Senior Vulnerability Remediation Engineer
About LumenLumen connects the world. We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and company from the people up – committed to teamwork, trust and transparency. People power progress.We’re looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future.The RoleWe are seeking a dynamic and experienced Senior Vulnerability Remediation Engineer to join our innovative team. This role requires a creative problem solver who is customer-obsessed, willing to learn, and capable of overcoming any obstacle. As a clear communicator and supportive teammate, you will play a crucial part in safeguarding our systems and enhancing our security processes.LocationThis is a remote position open to candidates based anywhere in the U.S.The Main Responsibilities
- Provide Vulnerability Management guidance, coordination, processes, grouping, workflows, exception handling, remediation processes, tracking and reporting.
- Coordinate with Business groups, Application and Infrastructure owners, Information Security, and other internal stakeholders to remediate infrastructure vulnerabilities and help drive currency efforts for systems near the end of lifecycle
- Provide situation-based support, using information security policies and compliance standards, to ensure identified vulnerabilities are remediated within SLA.
- Investigate vulnerability findings and present them within the enterprise to coordinate remediation efforts in collaboration with subject matter experts.
- Oversee remediation activities, such as installation of patches, software, and other compliance standards in accordance with established policies.
- Coordinate scanning and remediation activities of Application Vulnerabilities within the DevOps pipeline and deployment processes within ServiceNOW.
- Reporting against KPIs, KRIs, SLAs and Configuration Compliance.
- Bachelor’s Degree in Computer Science, Information Security, related field or equivalent experience
- 3+ years of experience in information security focused on Vulnerability Management
- 2+ years of experience with threat modeling, security design reviews, and security architecture
- 3+ years of experience with Vulnerability Management tools such as Tenable, CrowdStrike Spotlight, Axonius, Wiz and ServiceNOW
- Knowledge of application, network and operating system security, including a good understanding of Linux and Windows patching and network protocols.
- Applied experience with cloud platforms (e.g., AWS, Azure, GCP), including identity, networking, and workload security.
- Experience integrating systems into ServiceNow via APIs.
- Experience using vulnerability scanning tools, application scanning tools (SAST/DAST), and ServiceNow ticketing and automation tools.
- Experience using Vulnerability Response Applications for orchestration, automation, remediation, and governance.
- Experience with CI/CD pipelines and Agile methodologies
- Experience with Cloud security architecture and deployment models
- Experience with securing highly sensitive data
- Applied experience with OWASP Top 10, SANS Top 20, and NIST Vulnerability Database.
- Demonstrate knowledge of security technologies, trends, leading practices, and regulatory requirements and government security standards such as PCI, CMMC, FedRAMP and Controlled Unclassified Information (CUI) standards, along with best practices such as NIST Cybersecurity Framework (CSF), NIST 800-171, NIST 800-53, ISO 27001-27002 and other applicable security and privacy laws.
- Great communicator, facilitator and team player.
- Must be willing to achieve Secret Clearance.