Talent.com
Technology Vulnerability Management Engineer
Technology Vulnerability Management EngineerCooley • San Francisco, CA, United States
Technology Vulnerability Management Engineer

Technology Vulnerability Management Engineer

Cooley • San Francisco, CA, United States
8 days ago
Job type
  • Full-time
Job description

Technology Vulnerability Management Engineer

Cooley is seeking a Technology Vulnerability Management Engineer to join the Security team.

Position Summary : Cooley Technology embraces a culture of customer service excellence, and all members of the department are expected to move this agenda forward. To that end, the Technology Vulnerability Management Engineer is expected to recognize that the Cooley Technology department is a service organization first and foremost and will be evaluated on this requirement equal in importance to the technical or operational responsibilities outlined later in this document.

The Technology Vulnerability Management Engineer will lead the full vulnerability management lifecycle across endpoints, servers, applications, containers, and cloud environments. This role owns discovery, validation, risk-based prioritization, and remediation outcomes. The engineer will administer and optimize vulnerability management platforms, automate data flows and reporting, and partner with Technology and Innovation teams to meet SLA targets and reduce enterprise risk. The position will be a balance of hands-on technical execution, program leadership, and clear communication, while staying current on emerging threats and supporting audits, compliance efforts, and incident response activities. Specific duties include, but are not limited to, the following :

Position responsibilities

  • Support the development and continuous optimization of vulnerability management services, including scanning cadence, exception handling, SLAs and alignment with security controls
  • Build and maintain standards, playbooks, and repeatable processes to improve the efficiency and maturity of the vulnerability management program
  • Administer and optimize enterprise vulnerability management platforms (e.g., Tenable / Qualys / Rapid7), ensuring accurate coverage across assets
  • Integrate asset context from CMDB, EDR, and cloud inventory to drive effective risk-based prioritization
  • Build automation for data ingestion, deduplication, ticketing, and reporting using APIs, scripting, and other tools to improve data quality and reduce false positives
  • Analyze and interpret vulnerability scan results to assess severity, validate findings, and provide actionable remediation recommendations
  • Publish dashboards and reports tailored for engineers, management, and executive leadership to communication progress and risk
  • Drive remediation efforts, including patching, configuration baselines, and compensating controls, and validate results through rescans or attestations
  • Partner with developers, DevOps, and other stakeholders to implement "shift-left" practices such as pipeline scanning, container / base-image hygiene, and Infrastructure-as-Code (IaC) hardening
  • Collaborate with cross-functional teams to implement security solutions and controls that mitigate identified vulnerabilities
  • Support audits, assessments, and regulatory compliance requirements by providing accurate documentation and evidence
  • Identify opportunities for process improvements, tool optimization, and template standardization to increase efficiency and reduce operational overhead
  • Stay current on emerging threats, vulnerabilities, and industry best practices to ensure the program remains effective and modern
  • Contribute to advanced security testing activities such as penetration testing, application reviews and targeted vulnerability assessments as needed
  • Assist with incident response activities by providing vulnerability context, supporting root cause analysis, and helping to validate containment and remediation actions
  • All other duties as assigned or required

Skills and experience :

Required :

  • After orientation at Cooley LLP, exhibit proficiency in the Microsoft 365, MECM, Intune, iManage and other firm applications
  • Ability to work extended and / or weekend hours, as required
  • 2+ years of experience in cyber security, vulnerability management, or penetration testing. Senior candidates must have 5+ years' directly applicable experience in the field
  • Strong hands-on experience conducting vulnerability scans, including configuration and use of tools such as Tenable, Qualys, Rapid7
  • Knowledge of cybersecurity frameworks, controls and standards, and best practices
  • Solid understanding of Windows / Linux, networks, web / application stacks, and at least one major cloud provider (AWS / Azure)
  • Proficiency in Python or PowerShell and REST APIs; ability to build repeatable pipelines / dashboards
  • Familiarity with CVSS, KEV, EPSS and how they align with risk frameworks
  • Extensive knowledge and experience generating and disseminating easily digestible metrics and report to system owners and leadership
  • Preferred :

