Talent.com
Senior Security Engineer - Vulnerability Management
Senior Security Engineer - Vulnerability ManagementCARFAX • Centreville, VA, United States
Senior Security Engineer - Vulnerability Management

Senior Security Engineer - Vulnerability Management

CARFAX • Centreville, VA, United States
1 day ago
Job type
  • Full-time
Job description

Description

Join Team CARFAX as a Senior Security Engineer - Vulnerability Management

Isn't it time you bragged about where you work? At CARFAX, we do, every day. We pride ourselves on being mission-focused on helping to grow a brand built on accuracy and integrity. We care deeply about our products and our customers. We're more than just a company : We help millions of consumers make more informed decisions every day. We know that our teammates are our most valuable asset, and we value a balanced life while tackling challenging projects in a fast-paced environment.

We are seeking a highly skilled and motivated Senior Cyber Security Engineer - Vulnerability Management plays a vital role in safeguarding the organization's information assets by designing, implementing, and maintaining robust security measures. This role involves identifying and mitigating security vulnerabilities, responding to security incidents, and ensuring compliance with security policies and standards. The Senior Cyber Security Engineer - Vulnerability Management collaborates with various IT and business teams to integrate security best practices into every aspect of the organization's operations.

At CARFAX, we believe in the power of teamwork and value in-person interactions so that we can collaborate and thrive together. This position will require 3 days per week in our Centreville, VA office subject to change with future business needs.

What you'll be doing :

  • Oversee the end-to-end vulnerability management lifecycle, including scanning, assessment, prioritization, remediation tracking, and reporting.
  • Perform regular vulnerability scans across infrastructure, endpoints, and applications, ensuring accurate detection, proper asset coverage, and alignment with security and compliance requirements.
  • Perform risk-based analysis and triage vulnerability findings based on business impact, asset criticality, threat intelligence, and exploitability. Guide stakeholders on remediation priorities.
  • Collaborate with system owners to drive timely remediation. Develop actionable plans for patching or mitigating vulnerabilities.
  • Ensure system hardening and configuration compliance using industry benchmarks such as CIS and DISA STIGs.
  • Deploy, manage, and optimize vulnerability and compliance scanning tools. Automate scanning, reporting, and alerting to improve coverage and reduce manual effort.
  • Incorporate threat intelligence and exploit data to contextualize vulnerabilities and adjust risk ratings accordingly.
  • Develop clear, concise reports and dashboards that communicate vulnerability status, trends, KPIs, and risk posture to technical and non-technical stakeholders.
  • Continuously evaluate and improve vulnerability management processes, scanning schedules, and remediation workflows to align with evolving threats and organizational needs.
  • Ensure vulnerability management activities align with compliance requirements (e.g., PCI-DSS, SOC II, ISO 27001) and support audit documentation and responses.
  • Act as a liaison between security, infrastructure, application, and business teams. Serve as a subject matter expert on vulnerability-related issues.
  • Provide guidance to junior team members and support knowledge sharing within the cybersecurity team.

What we're looking for :

  • Bachelor's degree in computer science, Information Security, or a related field.
  • Minimum of 5+ years of experience in cybersecurity, with at least 3-4 years focused on vulnerability management.
  • Industry certifications such as CISSP, CEH, CompTIA Security+, or relevant vulnerability management credentials.
  • Strong experience with vulnerability scanning tools (e.g., Qualys, Tenable Nessus, Rapid7 InsightVM).
  • Solid understanding of vulnerability classification standards (e.g., CVSS, CWE, CAPEC) and security frameworks.
  • Familiarity with patch management, system hardening, and configuration management tools and processes.
  • Working knowledge of Linux, Windows, and macOS environments, including OS-level security controls.
  • Understanding of networking protocols, firewalls, and network security best practices.
  • Experience with compliance frameworks such as PCI-DSS, SOC II, or ISO 27001.
  • Strong analytical and problem-solving skills, with the ability to assess complex environments and identify potential exposures.
  • Excellent communication skills, with the ability to convey technical risk to both technical and non-technical stakeholders.
  • Ability to manage multiple projects and tasks in a dynamic, fast-paced environment.
  • What's in it for you :

