Hiring.Camp

Vulnerability Management Engineer III

Sutter Health

·

1 week ago

Salary
$147k – $235k
Location
2200 River Plaza Drive, United States of America
Workplace
Hybrid
Type
Full-time
Department
Engineering
Education
Bachelor
Source
Workday

Description

We are so glad you are interested in joining Sutter Health!

Organization:

SHSO-Sutter Health System Office-Valley

Position Overview:

This role will develop and build security controls, administer security technology solutions to reduce risk and/or ensure rapid delivery of least-privilege access to users. As a level 3 engineer, you will create technical plans and implementation strategies within security to address risk and improve user experience. Applies extensive knowledge of security, risk, and technology to lead the resolution of complex problems. This role will lead cross collaboration across business and technology teams to find solutions to complex challenges, applying advanced knowledge of the security ecosystem. Proficient at leading all phases of projects, programs and initiatives of diverse scope and complexity. Works and collaborates with others in a lead role based on business need. Duties include, but are not limited to, engineering, analysis, research, testing, and monitoring.

Vulnerability Management
• Own and engineer the enterprise Vulnerability Management platform, including configuration, optimization, coverage strategy, and continuous improvement of asset discovery and authenticated scanning capabilities
• Design and maintain end-to-end vulnerability data pipelines, ensuring accuracy, completeness, and normalization of vulnerability findings across infrastructure, endpoints, applications, and cloud assets
• Lead integration of vulnerability data into ITIL-aligned enterprise vulnerability reporting and remediation workflows, including automation of ticket creation, routing logic, SLA enforcement, and escalation paths
• Develop and operationalize risk-based prioritization models, correlating vulnerability severity, exploitability, threat intelligence, and asset criticality to drive enterprise remediation focus
• Define and deliver executive-level metrics, dashboards, and reporting, including remediation trends, exposure reduction, and program effectiveness, enabling data-driven risk decisions
• Act as a senior technical authority for vulnerability lifecycle management, including scan validation, false-positive reduction, coverage gap analysis, and continuous tuning to improve detection fidelity and reduce noise
• Serve as a senior technical advisor to application and engineering teams by translating vulnerability findings into clear, actionable guidance, explaining detection logic, validation methods, and risk context to enable effective and accurate remediation

Job Description:

EDUCATION:

  • Bachelor's: Business, Cybersecurity, Computer Science, Information Technology/Security, Risk Management, or related field or equivalent education/experience

TYPICAL EXPERIENCE:

  • 9 years recent relevant experience

PREFERRED EXPERIENCE:

  • Advanced knowledge of enterprise vulnerability management programs, including vulnerability lifecycle management, remediation governance, exception processes, and industry best practices.

  • Expertise administering enterprise vulnerability management platforms, including configuration, optimization, authenticated scanning, asset discovery, exposure management, and continuous improvement of security coverage.

  • Advanced experience with Tenable One, including vulnerability assessment, exposure management, attack surface management, asset inventory management, vulnerability prioritization, reporting, and platform administration.

  • Experience integrating vulnerability management platforms with ServiceNow Vulnerability Response, including vulnerability ingestion, asset correlation, CMDB reconciliation, workflow automation, remediation tracking, and operational reporting. 

  • Advanced understanding of vulnerability frameworks and standards, including CVE, CVSS, CWE, CPE, threat intelligence, exploitability analysis, and threat-informed risk assessment methodologies.

  • Experience leveraging security automation, workflow orchestration, REST APIs, and scripting languages such as PowerShell and Python to improve operational efficiency and scalability.

  • Strong analytical skills with demonstrated experience interpreting large-scale vulnerability data, performing risk quantification, and assessing cybersecurity risks to support effective decision-making.

  • Advanced experience developing cybersecurity metrics, KPIs, KRIs, dashboards, and executive-level reporting, with the ability to communicate complex technical findings and business risk insights to technical and non-technical stakeholders.

  • Experience supporting vulnerability data integration and synchronization between vulnerability management platforms, CMDB systems, and IT service management workflows to improve asset visibility, remediation effectiveness, and enterprise risk reduction.

SKILLS AND KNOWLEDGE:

  • An understanding of the impact of emerging business and end-user technologies have on information security requirements and architecture.

  • An understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business.

  • Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.

  • Good interpersonal skills, with an emphasis on the ability to effectively influence others.

  • A team-focused mentality with the demonstrable ability to work effectively with diverse team members.

  • Ability to communicate sophisticated and technical issues to diverse audiences up to company executives, orally and in writing, in an easily-understood, authoritative, and actionable manner.

  • Able to work with a changing schedule that includes standard or non-standard business hours of work.

  • Thorough knowledge of information systems security concepts and current information security trends and practices including security processes and methods.

  • General knowledge of Federal and State IS security and privacy-related regulatory requirements and laws.

  • General knowledge regarding National Institute of Standards and Technology (NIST), Health Insurance Portability and Accountability Act (HIPAA), Federal Information Processing Standards (FIPS), and other recognized industry security standards. and best practices.

  • In depth knowledge of cyber security solutions, policies, and technologies.

  • Understanding of the lifecycle of a network threat and network vulnerability exploitation in a healthcare environment.

