Senior Security Engineer, Vulnerability Management
Draper, UT, United States
Full Time Senior-level / Expert USD 109K - 207K
Proofpoint
Proofpoint helps protect people, data and brands against cyber attacks. Offering compliance and cybersecurity solutions for email, web, cloud, and more.About Us:
We are the leader in human-centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead of bad actors and safeguard the digital world. Join us in our pursuit to defend data and protect people.
How We Work:
At Proofpoint, you’ll be part of a global team that breaks barriers to redefine cybersecurity, guided by our BRAVE core values: Bold in how we dream and innovate, Responsive to feedback, challenges, and opportunities, Accountable for results and best-in-class outcomes, Visionary in future-focused problem-solving, Exceptional in execution and impact.
Corporate Overview
Proofpoint is a leading cybersecurity company protecting organizations’ greatest assets and biggest risks: vulnerabilities in people. With an integrated suite of cloud-based solutions, Proofpoint helps companies around the world stop targeted threats, safeguard their data, and make their users more resilient against cyber-attacks. Leading organizations of all sizes, including more than half of the Fortune 1000, rely on Proofpoint for people-centric security and compliance solutions mitigating their most critical risks across email, the cloud, social media, and the web.
We are singularly devoted to helping our customers protect their greatest assets and biggest security risk: their people. That’s why we’re a leader in next-generation cybersecurity.
Protection Starts with People. Proofpoint.
The Role
We are seeking a highly skilled and experienced Senior Security Engineer specializing in Vulnerability Management to join our Information Security team. This individual will play a pivotal role in safeguarding our infrastructure, applications, and services through proactive vulnerability identification, risk assessment, and remediation strategy development. The ideal candidate has deep, hands-on expertise with Tenable Security Center, Tenable.io, Wiz, and Veracode, as well as substantial experience managing and supporting FedRAMP and ISO 27001 audits. This is a technical leadership role that also involves strategic program design, stakeholder communication, audit preparation, and artifact maintenance. Based in Draper Utah, this key role will drive key vulnerability management initiatives for Proofpoint Product portfolio.
Key Responsibilities:
Vulnerability Management Operations:
- Lead enterprise-wide vulnerability management initiatives, ensuring coverage across cloud, on-premises, and hybrid environments.
- Manage, operate, and optimize Tenable Security Center, Tenable.io, Qualys VMDR, Wiz, and Veracode platforms.
- Analyze and prioritize vulnerabilities based on business risk, CVSS scores, threat intelligence, and asset criticality.
- Collaborate with IT and DevOps teams to drive timely remediation or mitigation.
- Maintain a metrics-driven approach to track vulnerability trends, SLAs, and program effectiveness. Security Audit and Compliance Support
- Serve as a key technical point of contact for FedRAMP and ISO 27001 assessments for the Vulnerability Management area.
Generate, update, and maintain FedRAMP security artifacts including:
- System Security Plan (SSP)
- Plan of Action and Milestones (POA&M)
- Continuous Monitoring (ConMon) reports
- Security Assessment Reports (SAR)
Risk Assessments and Control Implementation Summaries:
- Assist with gap assessments, readiness reviews, and coordinate with Third Party Assessment Organizations (3PAOs).
- Support audit interviews, evidence gathering, and remediation plans.
- Ensure continuous compliance with FedRAMP Moderate/High and ISO 27001 controls. Policy, Documentation, and Risk Management
- Draft and maintain security policies, standards, procedures, and guidelines related to vulnerability and patch management.
- Integrate vulnerability management findings into enterprise Risk Register.
- Develop executive-level dashboards and reports on risk visibility and leadership decision-making. Collaboration and Leadership
- Act as a technical SME and mentor to junior engineers on vulnerability management tooling and methodologies.
- Work cross-functionally with product security, IT, cloud, and compliance teams.
- Advocate for secure development practices and continuous improvement in vulnerability detection and response.
What You Bring:
- 6+ years of hands-on experience in information security, with at least 4 years specifically in vulnerability management.
- Demonstrable deep expertise with Tenable Security Center, Tenable.io, Wiz, and Veracode platforms.
- Expertise in automating / integrating the above platforms with Jira and other ticketing platforms with custom tools.
- In-depth knowledge of vulnerability assessment tools, CVEs, CVSS scoring, and remediation techniques.
- Strong experience managing or supporting FedRAMP (Moderate or High) and ISO 27001 compliance programs.
- Industry certifications such as CISSP, CISM, CRISC, or relevant technical certs (e.g., Tenable Certified, Veracode Certified).
- Knowledge of other compliance frameworks: NIST 800-53, SOC 2
Why Proofpoint
Protecting people is at the heart of our award-winning lineup of cybersecurity solutions, and the people who work here are the key to our success. We’re a customer-focused and a driven-to-win organization with leading-edge products. We are an inclusive, diverse, multinational company that believes in culture fit, but more importantly ‘culture-add’, and we strongly encourage people from all walks of life to apply.
We believe in hiring the best and the brightest to help cultivate our culture of collaboration and appreciation. Apply today and explore your future at Proofpoint! #LifeAtProofpoint
Why Proofpoint? At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you’ll love working with us:
• Competitive compensation
• Comprehensive benefits
• Learning & Development: We are committed to the growth and development of our team members, offering a range of programs including leadership and professional development workshops, stretch project assignments, and mentoring opportunities to help employees reach their full potential.
• Flexible work environment: [Remote options, hybrid schedules, flexible hours, etc.].
• Annual wellness and community outreach days
• Always on recognition for your contributions
• Global collaboration and networking opportunities
Our Culture:
Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone. We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to accessibility@proofpoint.com. How to Apply Interested? Submit your application here https://www.proofpoint.com/us/company/careers. We can’t wait to hear from you!
Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and/or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.
Base Pay Ranges:
SF Bay Area, New York City Metro Area:
Base Pay Range: 132,160.00 - 207,680.00 USDCalifornia (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska:
Base Pay Range: 109,410.00 - 171,930.00 USDAll other cities and states excluding those listed above:
Base Pay Range: 98,700.00 - 155,100.00 USDTags: Audits CISM CISSP Cloud Compliance CRISC CVSS DevOps FedRAMP ISO 27001 Jira Monitoring NIST NIST 800-53 POA&M Product security Qualys Risk assessment Risk management Security assessment Security Assessment Report SLAs SOC SOC 2 Strategy System Security Plan Threat intelligence Veracode Vulnerabilities Vulnerability management
Perks/benefits: Career development Competitive pay Equity / stock options Flex hours Flex vacation Startup environment Transparency Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.