Talent.com
Technology Vulnerability Management Engineer
Technology Vulnerability Management EngineerCooley LLP • Washington, DC, United States
Technology Vulnerability Management Engineer

Technology Vulnerability Management Engineer

Cooley LLP • Washington, DC, United States
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Technology Vulnerability Management Engineer

Cooley is seeking a Technology Vulnerability Management Engineer to join the Security team.

Position Summary : Cooley Technology embraces a culture of customer service excellence, and all members of the department are expected to move this agenda forward. To that end, the Technology Vulnerability Management Engineer is expected to recognize that the Cooley Technology department is a service organization first and foremost and will be evaluated on this requirement equal in importance to the technical or operational responsibilities outlined later in this document.

The Technology Vulnerability Management Engineer will lead the full vulnerability management lifecycle across endpoints, servers, applications, containers, and cloud environments. This role owns discovery, validation, risk-based prioritization, and remediation outcomes. The engineer will administer and optimize vulnerability management platforms, automate data flows and reporting, and partner with Technology and Innovation teams to meet SLA targets and reduce enterprise risk. The position will be a balance of hands-on technical execution, program leadership, and clear communication, while staying current on emerging threats and supporting audits, compliance efforts, and incident response activities. Specific duties include, but are not limited to, the following :

Position responsibilities

  • Support the development and continuous optimization of vulnerability management services, including scanning cadence, exception handling, SLAs and alignment with security controls
  • Build and maintain standards, playbooks, and repeatable processes to improve the efficiency and maturity of the vulnerability management program
  • Administer and optimize enterprise vulnerability management platforms (e.g., Tenable / Qualys / Rapid7), ensuring accurate coverage across assets
  • Integrate asset context from CMDB, EDR, and cloud inventory to drive effective risk-based prioritization
  • Build automation for data ingestion, deduplication, ticketing, and reporting using APIs, scripting, and other tools to improve data quality and reduce false positives
  • Analyze and interpret vulnerability scan results to assess severity, validate findings, and provide actionable remediation recommendations
  • Publish dashboards and reports tailored for engineers, management, and executive leadership to communication progress and risk
  • Drive remediation efforts, including patching, configuration baselines, and compensating controls, and validate results through rescans or attestations
  • Partner with developers, DevOps, and other stakeholders to implement "shift-left" practices such as pipeline scanning, container / base-image hygiene, and Infrastructure-as-Code (IaC) hardening
  • Collaborate with cross-functional teams to implement security solutions and controls that mitigate identified vulnerabilities
  • Support audits, assessments, and regulatory compliance requirements by providing accurate documentation and evidence
  • Identify opportunities for process improvements, tool optimization, and template standardization to increase efficiency and reduce operational overhead
  • Stay current on emerging threats, vulnerabilities, and industry best practices to ensure the program remains effective and modern
  • Contribute to advanced security testing activities such as penetration testing, application reviews and targeted vulnerability assessments as needed
  • Assist with incident response activities by providing vulnerability context, supporting root cause analysis, and helping to validate containment and remediation actions
  • All other duties as assigned or required

Skills and experience :

Required :

  • After orientation at Cooley LLP, exhibit proficiency in the Microsoft 365, MECM, Intune, iManage and other firm applications
  • Ability to work extended and / or weekend hours, as required
  • 2+ years of experience in cyber security, vulnerability management, or penetration testing. Senior candidates must have 5+ years' directly applicable experience in the field
  • Strong hands-on experience conducting vulnerability scans, including configuration and use of tools such as Tenable, Qualys, Rapid7
  • Knowledge of cybersecurity frameworks, controls and standards, and best practices
  • Solid understanding of Windows / Linux, networks, web / application stacks, and at least one major cloud provider (AWS / Azure)
  • Proficiency in Python or PowerShell and REST APIs; ability to build repeatable pipelines / dashboards
  • Familiarity with CVSS, KEV, EPSS and how they align with risk frameworks
  • Extensive knowledge and experience generating and disseminating easily digestible metrics and report to system owners and leadership
  • Preferred :

  • Bachelor's Degree in Information Technology or Computer Information Systems
  • Knowledge of the Mitre ATT&CK framework and NIST Cyber Security Framework
  • Familiarity with common security controls in the enterprise (Firewall, Proxy, AV, SIEM, etc.)
  • Experience with incident response procedures
  • Extensive knowledge and understanding of security issues, techniques, and implications across multiple computer platforms
  • Demonstrated experience leading and developing others by providing technical guidance and leadership to project teams
  • Solid knowledge and understanding of security regulations and best practices such as the ISO 27000 family of standards
  • Demonstrated experience communicating technical information to business clients and less experienced technologists
  • CISSP, CISM or equivalent
  • Experience with CI / CD pipelines
  • Cloud Architecture and / or Cloud Security Certifications (AWS, Azure, GCP)
  • Cloud Security Alliance (CCSP, CCSK) (ISC)2
  • Additional security certifications
  • Competencies :