  • Bachelor's Degree in Information Technology or Computer Information Systems
  • Knowledge of the Mitre ATT&CK framework and NIST Cyber Security Framework
  • Familiarity with common security controls in the enterprise (Firewall, Proxy, AV, SIEM, etc.)
  • Experience with incident response procedures
  • Extensive knowledge and understanding of security issues, techniques, and implications across multiple computer platforms
  • Demonstrated experience leading and developing others by providing technical guidance and leadership to project teams
  • Solid knowledge and understanding of security regulations and best practices such as the ISO 27000 family of standards
  • Demonstrated experience communicating technical information to business clients and less experienced technologists
  • CISSP, CISM or equivalent
  • Experience with CI / CD pipelines
  • Cloud Architecture and / or Cloud Security Certifications (AWS, Azure, GCP)
  • Cloud Security Alliance (CCSP, CCSK) (ISC)2
  • Additional security certifications
  • Competencies :

  • Exceptional customer service skills
  • Excellent analytical, problem-solving, customer service, project management and communication skills
  • Goal-oriented
  • Proven track record of excellent decision making, integrity and working with IT management, business users and business professionals
  • Excellent oral and written communication skills, including technical and user documentation
  • Strong organizational skills
  • Ability to work independently and under high pressure with tight schedules and deadlines
  • Ability to interact well with all levels of business professionals
  • Excellent active listening skills
  • Flexible and patient with process development / execution and adherence to instruct project management practices
  • Capable of grasping new concepts quickly and without prior experience
  • Detail-oriented
  • Ability to multi-task and work in fast-paced environment
  • Ability to interact and coordinate with several teams to achieve objectives
  • Ability to solve problems independently and simultaneously, effectively managing multiple tasks
  • Professional demeanor at all times
  • Cooley offers a competitive compensation and excellent benefits package and is committed to fair and equitable employment practices. EOE.

    The expected annual pay range for this position is $110,000 - $155,000. Please note that final offer amount will be dependent on geographic location, applicable experience and skillset of the candidate. Senior level candidates may be considered for this position and would be eligible for a higher salary range based on experience.

    We offer a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and / or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, long-term care coverage, backup care for children and / or adults and other parental support benefits. In addition to elective benefit options, benefited employees receive firm-paid life insurance, AD&D, LTD, short term medical benefits as well as 21 days of Paid Time Off ("PTO") and 10 paid holidays each year. We provide generous parental leave and fertility benefits. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.

    Create a job alert for this search

    Vulnerability Management Engineer • San Francisco, CA, United States

    Related jobs
    Senior Vulnerability Management Engineer

    Senior Vulnerability Management Engineer

    Strava • San Francisco, CA, United States
    Full-time
    Strava is the app for active people.With over 150 million athletes in more than 185 countries, it's more than tracking workouts-it's where connection, motivation, and personal bests thrive.No matte...Show more
    Last updated: 30+ days ago • Promoted
    Principal DevOps Engineer

    Principal DevOps Engineer

    Informatica LLC • Redwood City, CA, United States
    Full-time
    Build Your Career at Informatica.We seek innovative thinkers who believe in the power of data to drive meaningful change. At Informatica, we welcome adventurous minds eager to solve the world's most...Show more
    Last updated: 30+ days ago • Promoted
    Site Reliability Engineer

    Site Reliability Engineer

    ConductorOne • San Francisco, CA, United States
    Full-time
    ConductorOne is the first AI-native identity security platform that protects every identity : human, non-human, and AI.With powerful automation, platform-level AI, and out-of-the-box connectors, it ...Show more
    Last updated: 30+ days ago • Promoted
    Staff Systems Engineer

    Staff Systems Engineer

    Bio-Rad Laboratories • Hercules, CA, United States
    Full-time
    Working within Bio-Rad's Life Science R&D Group as a Systems Engineer, you will take engineering concepts, requirements and transform them into functional prototypes and finished products that impr...Show more
    Last updated: 30+ days ago • Promoted
    Deployment Engineer

    Deployment Engineer

    Netic • San Francisco, CA, United States
    Full-time
    Netic is the AI revenue engine that handles multi‑modal workflows, generates new demand, and drives measurable revenue for the $500B+ essential service industries that keep America running.With $20...Show more
    Last updated: 30+ days ago • Promoted
    Principal Vulnerability Engineer

    Principal Vulnerability Engineer

    Kandji • San Francisco, CA, United States
    Full-time
    Principal Vulnerability Engineer.San Francisco / Engineering / Full-Time / On-site.Kandji is the Apple Device Management and Security Platform. Kandji empowers companies to manage and secure Apple d...Show more
    Last updated: 30+ days ago • Promoted
    Threat Advisory Engineer, Solutions Engineering

    Threat Advisory Engineer, Solutions Engineering

    Cloudflare Inc • San Francisco, CA, United States
    Full-time
    At Cloudflare, we are on a mission to help build a better Internet.Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for cust...Show more
    Last updated: 19 days ago • Promoted
    Senior Observability Engineer : Scalable Telemetry & Kubernetes

