerabilities across on-premise infrastructure, multi-cloud platforms (AWS, Azure, GCP), and container technologies (Docker, Kubernetes)
Exceptional leadership and communication skills
Bachelor’s degree in a relevant field (Computer Science, Cybersecurity, etc.) or equivalent extensive experience
Experience with scripting languages (Python, PowerShell)
Knowledge of "Security as Code" principles and CI/CD pipeline integration
Familiarity with compliance frameworks (PCI DSS, HIPAA, SOX, NIST)
Deployed Engineer at LangChain working on LLM applications and collaborating with customers and enterprise sales. Leading technical demos and training workshops for developer audiences.
Engineer I developing and maintaining project control systems in construction. Collaborating with stakeholders to optimize project performance and reporting.
Engineer I role in project planning and control for projects in Process, Manufacturing, Production Industry at AtkinsRéalis. Focus on cost management, scheduling, and project delivery.
Engineer managing design, planning, implementation, and operations for outdoor radio networks. Leading mobile cell site deployments and collaborating with RF engineers and subcontractors.
InfoSec Enablement Engineer driving security transformation for new and legacy systems. Collaborating on complex architectures and providing proactive security solutions.
Field Service Engineer working at client laboratories to install and maintain atomic spectroscopy products. Requires a chemistry degree and significant analytical techniques experience.
Flying Doctor & ECU Validation Engineer delivering automotive electronics support in dynamic environments. Handling ECU validation, diagnostics, and multimedia system updates.
Principal Configuration Engineer for Integrated Sensing and Protection at Leonardo in the UK. Managing configuration management activities and liaising with various project stakeholders.
Senior Engineer at Tenneco steering customer requirements and technical documentation. Lead communication with stakeholders and coordinate internal engineering teams for project deliverables.
Graduate Engineer in TechnipFMC's team focusing on energy industry innovations and project management. Engaging in various functions including Tendering, Operations, Procurement, and more.