  • Exceptional customer service skills
  • Excellent analytical, problem-solving, customer service, project management and communication skills
  • Goal-oriented
  • Proven track record of excellent decision making, integrity and working with IT management, business users and business professionals
  • Excellent oral and written communication skills, including technical and user documentation
  • Strong organizational skills
  • Ability to work independently and under high pressure with tight schedules and deadlines
  • Ability to interact well with all levels of business professionals
  • Excellent active listening skills
  • Flexible and patient with process development / execution and adherence to instruct project management practices
  • Capable of grasping new concepts quickly and without prior experience
  • Detail-oriented
  • Ability to multi-task and work in fast-paced environment
  • Ability to interact and coordinate with several teams to achieve objectives
  • Ability to solve problems independently and simultaneously, effectively managing multiple tasks
  • Professional demeanor at all times
  • Cooley offers a competitive compensation and excellent benefits package and is committed to fair and equitable employment practices. EOE.

    The expected annual pay range for this position is $110,000 - $155,000. Please note that final offer amount will be dependent on geographic location, applicable experience and skillset of the candidate. Senior level candidates may be considered for this position and would be eligible for a higher salary range based on experience.

    We offer a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and / or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, long-term care coverage, backup care for children and / or adults and other parental support benefits. In addition to elective benefit options, benefited employees receive firm-paid life insurance, AD&D, LTD, short term medical benefits as well as 21 days of Paid Time Off ("PTO") and 10 paid holidays each year. We provide generous parental leave and fertility benefits. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.

    serp_jobs.job_alerts.create_a_job

    Vulnerability Management Engineer • Washington, DC, United States

    Job_description.internal_linking.related_jobs
    Manager, Vulnerability Management

    Manager, Vulnerability Management

    Marriott Hotels Resorts • Bethesda, Maryland, USA
    serp_jobs.job_card.full_time
    The Manager Vulnerability Management functions as a technical expert in the area of vulnerability scanning and remediation tracking. The role will be responsible for identifying vulnerabilities thro...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Travel Mammography Tech - $3,052 to $3,344 per week in Lutherville Timonium, MD

    Travel Mammography Tech - $3,052 to $3,344 per week in Lutherville Timonium, MD

    AlliedTravelNetwork • Columbia, Maryland, US
    serp_jobs.job_card.full_time
    AlliedTravelNetwork is working with AMN Healthcare Allied to find a qualified Mammography Tech in LUTHERVILLE TIMONIUM, Maryland, 21093!. Job Description & Requirements.Mammography Tech - (Mam -...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Engagement Manager (Cyber), Public Sector

    Engagement Manager (Cyber), Public Sector

    Scale AI, Inc. • Columbia, MD, United States
    serp_jobs.job_card.full_time
    Scale AI is at the forefront of the AI revolution, helping the U.AI across national security missions.We're building enterprise-grade generative AI solutions and delivering them into operational us...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Mid-level Vulnerability & Patch Management Engineer

    Mid-level Vulnerability & Patch Management Engineer

    Veracity • Washington, DC, United States
    serp_jobs.job_card.full_time
    Mid-level Vulnerability & Patch Management Engineer.DESCRIPTION OF RESPONSIBILITIES.Responsible for supporting the personnel, applications, and appliances employed to maintain compliance with all r...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Security Engineer-Senior Vulnerability Mgmt

    Security Engineer-Senior Vulnerability Mgmt

    Aditi Consulting • Washington, DC, United States
    serp_jobs.job_card.full_time
    Lead a small team of individuals who support cybersecurity operational environment and Vulnerability Management related requirements / needs. Engage with Federal Leadership and counterparts to identi...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Reverse Engineer / Cyber Capability Engineer

    Reverse Engineer / Cyber Capability Engineer

    The Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
    serp_jobs.job_card.full_time
    Are you a creative engineer with natural curiosity who wants to understand how things work?.Do you love finding vulnerabilities and teaming with outstanding reverse engineers?.Are you passionate ab...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Deployment Site Reliability Engineer - Connected Warfare

    Deployment Site Reliability Engineer - Connected Warfare

    Anduril Industries • Washington, District of Columbia, United States
    serp_jobs.job_card.full_time
    Anduril Industries is a defense technology company with a mission to transform U.By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the def...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Cyber Operations Splunk Engineer

