[Remote] Tenable Vulnerability Management Engineer
Note The job is a remote job and is open to candidates in USA. Symmetrio is recruiting a Remote Tenable Vulnerability Management Engineer Consultant for a large government organization in Philadelphia, PA. The role is responsible for engineering and maturing an enterprise vulnerability management program through Tenable platform optimization, risk-based prioritization, automation, AI-enabled analysis, remediation tracking, and executive reporting. Responsibilities Conduct vulnerability assessments using Tenable to identify potential security vulnerabilities within our systems, networks, and applications Collaborate with cross-functional teams to analyze and prioritize vulnerabilities based on risk levels and potential impact Develop and implement vulnerability management processes, procedures, and best practices to ensure timely identification, remediation, and reporting of vulnerabilities Monitor and track the remediation of identified vulnerabilities, ensuring that they are addressed within defined timelines Stay updated with the latest security vulnerabilities, threats, and industry best practices to continuously improve the vulnerability management program Perform regular vulnerability scanning and penetration testing to proactively identify and address potential security weaknesses Work closely with IT teams to provide guidance and support in remediating vulnerabilities, including suggesting configuration changes, patches, and other remediation actions Provide technical expertise and guidance to internal stakeholders on vulnerability management issues and best practices Collaborate with the Incident Response team to investigate and respond to security incidents related to vulnerabilities Skills * Bachelor's degree in Computer Science, Information Security, or a related field, preferred but not required with acceptable experience 3-5 years of recent, hands-on experience administering and engineering Tenable solutions in a large enterprise environment is acceptable in replacement of education * Demonstrated recent experience with the Tenable platform, with strong hands-on expertise in Tenable Vulnerability Management (Tenable.io) and Nessus, including scanner deployment and management, scan configuration, asset discovery, tagging, credentialed scanning, plugin management, troubleshooting, dashboards, reporting, and platform optimization * Experience using Tenable Web App Scanning to identify and assess vulnerabilities in web applications and APIs * Proven experience designing, operating, and maturing an enterprise vulnerability management program, including vulnerability discovery, validation, risk-based prioritization, remediation tracking, exception management, metrics, reporting, and continuous improvement * Advanced scripting and automation skills, particularly PowerShell Python or similar scripting experience is highly desirable Must be able to create and maintain scripts that automate Tenable administration, data collection, enrichment, reporting, integrations, remediation workflows, and other vulnerability management activities * Experience working with Tenable APIs and integrating Tenable vulnerability and asset data with enterprise technologies such as ticketing systems, SIEM/SOAR platforms, CMDBs, asset inventories, dashboards, or other security tools * Demonstrated ability and interest in leveraging AI tools to assist with vulnerability analysis, data correlation, pattern identification, prioritization, remediation research, scripting, reporting, and other vulnerability management use cases while applying appropriate validation and security controls to AI-generated outputs * Strong understanding of vulnerability intelligence and risk-based prioritization, including CVE, CVSS, CISA Known Exploited Vulnerabilities (KEV), exploitability, threat intelligence, asset criticality, exposure, compensating controls, and business impact * Solid understanding of common vulnerabilities, attack vectors, mitigation techniques, network and application security concepts, and the ability to distinguish actionable risk from scanner noise or false positives * Experience with network scanning, authenticated/credentialed scanning, web application scanning, vulnerability validation, and penetration testing or vulnerability exploitation techniques * Knowledge of industry standards and frameworks such as CVSS, CVE, OWASP, NIST, and vulnerability management best practices * Strong analytical, troubleshooting, communication, and problem-solving skills, with the ability to translate technical vulnerability data into clear remediation guidance and risk information for infrastructure teams, application owners, leadership, and other stakeholders * Demonstrated ability to independently identify gaps in vulnerability coverage, tooling, processes, automation, reporting, and governance and recommend and implement improvements that measurably increase vulnerability management program maturity Relevant certifications (e.g., CISSP, CEH, GIAC), including Tenable or other vendor certifications, are highly desirable Experience with additional Tenable services and capabilities is strongly preferred Python or similar scripting experience is highly desirable Benefits Remote position Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k) Paid Time Off (Vacation, Sick & Public Holidays) Company Overview Symmetrio prides itself on our unwavering dedication to understanding clients’ unique needs, organizational design, culture, and operational challenges. It was founded in 2012, and is headquartered in Philadelphia, Pennsylvania, USA, with a workforce of 51-200 employees. Its website is https// Company H1B Sponsorship Symmetrio has a track record of offering H1B sponsorships, with 1 in 2024. Please note that this does not guarantee sponsorship for this specific role.