  • Competitive compensation, benefits and generous time-off policies
  • 4-Day summer work weeks and a winter holiday break
  • 401(k) / DCPP matching
  • Annual bonus program
  • Casual, dog-friendly, and innovative office spaces
  • For a comprehensive list of benefits, please visit our website :
  • Don't just take our word for it :

  • 10X Virginia Business Best Places to Work
  • 10X Washingtonian Great Places to Work
  • 9X Washington Post Top Workplace
  • St.Louis Post-Dispatch Best Places to Work
  • About CARFAX and S&P Global Mobility

    S&P Global has recently announced the intent to separate our Mobility Segment into a standalone public company.

    CARFAX, part of S&P Global Mobility, helps millions of people every day confidently shop, buy, service and sell used cars with innovative solutions powered by CARFAX vehicle history information. The expert in vehicle history since 1984, CARFAX provides exclusive services like CARFAX Used Car Listings, CARFAX Car Care, CARFAX History-Based Value and the flagship CARFAX® Vehicle History Report™ to consumers and the automotive industry. CARFAX owns the world's largest vehicle history database and is nationally recognized as a top workplace by The Washington Post and Glassdoor.com. Shop, Buy, Service, Sell - Show me the CARFAX™. S&P Global Mobility is a division of S&P Global (NYSE : SPGI). S&P Global is the world's foremost provider of credit ratings, benchmarks, analytics and workflow solutions in the global capital, commodity and automotive markets.

    US Equal Opportunity Employer Statement : CARFAX is an Affirmative Action / Equal Opportunity Employer. It is the policy of CARFAX to provide equal employment opportunity to all persons regardless of race, color, sex, pregnancy, religion, national origin, age, ancestry, citizenship status, veteran status, military status, disability or handicap, sexual orientation, genetic information or any other status protected by federal, state or local law. In addition, CARFAX will provide reasonable accommodations for qualified individuals with disabilities. We maintain a drug-free workplace. We are a participant in E-Verify.

    Canadian Equal Opportunity Employer Statement : CARFAX Canada is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to race / ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law.

    We're committed to providing accommodations by request for candidates taking part in all aspects of the recruitment and selection process. For a confidential inquiry or to request an accommodation, please contact your recruiter or email [email protected].

    Create a job alert for this search

    Senior Security Engineer • Centreville, VA, United States

    Related jobs
    Senior Information Security Engineer / Vulnerability Manager

    Senior Information Security Engineer / Vulnerability Manager

    C2 Labs, Inc. • Washington, DC, United States
    Full-time
    Senior Information Security Engineer / Vulnerability Manager.C2 Labs partners with clients on their IT transformation journey via our industry-leading capabilities in full stack development, hyper-...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Legal & General America • Frederick, MD, United States
    Full-time
    Senior Security Engineer Job LocationsUS-MD-Frederick ID 2025-3185 # of Openings Remaining 1 Category IT Overview.At Legal & General America, we aim to make a positive difference in the lives of ou...Show more
    Last updated: 4 hours ago • Promoted • New!
    Security Engineer-Senior Vulnerability Mgmt

    Security Engineer-Senior Vulnerability Mgmt

    Aditi Consulting • Washington, DC, United States
    Full-time
    Lead a small team of individuals who support cybersecurity operational environment and Vulnerability Management related requirements / needs. Engage with Federal Leadership and counterparts to identi...Show more
    Last updated: 1 day ago • Promoted
    Vulnerability Management Engineer

    Vulnerability Management Engineer

    ShorePoint Inc • Washington, DC, United States
    Full-time
    ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience ...Show more
    Last updated: 22 hours ago • Promoted • New!
    Senior Security Engineer

    Senior Security Engineer

    CoStar Group • Arlington, VA, United States
    Full-time
    CoStar Group (NASDAQ : CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, ...Show more
    Last updated: 1 day ago • Promoted
    Senior Security Engineer II (DevSecOps)