    Senior Observability Engineer : Scalable Telemetry & Kubernetes

    Crusoe Energy Systems LLC • San Francisco, CA, United States
    Full-time
    A leading energy technology company is seeking a Senior / Staff Software Engineer for observability platforms, focused on designing and operating scalable systems in a multi-datacenter environment.Ca...Show more
    Last updated: 2 days ago • Promoted
    Senior Field Engineering TechnicianReliability & Test • Berkeley, CA • Full time • On-site

    Senior Field Engineering TechnicianReliability & Test • Berkeley, CA • Full time • On-site

    Form Energy • Berkeley, CA, United States
    Full-time
    Are you ready to build America's energy future? Form Energy is an American manufacturing and energy technology company.We're revolutionizing energy storage with cost-effective, multi-day technology...Show more
    Last updated: 30+ days ago • Promoted
    Full-Stack Systems Engineer

    Full-Stack Systems Engineer

    Purple Unicorn Company • San Francisco, CA, United States
    Full-time
    Non-negotiable : ALL ROLES ARE ON-SITE IN SAN FRANCISCO.IN ORDER TO BE CONSIDERED YOU MUST BE LOCAL OR WILLING TO MOVE.Must be authorized to work in the US • • •. At SalesPatriot, we are more than a sof...Show more
    Last updated: 30+ days ago • Promoted
    Forward Deployed Engineer

    Forward Deployed Engineer

    Rise Technical Recruitment Limited • San Francisco, CA, United States
    Full-time
    Forward Deployed Engineer (AI Infrastructure).San Francisco, CA - Onsite (6 days / week).Are you an engineer who loves solving complex, real-world problems directly with customers? Do you want to wor...Show more
    Last updated: 25 days ago • Promoted
    Threat Assessment Engineer

    Threat Assessment Engineer

    KellyMitchell Group • San Francisco, CA, United States
    Full-time
    Our client is seeking a Threat Assessment Engineer to join their team! This position is remote.Perform threat modeling for infrastructure and applications, including security architecture and data ...Show more
    Last updated: 19 days ago • Promoted
    Technology Vulnerability Management Engineer

    Technology Vulnerability Management Engineer

    Cooley LLP • San Francisco, CA, United States
    Full-time
    Technology Vulnerability Management Engineer.Cooley is seeking a Technology Vulnerability Management Engineer to join the Security team. Cooley Technology embraces a culture of customer service exce...Show more
    Last updated: 10 days ago • Promoted
    Engineering Manager, Offensive Security & Vulnerability Management

    Engineering Manager, Offensive Security & Vulnerability Management

    Robinhood • Menlo Park, CA, United States
    Full-time
    Join us in building the future of finance.Our mission is to democratize finance for all.An estimated $124 trillion of assets will be inherited by younger generations in the next two decades.The lar...Show more
    Last updated: 30+ days ago • Promoted
    Forward Deployed Engineer - MTS

    Forward Deployed Engineer - MTS

    Context • San Francisco, CA, United States
    Full-time
    We're on a mission to unlock the next frontier of productivity for knowledge workers.Context AI is building the future of enterprise AI—systems that don't just answer questions or automate simple t...Show more
    Last updated: 30+ days ago • Promoted
    HPC Storage Systems Group Leader

    HPC Storage Systems Group Leader

    Lawrence Berkeley National Laboratory • Berkeley, CA, United States
    Full-time +2
    The National Energy Research Scientific Computing Center (NERSC) is inviting applications for the position of Storage Systems Group (SSG) Lead. NERSC's mission is to accelerate scientific discovery ...Show more
    Last updated: 17 days ago • Promoted
    Senior Site Reliability Engineer, Healthcare Cloud Infrastructure and Networking

    Senior Site Reliability Engineer, Healthcare Cloud Infrastructure and Networking

    Collective Health • San Francisco, CA, United States
    Full-time
    Senior Site Reliability Engineer, Healthcare Cloud Infrastructure and Networking.At Collective Health, we’re transforming how employers and their people engage with their health benefits by seamles...Show more
    Last updated: 1 day ago • Promoted
    Deployment Engineering, Networking

    Deployment Engineering, Networking

    Recruiting From Scratch • San Francisco, CA, United States
    Full-time
    Mission District, San Francisco, CA (Hybrid – Tue–Thu in office).Recruiting from Scratch — a specialized talent firm dedicated to helping companies build exceptional teams.Our client is a fast-grow...Show more
    Last updated: 30+ days ago • Promoted