Talent.com
Technology Vulnerability Management Engineer
Technology Vulnerability Management EngineerCooley LLP • Chicago, IL, United States
Technology Vulnerability Management Engineer

Technology Vulnerability Management Engineer

Cooley LLP • Chicago, IL, United States
30+ days ago
Job type
  • Full-time
Job description
Technology Vulnerability Management Engineer

Cooley is seeking a Technology Vulnerability Management Engineer to join the Security team.

Position Summary: Cooley Technology embraces a culture of customer service excellence, and all members of the department are expected to move this agenda forward. To that end, the Technology Vulnerability Management Engineer is expected to recognize that the Cooley Technology department is a service organization first and foremost and will be evaluated on this requirement equal in importance to the technical or operational responsibilities outlined later in this document.

The Technology Vulnerability Management Engineer will lead the full vulnerability management lifecycle across endpoints, servers, applications, containers, and cloud environments. This role owns discovery, validation, risk-based prioritization, and remediation outcomes. The engineer will administer and optimize vulnerability management platforms, automate data flows and reporting, and partner with Technology and Innovation teams to meet SLA targets and reduce enterprise risk. The position will be a balance of hands-on technical execution, program leadership, and clear communication, while staying current on emerging threats and supporting audits, compliance efforts, and incident response activities. Specific duties include, but are not limited to, the following:

Position responsibilities

  • Support the development and continuous optimization of vulnerability management services, including scanning cadence, exception handling, SLAs and alignment with security controls
  • Build and maintain standards, playbooks, and repeatable processes to improve the efficiency and maturity of the vulnerability management program
  • Administer and optimize enterprise vulnerability management platforms (e.g., Tenable/Qualys/Rapid7), ensuring accurate coverage across assets
  • Integrate asset context from CMDB, EDR, and cloud inventory to drive effective risk-based prioritization
  • Build automation for data ingestion, deduplication, ticketing, and reporting using APIs, scripting, and other tools to improve data quality and reduce false positives
  • Analyze and interpret vulnerability scan results to assess severity, validate findings, and provide actionable remediation recommendations
  • Publish dashboards and reports tailored for engineers, management, and executive leadership to communication progress and risk
  • Drive remediation efforts, including patching, configuration baselines, and compensating controls, and validate results through rescans or attestations
  • Partner with developers, DevOps, and other stakeholders to implement "shift-left" practices such as pipeline scanning, container/base-image hygiene, and Infrastructure-as-Code (IaC) hardening
  • Collaborate with cross-functional teams to implement security solutions and controls that mitigate identified vulnerabilities
  • Support audits, assessments, and regulatory compliance requirements by providing accurate documentation and evidence
  • Identify opportunities for process improvements, tool optimization, and template standardization to increase efficiency and reduce operational overhead
  • Stay current on emerging threats, vulnerabilities, and industry best practices to ensure the program remains effective and modern
  • Contribute to advanced security testing activities such as penetration testing, application reviews and targeted vulnerability assessments as needed
  • Assist with incident response activities by providing vulnerability context, supporting root cause analysis, and helping to validate containment and remediation actions
  • All other duties as assigned or required

Skills and experience:

Required:

  • After orientation at Cooley LLP, exhibit proficiency in the Microsoft 365, MECM, Intune, iManage and other firm applications
  • Ability to work extended and/or weekend hours, as required
  • 2+ years of experience in cyber security, vulnerability management, or penetration testing. Senior candidates must have 5+ years' directly applicable experience in the field
  • Strong hands-on experience conducting vulnerability scans, including configuration and use of tools such as Tenable, Qualys, Rapid7
  • Knowledge of cybersecurity frameworks, controls and standards, and best practices
  • Solid understanding of Windows/Linux, networks, web/application stacks, and at least one major cloud provider (AWS/Azure)
  • Proficiency in Python or PowerShell and REST APIs; ability to build repeatable pipelines/dashboards
  • Familiarity with CVSS, KEV, EPSS and how they align with risk frameworks
  • Extensive knowledge and experience generating and disseminating easily digestible metrics and report to system owners and leadership

Preferred:

  • Bachelor's Degree in Information Technology or Computer Information Systems
  • Knowledge of the Mitre ATT&CK framework and NIST Cyber Security Framework
  • Familiarity with common security controls in the enterprise (Firewall, Proxy, AV, SIEM, etc.)
  • Experience with incident response procedures
  • Extensive knowledge and understanding of security issues, techniques, and implications across multiple computer platforms
  • Demonstrated experience leading and developing others by providing technical guidance and leadership to project teams
  • Solid knowledge and understanding of security regulations and best practices such as the ISO 27000 family of standards
  • Demonstrated experience communicating technical information to business clients and less experienced technologists
  • CISSP, CISM or equivalent
  • Experience with CI/CD pipelines
  • Cloud Architecture and/or Cloud Security Certifications (AWS, Azure, GCP)
  • Cloud Security Alliance (CCSP, CCSK) (ISC)2
  • Additional security certifications

Competencies:

  • Exceptional customer service skills
  • Excellent analytical, problem-solving, customer service, project management and communication skills
  • Goal-oriented
  • Proven track record of excellent decision making, integrity and working with IT management, business users and business professionals
  • Excellent oral and written communication skills, including technical and user documentation
  • Strong organizational skills
  • Ability to work independently and under high pressure with tight schedules and deadlines
  • Ability to interact well with all levels of business professionals
  • Excellent active listening skills
  • Flexible and patient with process development/execution and adherence to instruct project management practices
  • Capable of grasping new concepts quickly and without prior experience
  • Detail-oriented
  • Ability to multi-task and work in fast-paced environment
  • Ability to interact and coordinate with several teams to achieve objectives
  • Ability to solve problems independently and simultaneously, effectively managing multiple tasks
  • Professional demeanor at all times

Cooley offers a competitive compensation and excellent benefits package and is committed to fair and equitable employment practices. EOE.

The expected annual pay range for this position is $110,000 - $155,000. Please note that final offer amount will be dependent on geographic location, applicable experience and skillset of the candidate. Senior level candidates may be considered for this position and would be eligible for a higher salary range based on experience.

We offer a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and/or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, long-term care coverage, backup care for children and/or adults and other parental support benefits. In addition to elective benefit options, benefited employees receive firm-paid life insurance, AD&D, LTD, short term medical benefits as well as 21 days of Paid Time Off ("PTO") and 10 paid holidays each year. We provide generous parental leave and fertility benefits. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.

Create a job alert for this search

Technology Vulnerability Management Engineer • Chicago, IL, United States

Similar jobs
Senior Platform Engineer / MLOps / DevOps / Chicago

Senior Platform Engineer / MLOps / DevOps / Chicago

Motion Recruitment Partners LLC • Chicago, IL, United States
Full-time
We’re supporting a firm known for investing in industry game changers.They are not a startup but are intentionally lean.They look for entrepreneurial-minded engineers who can build from 0-1.They’re...Show more
Last updated: 26 days ago • Promoted
Senior Platform Engineer - ML Infra & MLOps (Chicago)

Senior Platform Engineer - ML Infra & MLOps (Chicago)

Motion Recruitment Partners LLC • Chicago, IL, United States
Full-time
A dynamic tech firm is seeking an experienced Engineer to join their Machine Learning team in Chicago.You will be essential in building core infrastructure, including managing Kubernetes clusters, ...Show more
Last updated: 26 days ago • Promoted
Network Penetration Engineer | Red Team & Social Engineering

Network Penetration Engineer | Red Team & Social Engineering

Evolve Security • Chicago, IL, United States
Full-time
A cybersecurity services firm in Chicago seeks a Penetration Testing Engineer for a hands-on role in offensive security.This position involves conducting network and cloud assessments, executing re...Show more
Last updated: 26 days ago • Promoted
Senior Observability & SRE Engineer

Senior Observability & SRE Engineer

Focused Labs • Chicago, IL, United States
Full-time
A technology consulting company in Chicago is seeking a Site Reliability Engineer with expertise in OpenTelemetry.The role involves designing observability solutions, managing incident response, an...Show more
Last updated: 23 days ago • Promoted
Senior Cloud Detection Engineer

Senior Cloud Detection Engineer

Bank of America • Chicago, IL, United States
Full-time
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.We do this by driving Responsible Growth and delivering for our clien...Show more
Last updated: 23 days ago • Promoted
Cyber MSFT Threat Protection Senior Manager

Cyber MSFT Threat Protection Senior Manager

Grant Thornton • Chicago, IL, United States
Full-time
As a Cybersecurity Senior Manager focused on Microsoft Threat Protection, you will lead complex, high-impact engagements that help clients proactively defend against advanced cyber threats.You will...Show more
Last updated: 25 days ago • Promoted
Forward Deployed Engineer