    Senior Security Engineer II (DevSecOps)

    Aledade, Inc. • Bethesda, MD, United States
    Full-time
    As a Senior Security Engineer II at Aledade, we play a central role in helping secure our enterprise, cloud native environments, and applications. We’re looking for security engineers that understan...Show more
    Last updated: 5 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    AnaVation LLC • Quantico, VA, United States
    Full-time
    Be Challenged and Make a Difference.In a world of technology, people make the difference.We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched va...Show more
    Last updated: 1 day ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Tad PGS • Washington, DC, United States
    Full-time
    We have an outstanding Contract position for aSenior Security Engineerto join a leading Company located in theWashington, DCsurrounding area. Candidate must possess an Active Top Secret or Top Secre...Show more
    Last updated: 22 hours ago • Promoted • New!
    Senior Security Engineer

    Senior Security Engineer

    CoStar Realty Information, Inc. • Arlington, VA, United States
    Full-time
    CoStar Group (NASDAQ : CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, ...Show more
    Last updated: 1 day ago • Promoted
    Vulnerability Engineer

    Vulnerability Engineer

    SkyePoint Decisions • Laurel, MD, United States
    Full-time
    Cyber and Information Security.SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT s...Show more
    Last updated: 4 hours ago • Promoted • New!
    Senior Security Engineer

    Senior Security Engineer

    DirectViz Solutions • Washington, DC, United States
    Full-time
    DirectViz Solutions, (DVS) is a rapidly growing government contractor that provides strategic services that meet mission IT needs for government customers. DVS provides innovative information techno...Show more
    Last updated: 4 hours ago • Promoted • New!
    Technology Vulnerability Management Engineer

    Technology Vulnerability Management Engineer

    Cooley • Washington, DC, United States
    Full-time
    Technology Vulnerability Management Engineer.Cooley is seeking a Technology Vulnerability Management Engineer to join the Security team. Cooley Technology embraces a culture of customer service exce...Show more
    Last updated: 22 hours ago • Promoted • New!
    Senior Security Engineer

    Senior Security Engineer

    Executive Recruiting • Washington, DC, United States
    Full-time
    Washington, DC | (Hybrid - 3 days in office with travel as required).Must be eligible to obtain a DoD security clearance. This role is critical in securing mission-critical cloud applications and ma...Show more
    Last updated: 1 day ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    NetImpact Strategies • Bethesda, MD, United States
    Full-time
    Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.We are seeking a highly skilled Security Engineer to join our team, specializing in implementing secur...Show more
    Last updated: 30+ days ago • Promoted
    4272 Senior Security Engineer

    4272 Senior Security Engineer

    Procession Systems • Quantico, VA, United States
    Full-time
    We are seeking a highly skilled Senior Security Engineer to provide expertise, guidance, recommendations and document security configurations for the implementation of security tools and processes ...Show more
    Last updated: 1 day ago • Promoted
    Vulnerability Remediation Engineer

    Vulnerability Remediation Engineer

    SkyePoint Decisions • Laurel, MD, United States
    Full-time
    Vulnerability Remediation Engineer.Cyber and Information Security.SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applicatio...Show more
    Last updated: 4 hours ago • Promoted • New!
    Nucleus Security Engineer

    Nucleus Security Engineer

    Leidos Inc • Arlington, VA, United States
    Full-time
    We are seeking a skilled and dedicated Vulnerability Management Administrator to manage and maintain our vulnerability management program using theNucleus Securityplatform.The ideal candidate will ...Show more
    Last updated: 16 hours ago • Promoted • New!
    Senior Security Engineer

    Senior Security Engineer

    USM • Washington, DC, United States
    Full-time
    Role : Senior Security Engineer.Location : Washington, DC (Remote but need to be within 100 miles of DC for emergency meetings). Citizenship : US Citizen able to obtain Public Trust Clearance.Rate : $70...Show more
    Last updated: 1 day ago • Promoted