Junior Security Engineer (ConMon) | Remote US
United States
Applications have closed
Coalfire
Coalfire is a cybersecurity and compliance services company that works with enterprises and tech businesses in FedRAMP, cloud migration, AI Risk, pen…Position SummaryAs Vulnerability Management I Engineer at Coalfire within our Managed Services group, you will be a self-starter, passionate about cloud security, and thrive on problem-solving. You will provide strategy, leadership, and operational support of Vulnerability Management processes for clients with regulatory compliance requirements. The Managed Services team is responsible for identifying, assessing, and managing threats, vulnerabilities, and associated risks to clients’ information assets and resources. You will work within major public clouds and best-of-breed tools, utilizing your technical abilities to monitor vulnerabilities and recommend remediation or resolution.
What You'll Do
- Join a highly collaborative security operations team designing and delivering vulnerability management services to Cloud
- Service Providers, and other organizations operating highly regulated environments.
- Serve as the principal advisor to the client and our team on all matters related to vulnerability management.
- Collaborate in a cross functional model with infrastructure engineering, site relatability engineering, and client’s success managers to deliver a seamless, holistic experience for client engagements.
- Work across a myriad of technology stacks in the leading cloud providers like AWS, Azure, and GCP, embracing their unique client-driven deployments and operational requirements.
- Coordinate with clients and team members to identify the right balance of cloud and defense-in-depth techniques to translate client’s goals into a secure and effective solution.
- Influence the maturity of Coalfire processes and standards related to vulnerability management activities and propagate through development and maintenance of standard operating procedures, training curriculums, technical documentation, and troubleshooting guidelines.
- Serve as part of the vulnerability management team that is conducting:
- Recurring and on-demand OS/DB, web application, and container scanning activities;
- Development of Plan of Action and Milestone (POA&M) reports
- Client-facing and Government-facing discussions related to results and risks for multiple client environments.
- Conduct testing and data reviews to evaluate the effectiveness of current contractual measures
- Provide support to the security assessment and authorization process
- Communicate with internal management to provide insights into the current risk in client environments and proposed remediation strategies
What You'll Bring
- BS or above in related Information Technology field or equivalent combination of education and experience
- 2+ years of related experience in professional services, vulnerability management, and compliance monitoring.
- Experience supporting clients in a managed service organization.
- Familiarity with ITSM solutions (e.g., Jira, ServiceNow) and meeting SLAs.
- Skills in web application testing, API testing, and network testing.
- Ability to analyze information security vulnerabilities and collaborate with teams for remediation.
- Experience developing playbooks, runbooks, and troubleshooting technical issues.
- Knowledge of vulnerability scoring systems (CVSS/CMSS).
- Experience with vulnerability scanning tools (e.g., Nessus, Nexpose, Burp Suite).
- Ability to analyze vulnerabilities and adjust risk ratings based on internal factors.
- Familiarity with OS Baseline Configuration standards (e.g., CIS Critical Security Controls Scanning).
- Excellent communication, organizational, and problem-solving skills.
- Experience working with auditors to ensure adherence to controls, policies, and standards.
- Strong documentation skills, including technical diagrams and descriptions.
- Ability to work independently and as part of a team with a professional attitude and demeanor.
- Critical thinking, and ability to balance environmental requirements with mission needs
Bonus Points
- Certifications in Cloud Vendors, as well as with organizations such as PMP, CISSP, CISM, or CISA
- Previous Experience in a 24x7x365 environment for a SaaS provider
Tags: APIs AWS Azure Burp Suite CISA CISM CISSP Cloud Compliance CVSS GCP Jira Monitoring Nessus POA&M SaaS Security assessment SLAs Strategy Vulnerabilities Vulnerability management Web application testing
Perks/benefits: Career development Competitive pay Equity / stock options Flex hours Flex vacation Health care Insurance Parental leave Salary bonus Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.