    Cyber Operations Splunk Engineer

    BOOZ, ALLEN & HAMILTON, INC. • Alexandria, VA, US
    serp_jobs.job_card.full_time +1
    Cyber Operations Splunk Engineer.Support enterprise vulnerability management and cyber defense operations.Provide cyber operations monitoring and notification capabilities, to include developing an...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Cloud / Virtualization Engineer - NCCoE

    Senior Cloud / Virtualization Engineer - NCCoE

    ITC Federal, Inc • Rockville, MD, United States
    serp_jobs.job_card.full_time
    Senior Cloud / Virtualization Engineer - NCCoE.Sr Virtualization / Cloud Engineer.National Institute of Standards and Technology (NIST), National Cybersecurity Center of Excellence (NCCoE).Ability to...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    FIPS 140 Security Engineer

    FIPS 140 Security Engineer

    ALTA IT Services • Columbia, MD, US
    serp_jobs.job_card.temporary
    Job Title : FIPS 140 Security Engineer Location : Columbia, MD (Remote) Compensation : $60.HR Duration : 6 month contract to hire In joining the team, you will get an exciting opportunity to work in th...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    DevOps Engineer (Journeymen - SME Level)

    DevOps Engineer (Journeymen - SME Level)

    Xcelerate Solutions • Bethesda, Maryland, United States
    serp_jobs.job_card.full_time
    DevOps Engineer – TS / SCI with Full Scope Polygraph.Xcelerate Solutions is seeking a highly skilled DevOps Engineer to provide mission-critical system support to our Intelligence Community (IC) cust...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Travel CT Tech - $3,467 per week in Lutherville Timonium, MD

    Travel CT Tech - $3,467 per week in Lutherville Timonium, MD

    AlliedTravelCareers • Columbia, Maryland, US
    serp_jobs.job_card.full_time
    AlliedTravelCareers is working with Medical Solutions to find a qualified CT Tech in Lutherville Timonium, Maryland, 21093!. A facility in Lutherville Timonium, MD is seeking its next amazing CT Tec...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Endpoint Vulnerability Management SME / Team Lead

    Endpoint Vulnerability Management SME / Team Lead

    MBL Technologies • Bethesda, MD, United States
    serp_jobs.job_card.full_time
    Federal government and commercial markets.Our solutions are tailored to support each client's mission, accounting for their unique needs and operating environments to ensure success.We bring the ri...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Travel Mammography Tech - $3,052 to $3,344 per week in Lutherville Timonium, MD

    Travel Mammography Tech - $3,052 to $3,344 per week in Lutherville Timonium, MD

    AMN Healthcare Allied • Columbia, Maryland, US
    serp_jobs.job_card.full_time
    Job Description & Requirements.Mammography Tech - (Mam - Mammo Tech) .StartDate : ASAP Available Shifts : 8 D Pay Rate : $3051. Mammo Tech for Lutherville, MD Travel Mammography Tech jobs in Lut...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Hiring our Heroes Skillbridge - Systems Engineer

    Hiring our Heroes Skillbridge - Systems Engineer

    SYSTEMS PLANNING AND ANALYSIS, INC. • Alexandria, VA, US
    serp_jobs.job_card.full_time
    Systems Planning and Analysis, Inc.SPA) delivers high-impact, technical solutions to complex national security issues.With over 50 years of business expertise and consistent growth, we are known fo...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Claim Specialist - Property Field Inspection

    Claim Specialist - Property Field Inspection

    State Farm • Columbia, MD, United States
    serp_jobs.job_card.full_time
    Being good neighbors - helping people, investing in our communities, and making the world a better place - is who we are at State Farm. It is at the core of how we operate and the reason for our suc...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Endpoint Vulnerability Management Subject-Matter Expert / Technical Lead

    Endpoint Vulnerability Management Subject-Matter Expert / Technical Lead

    GovCIO • Washington, DC, United States
    serp_jobs.job_card.full_time
    GovCIO is currently hiring for Endpoint Vulnerability Management Subject-Matter Expert / Technical Lead for our NIH Proposal. The Technical Lead will support our client's contract needs.This position ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Travel Surgical Tech - $1,617 to $1,720 per week in Columbia, MD

    Travel Surgical Tech - $1,617 to $1,720 per week in Columbia, MD

    Fusion Medical Staffing • Columbia, MD, US
    serp_jobs.job_card.full_time
    Facility in Columbia, Maryland.Fusion Medical Staffing is seeking a skilled Surgical Technologist for a 12-week travel assignment in Columbia, Maryland. As a member of our team, you'll have the oppo...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted