Job description
About This Opportunity CTI Staffing is partnering with a well-established organization in the insurance industry to find a Vulnerability Management Engineer for their IT Security team. This is a fully remote contract engagement with right-to-hire potential. This team is standing up a mature, sustainable vulnerability management program across a large and continuously evolving asset environment.
You'll own the build: from reconciling the asset inventory to standing up the remediation workflow that the program runs on. If you like building programs rather than inheriting them, this is that role.
What You'll Do
Reconcile asset data across vulnerability scanners, endpoint security platforms, identity sources, and the CMDB to identify coverage gaps Aggregate and de-duplicate vulnerability findings and baseline the current-state posture Enrich findings with exploit intelligence (CVSS, EPSS, CISA KEV, validated-exploitable status) and produce a risk-ranked register Build and configure the Service.
Now Vulnerability Response remediation workflow, including SLAs and an exception/risk-acceptance process Drive initial remediation waves on highest-risk exposures in partnership with asset owners Report program metrics and provide weekly status to security leadership Author operational runbooks and operate the program in steady state Apply AI tools to accelerate de-duplication, analysis, prioritization, and reporting Requirements What You Bring Must-Have: Hands-on experience operating enterprise vulnerability tooling, including Tenable and Crowd.
Strike (Falcon Spotlight / Exposure Management) Service. Now Vulnerability Response / Sec. Ops workflow build experience (this is the engagement's core deliverable) Risk-based prioritization using CVSS, EPSS, and CISA KEV Remediation orchestration across infrastructure and application owners, including SLA design Metrics and executive-ready reporting Proficiency applying frontier AI models (e.
g., ChatGPT Enterprise, Claude) to security engineering work US Citizenship required (client cannot provide sponsorship) Nice-to-Have: Node. Zero or other autonomous pentest familiarity Patch and change-management integration CMDB reconciliation experience Insurance, financial services, or regulated-industry background CISSP, GIAC, or Tenable/Crowd.
Strike vendor certifications Technical Environment: Tenable, Crowd. Strike (Falcon Spotlight / Exposure Management, NG-SIEM), Node. Zero Service. Now (Vulnerability Response, Sec. Ops, CMDB) Okta, Active Directory, Intune/MDM ChatGPT Enterprise and Claude What Success Looks Like: An authoritative, reconciled asset inventory with known coverage gaps closed A live Service.
Now Vulnerability Response workflow with SLAs, driving measurable remediation on the highest-risk exposures Runbooks and a steady-state program the internal team can operate