Forward Deployed Engineer

Saragossa • Chicago, IL, United States
Full-time
AI Forward Deployed Engineer - Build Real World AI Systems.You will be a founding level builder working directly with clients to design, architect, and deploy production grade AI systems from day o...Show more
Last updated: 15 days ago • Promoted
Kubernetes, Container Security & AI Runtime Protection Cybersecurity Engineer

Kubernetes, Container Security & AI Runtime Protection Cybersecurity Engineer

Huntington National Bank • Chicago, IL, United States
Full-time
This employer will not sponsor applicants for the following work visas: F-1 student, H-1B worker, O-1 worker, TN worker, E-3 worker.Applicants must be currently authorized to work in the United Sta...Show more
Last updated: 21 days ago • Promoted
Nuclear PRA Engineer — Remote & Risk-Informed Safety

Nuclear PRA Engineer — Remote & Risk-Informed Safety

Jensen Hughes • Chicago, IL, United States
Remote
Full-time
A leading engineering firm in Schaumburg is seeking junior, mid, and senior level Engineers specializing in Probabilistic Risk Assessment (PRA).Candidates will engage in significant projects that e...Show more
Last updated: 30+ days ago • Promoted
Datacenter Ops Lead: Compliance & Infra

Datacenter Ops Lead: Compliance & Infra

Fortinet • Chicago, IL, United States
Full-time
A cybersecurity company in Chicago seeks a Datacenter Operations Manager responsible for managing data center infrastructure.The role involves overseeing equipment setup, monitoring systems, and co...Show more
Last updated: 26 days ago • Promoted
Security Engineer

Security Engineer

Paul Murphy Associates • Chicago, IL, US
Full-time
Quick Apply
Chicago, IL (Hybrid, in-office).Our client, a well-capitalized start-up building a U.DCM) and clearinghouse (DCO), is seeking a Security Engineer to serve as a hands-on technical lead responsible f...Show more
Last updated: 19 days ago • Promoted
Staff MLOps Engineer

Staff MLOps Engineer

Grindr LLC • Chicago, IL, United States
Full-time
This is a hybrid role based in our Bay Area (SF or Palo Alto) or our Chicago offices and will require you to be in office Tuesdays and Thursdays.What’s so interesting about this role?.We at Grindr ...Show more
Last updated: 21 days ago • Promoted
Pursuit Lead II, TMEG, Google Cloud

Pursuit Lead II, TMEG, Google Cloud

Google • Chicago, IL, United States
Full-time
Pursuit Lead II, TMEG, Google Cloud _corporate_fare_ Google _place_ Chicago, IL, USA; Atlanta, GA, USA; +5 more; +4 more **Mid** Experience driving progress, solving problems, and mentoring more ju...Show more
Last updated: 12 days ago • Promoted
Special Agent: Cybersecurity/Technology Expertise

Special Agent: Cybersecurity/Technology Expertise

ClearanceJobs • Chicago, IL, United States
Full-time +1
The position advertised has been exempted from the federal civilian hiring freeze.Job Title: Special Agent, GL-10 Full Performance Level: GS-13 Location: U.Locations Working Hours: Minimum of 50 ho...Show more
Last updated: 4 days ago • Promoted
Tanium Engineer III — Endpoint Management & Security

Tanium Engineer III — Endpoint Management & Security

McDonald's • Chicago, IL, United States
Full-time
A leading global restaurant brand is seeking an experienced Tanium Engineer III to join their Cybersecurity Endpoint Management team.This role focuses on optimizing the Tanium platform for real-tim...Show more
Last updated: 2 days ago • Promoted
Lead DevOps Engineer

Lead DevOps Engineer

Federal Home Loan Bank of Chicago • Chicago, IL, United States
Full-time
Federal Home Loan Bank of Chicago.At FHLBank Chicago, we support a high performing, engaged workforce and provide competitive compensation and benefits.We offer a comprehensive benefits program, in...Show more
Last updated: 26 days ago • Promoted
Site Reliability Engineer

Site Reliability Engineer

Attain • Chicago, IL, United States
Full-time
Built for consumers and companies, alike.In a world driven by data, we believe consumers and businesses can coexist.Our founders had a vision to empower consumers to leverage their greatest asset—t...Show more
Last updated: 17 days ago • Promoted
Cybersecurity Engineer

Cybersecurity Engineer

CFS • Evanston, IL, United States
Permanent
Remote (occasional in office, ~2 days per month).M/D/V, 401K, Pet Insurance, Tuition Reimbursement, & More.Enhance the company’s cybersecurity and ensure the protection of the organization’s data.D...Show more
Last updated: 4 days ago • Promoted