Skip to Content

Vulnerability & Remediation Engineer

--Vacancies LLC--

Job Overview

The Vulnerability & Remediation Engineer is responsible for managing the end-to-end vulnerability management and remediation lifecycle across digital infrastructure.

The role focuses on identifying and prioritizing security vulnerabilities, planning and executing patch deployments across operating systems, cloud environments, networks, and third-party applications, and ensuring remediation activities are completed within defined SLAs.

The ideal candidate will work closely with internal IT and security teams to address security gaps, manage vulnerability exceptions, maintain operational stability, and ensure compliance with established Change Advisory Board (CAB) processes.

Key Responsibilities

Remediation Planning & Preparation

  • Define patch groups, deployment rings, and execution sequences across pilot, pre-production, and production environments.
  • Verify pre-deployment requirements, including snapshots, backups, disk capacity, and required access.
  • Prepare change records, conduct risk assessments, and coordinate approvals through the CAB.
  • Identify required patches, dependencies, and compatibility considerations across operating systems, cloud platforms, and third-party software.

Patch Deployment & Execution

  • Deploy approved security patches and updates across servers, endpoints, and cloud workloads.
  • Apply updates to in-scope network devices and appliances while minimizing service disruption.
  • Execute controlled, staged patch rollouts within approved maintenance windows.
  • Conduct rapid impact assessments for zero-day and actively exploited vulnerabilities.
  • Coordinate emergency change approvals and execute out-of-band patching or approved mitigations when required.

Threat Intelligence & Vulnerability Prioritization

  • Monitor vendor security advisories and the CISA Known Exploited Vulnerabilities (KEV) catalog.
  • Prioritize vulnerabilities based on exploitability, asset criticality, internet exposure, and operational constraints.
  • Conduct vulnerability scanning and support ongoing vulnerability management activities.
  • Investigate and resolve false positives.
  • Maintain accurate asset inventories and vulnerability scope records.

Post-Deployment Validation & Troubleshooting

  • Validate successful remediation through rescans, system health checks, and functional testing.
  • Work with application owners to confirm that patched systems remain operational.
  • Investigate failed patch deployments and identify root causes.
  • Reattempt failed deployments or execute approved rollback procedures where required.
  • Ensure deployment failures are properly documented and corrective actions are implemented.

Risk & Exception Management

  • Implement approved compensating controls, security mitigations, hardening configurations, or access restrictions when direct patching is not possible.
  • Identify End-of-Life (EOL) systems and maintain a dedicated EOL asset register.
  • Recommend upgrade plans, remediation sequences, and appropriate security controls for EOL systems.
  • Support vulnerability risk acceptance workflows.
  • Track exception expiration dates and conduct periodic reviews of approved exceptions.

Governance, Reporting & Documentation

  • Ensure vulnerability remediation activities meet defined SLAs, milestones, and operational requirements.
  • Prepare weekly and monthly reports covering:
    • Remediation progress
    • Patch success and failure rates
    • SLA compliance
    • Outstanding vulnerabilities
    • Exception status
  • Maintain evidence packs, scan results, remediation evidence, and exception documentation.
  • Develop, maintain, and update SOPs and runbooks covering vulnerability scanning, patching, validation, and emergency response procedures.

Service Transition & Collaboration

  • Collaborate continuously with internal IT and security teams until identified vulnerabilities are fully remediated and closed.
  • Administer and integrate vulnerability management tools with existing security and IT environments.
  • Support onboarding activities by ensuring access, tooling, and operational readiness.
  • Manage service offboarding and transition activities, including:
    • Knowledge transfer sessions
    • Documentation handover
    • Access removal confirmation
    • Backlog and outstanding vulnerability transfers

Required Qualifications

Experience

  • 4+ years of dedicated experience in vulnerability management, security engineering, or enterprise patch management.

Education

  • Bachelor's degree in:
    • Cybersecurity
    • Computer Science
    • Information Technology
    • Or another related field

Certifications

Candidates must hold at least one of the following industry-recognized certifications:

  • CISSP – Certified Information Systems Security Professional
  • GCIH – GIAC Certified Incident Handler
  • CompTIA Security+
  • AWS Certified Security
  • Microsoft Certified: Azure Security Engineer Associate

Technical Skills

Vulnerability Management

  • Tenable
  • Qualys
  • Rapid7
  • Vulnerability scanning and assessment
  • False-positive analysis
  • Asset inventory and scope management

Patch Management & Automation

  • Microsoft Endpoint Configuration Manager (MECM)
  • Windows Server Update Services (WSUS)
  • Ansible
  • Terraform
  • Patch deployment automation and orchestration

IT Service Management

  • ServiceNow
  • Jira Service Management
  • CAB and change-management workflows
  • ITSM ticketing and documentation

Operating Systems

  • Windows Server administration
  • Linux administration and major Linux distributions

Cloud Security

Experience securing and patching cloud workloads across:

  • AWS
  • Microsoft Azure
  • Google Cloud Platform (GCP)
  • Cloud-native security and patching services

Preferred Qualifications

  • Experience developing custom scripts to automate patching, reporting, or vulnerability management workflows.
  • Previous experience working within a Managed Security Service Provider (MSSP) environment.
  • Familiarity with offensive security concepts and penetration testing methodologies.
  • Strong understanding of Active Directory architecture, attack paths, and exploitability.
  • Experience handling zero-day and actively exploited vulnerabilities.
  • Strong understanding of enterprise change-management and remediation processes.

Core Competencies

  • Vulnerability Management
  • Patch Management
  • Security Remediation
  • Threat Intelligence
  • Risk-Based Prioritization
  • Cloud Security
  • Windows & Linux Administration
  • Network Security
  • ITSM & Change Management
  • Security Automation
  • Incident & Emergency Response
  • Governance & Compliance