Senior Vulnerability Engineer
FlairsTech- Posted 6 hours ago
- Be among the first 10 applicants
Job Description
Responsibilities
· Deploy and operate the self-hosted vulnerability management platform (DefectDojo) on Kubernetes, including access control, upgrades, backups, and hardening.
· Build and maintain the ingestion pipeline that converts and normalizes scanner exports (CSV, JSON, XML, SARIF) and imports them reliably.
· Maintain de-duplication and re-import logic so recurring findings stay single items and resolved ones close automatically.
· Build routing that assigns each finding to the correct owning team (Cloud, DB, Windows, Linux) based on asset attributes and keep that mapping current.
· Implement alerting to teams by email and other channels and integrate ITSM such as SymphonyAI.
· Triage and validate findings, filter false positives, and prioritize by real risk using severity, exploitability, and business context.
· Drive remediation with owning teams: define the fix, agree timelines, and follow through to verified closure.
· Coordinate and perform patching and hardening across the concerned team.
· Track progress against SLAs, escalate overdue items, and produce reporting for stakeholders.
Requirements
· 3 to 5 years in vulnerability management or a closely related security role.
· Strong grasp of vulnerability fundamentals: CVE, CVSS, exploitability, prioritization, and remediation lifecycles.
· Hands-on with a vulnerability management or findings platform such as DefectDojo, Tenable, Qualys, or Rapid7.
· Self-hosting and Kubernetes experience: containers, Helm, deployment, and operations, ideally on GCP.
· Linux and Windows administration, including patch management and CIS hardening.
· Scripting for automation and integration (Python preferred), with REST APIs and webhooks.
· Clear communication with security and IT teams, and awareness of NCA controls and data residency.
More Info
Key Skills
DefectDojo
webhooks
Rapid7
Tenable
CIS hardening