  • Technical skills in planning, administration, and management of information systems, operational and technical security controls, and security risk analysis and management.

  • Proven ability to prioritize work while multi-tasking on assigned work.

  • Ability to participate in security incident and post incident response process.

  • Support of Change management requirements and processes for all production level changes.

  • Understanding of Sutter Health policies, standards, and requirements for all recommendations and solutions.

These Principal Accountabilities, Requirements and Qualifications are not exhaustive, but are merely the most descriptive of the current job. Management reserves the right to revise the job description or require that other tasks be performed when the circumstances of the job change (for example, emergencies, staff changes, workload, or technical development).

Job Shift:

Days

Schedule:

Full Time

Days of the Week:

Monday - Friday

Weekend Requirements:

As Needed

Benefits:

Yes

Unions:

No

Position Status:

Exempt

Weekly Hours:

40

Employee Status:

Regular

Sutter Health is an equal opportunity employer EOE/M/F/Disability/Veterans.

Pay Range is $146,910.40 to $235,060.80 / annual salary

The compensation range may vary based on the geographic location where the position is filled. Total compensation considers multiple factors, including, but not limited to a candidate’s experience, education, skills, licensure, certifications, departmental equity, training, and organizational needs. Base pay is only one component of Sutter Health’s comprehensive total rewards program. Eligible positions also include a comprehensive benefits package.

Skills

PythonServiceNowCybersecurityRESTRisk ManagementInventory ManagementChange ManagementITILHIPAA

Similar Jobs

30

Vulnerability Management Engineer

Workstreet · Philippines

1 week ago

Vulnerability Management Engineer

Workstreet · India

1 week ago

Vulnerability Management Engineer

Verizon Communications · 7701 E Telecom Pkwy, Temple Terrace, FL (FL0321), United States of America +2 · Hybrid

3 weeks ago

Vulnerability Management Engineer

NuHarbor Security · Remote · Remote

1 month ago

Vulnerability Management Engineer

Caci · 398 NATIONAL HARBOR MD, United States of America · Onsite

1 month ago

Vulnerability Management Engineer

Omnissa · India-Bangalore-Office-Kalyani Vista · Hybrid, Onsite

1 month ago

Vulnerability Management Engineer

Hp · ECP01 - E City Park, (ECP01), India +1

4 months ago

Vulnerability Management Engineer

G2 · Bengaluru · On-site

4 months ago

Vulnerability Management Engineer

LSEG · IND-BLR-Divyasree Technopolis, India

5 months ago

Vulnerability Management Engineer

Cloudflare · Hybrid +1 · Hybrid

5 months ago

Vulnerability Management Engineer

Quberesearchandtechnologies · London +1 · Hybrid

6 months ago

Security Engineer, Vulnerability Management and Remediation Operations

Amazon

Yesterday

Lead Information Security Engineer - Vulnerability Management

Fifththird · Virtual - Ohio, United States of America · Remote

3 days ago

Lead InfoSec Engineer, Vulnerability Management

Spgi · US - NY NYC - 55 WATER ST 40 HRS, United States of America · Hybrid

4 days ago

Senior Staff Software Engineer, Vulnerability Management

Zocdoc · USA Remote +1 · Remote

5 days ago

Vulnerability Management Engineer, IT Specialist III - BCIT

The City of Baltimore Job Opportunities · 401 E Fayette St, United States of America · Hybrid

1 week ago

Security Engineer – Vulnerability Management

Slihrms · IN.TN.Chennai.IndiQube Alpine, Jawaharlal Nehru Road, Block No. 4, SIDCO Industrial Estate.Guindy, India

1 week ago

Senior Vulnerability Management Engineer

Group1001Wd · Remote Location, United States of America · Remote

1 week ago

Cyber Security Engineer (Vulnerability Management & SecOperations)

Solarisbank · Berlin

1 week ago

Security Engineer, Vulnerability Management and Automation

Figure · San Jose, CA +1 · Onsite

4 weeks ago

Staff Security Engineer – Vulnerability Management

Geico · WA Remote Zone 1, United States of America +3 · Hybrid

1 month ago

Cybersecurity Engineer - Vulnerability Management

Janestreet · New York, New York, United States

1 month ago

Sr Vulnerability Management Engineer

Solventum · Remote - Minnesota, United States of America +51 · Remote

1 month ago

Sr. Vulnerability Management Engineer

Omnissa · USA-GA-Office-Atlanta, United States of America · Remote, Hybrid

1 month ago

Senior Vulnerability Management Engineer

Ebay · Dublin, Ireland · Hybrid

1 month ago

Senior Cybersecurity Vulnerability Management Engineer

General Motors · GM Global Technical Center - Michigan IT Innovation Center, United States of America · Hybrid

1 month ago

(Junior) Security Engineer - Vulnerability Management (m/w/d)

Bank Verlag · Köln, Nordrhein-Westfalen

1 month ago

Staff Software Engineer, Vulnerability Management

Geico · MD Bethesda Office, United States of America +3 · Hybrid

1 month ago

Senior Product Security Engineer, Vulnerability Management

Clear · New York, New York, United States +1

1 month ago

Sr. Security Software Engineer, Vulnerability Management - Slack

Slack · Georgia - Atlanta, United States of America +2 · Onsite

1 month ago